Greater Toronto Area, Canada
Waqar Mehboob
Cybersecurity Leader · AI, Cloud Security & GRC
Securing how organizations adopt AI — 25+ years across cloud security, GRC, and the AI-native enterprise.
Available for speaking, workshops, panels & advisory

Profile
Executive summary
Cybersecurity leader, AI-security and GRC program lead with 25+ years across cloud security, AI governance, risk management, information-security auditing, and data assurance — spanning banking, public sector, healthcare, pension administration, logistics, technology, SMB, Big 4, and multinational environments. I combine hands-on implementation across Microsoft Security, Azure, M365, Purview, Defender, Entra, and Zscaler with executive-level advisory in ISO 27001, SOC 1/2, NIST, and CIS Controls. Today I focus on securing how organizations actually adopt AI: the safe rollout of Microsoft 365 Copilot, Purview DSPM, Responsible AI, and agentic-AI governance.
Global reach
Global security delivery across 19 countries
25+ years across banks, Big 4, manufacturing, public sector, technology, and multinational environments.
- 0Organizations
- 0Countries
- 0Continents
- 0/0On-site / Remote
CanadaSouth AfricaPakistan
CanadaUSA
CanadaUSA
UAEIndia
PakistanUAE
UAE





The differentiator
An AI-native security practice
I am not an observer of the AI shift — I have built my practice around it. My learning curve maps directly onto the industry's: from cloud fundamentals, to using LLMs to accelerate delivery, to securing enterprise AI, to governing autonomous agents.
- 2020
Cloud foundations
Earned AZ-900 (Azure Fundamentals), establishing the cloud platform fluency every later AI initiative would build on.
- 2022
Security & compliance fundamentals
Earned SC-900 — Microsoft Security, Compliance & Identity — formalizing the control framework for cloud-native workloads.
- 2023–24
AI-assisted delivery
Adopted GPT-4 and Bing/Copilot in daily delivery — drafting deliverables, automating Excel/VB macros for data reconciliation, and coaching ISO 27005 risk modelling with AI.
- 2024
Securing enterprise AI
Led the secure launch of Microsoft 365 Copilot using Purview and SharePoint Advanced Management; red-teamed Copilot for data oversharing and built insider-risk and DSPM controls around it.
- 2025
Governing agentic AI
Operationalized Microsoft Security Copilot for the SOC, authored DLP policy for Power Platform AI agents, and configured agentic-AI guardrails (Onyx) for data-leakage and anomalous behaviour — then completed SC-200 SOC Analyst training.
Capabilities
Core skills
AI Security, Copilot & Data Governance
- M365 Copilot Security
- Security Copilot
- GitHub Copilot governance
- Purview DSPM
- Insider Risk
- Power Platform DLP
- Responsible AI
- Agentic AI / Onyx
- GenAI SaaS governance
Cloud & Microsoft Security
- Azure Security
- Defender for Cloud (CSPM/CWP)
- Defender XDR
- Microsoft Sentinel
- Azure Policy
- KQL / Log Analytics
- Event Hub / AMA / DCR
- Intune
- Entra ID
Identity, Access & SaaS Security
- Conditional Access
- MFA
- Entra ID Protection
- SSO / OAuth2 / OIDC
- Identity Governance
- Defender for Cloud Apps
- Zscaler / CASB
- DLP
- SSPM
GRC, Audit & Compliance
- ISO 27001 (impl. & cert. audits)
- ISO 27017 / 27018 / 27005 / 27006
- SOC 1 / SOC 2
- NIST CSF 2.0
- CIS Controls & Benchmarks
- COBIT
- OSFI / FFIEC / OCC
- Third-Party Risk
- SOX / CDIC
Data Assurance & Analytics
- Data governance
- Master data management
- Data migration / integration testing
- CAAT / ACL / IDEA
- SQL Server / SSIS / Informatica
- Power Query
- Tableau / QlikView
- Excel / VBA
SecOps, IR & Programs
- Incident response
- Ransomware / OT IR support
- QRadar / RSA
- CyberArk PAM
- vCISO
- Vulnerability mgmt
- Secure SDLC
- Security metrics / KRIs
- Training & enablement
What people say
Trusted by clients & leaders
A few words from 75+ recommendations by CTOs, CIOs, CISOs, and programme leaders.
Waqar's team performed an excellent job evaluating existing processes and provided a comprehensive analysis and roadmap to required maturity levels. They integrated seamlessly into our workforce and really felt like an extension of our own resources. We were able to achieve simultaneous certifications and complete concurrent audits with the Canadian Cyber team — we would be delighted to recommend Waqar and his team to any organization that needs to establish, evolve or maintain their cybersecurity program.
Canadian Cyber performed an excellent review of our existing process, policies and operational workflows, and delivered all the necessary recommendations to attain ISO 27001 certification in a very short span of time. We strongly recommend their service — an organization of any size can trust them as a long-term, reliable cybersecurity & digitization partner.
Waqar and his team are extremely knowledgeable, diligent, and tireless. I brought Waqar on to design and implement an ISO 27001 program; with shifting priorities this grew to include SOC 1 and SOC 2 Type II. They have been instrumental in helping design, plan, implement, and operate all the policies, procedures, and controls required to satisfy an audit. His team integrates so well that we are genuinely working as one team.