Skip to content

Greater Toronto Area, Canada

Waqar Mehboob

Cybersecurity Leader · AI, Cloud Security & GRC

Securing how organizations adopt AI — 25+ years across cloud security, GRC, and the AI-native enterprise.

Available for speaking, workshops, panels & advisory

  • Government of Canada Secret Clearance (2024)
  • CISSP · CISA · CISM · CCSP
  • 25+ years
Waqar Mehboob — Cybersecurity Leader · AI, Cloud Security & GRC

Profile

Executive summary

Cybersecurity leader, AI-security and GRC program lead with 25+ years across cloud security, AI governance, risk management, information-security auditing, and data assurance — spanning banking, public sector, healthcare, pension administration, logistics, technology, SMB, Big 4, and multinational environments. I combine hands-on implementation across Microsoft Security, Azure, M365, Purview, Defender, Entra, and Zscaler with executive-level advisory in ISO 27001, SOC 1/2, NIST, and CIS Controls. Today I focus on securing how organizations actually adopt AI: the safe rollout of Microsoft 365 Copilot, Purview DSPM, Responsible AI, and agentic-AI governance.

Global reach

Global security delivery across 19 countries

25+ years across banks, Big 4, manufacturing, public sector, technology, and multinational environments.

  • 0Organizations
  • 0Countries
  • 0Continents
  • 0/0On-site / Remote
On-site deliveryRemote delivery
Global Food & Beverage Manufacturer

The differentiator

An AI-native security practice

I am not an observer of the AI shift — I have built my practice around it. My learning curve maps directly onto the industry's: from cloud fundamentals, to using LLMs to accelerate delivery, to securing enterprise AI, to governing autonomous agents.

  1. 2020

    Cloud foundations

    Earned AZ-900 (Azure Fundamentals), establishing the cloud platform fluency every later AI initiative would build on.

  2. 2022

    Security & compliance fundamentals

    Earned SC-900 — Microsoft Security, Compliance & Identity — formalizing the control framework for cloud-native workloads.

  3. 2023–24

    AI-assisted delivery

    Adopted GPT-4 and Bing/Copilot in daily delivery — drafting deliverables, automating Excel/VB macros for data reconciliation, and coaching ISO 27005 risk modelling with AI.

  4. 2024

    Securing enterprise AI

    Led the secure launch of Microsoft 365 Copilot using Purview and SharePoint Advanced Management; red-teamed Copilot for data oversharing and built insider-risk and DSPM controls around it.

  5. 2025

    Governing agentic AI

    Operationalized Microsoft Security Copilot for the SOC, authored DLP policy for Power Platform AI agents, and configured agentic-AI guardrails (Onyx) for data-leakage and anomalous behaviour — then completed SC-200 SOC Analyst training.

Secure Microsoft 365 Copilot launch (Purview + SAM)Security Copilot operationalized for SOC efficiencyAgentic AI governance — Power Platform & OnyxCopilot red-teaming for oversharing & data leakageSC-200 SOC Analyst (2025)

Explore The AI-Native Security Framework →

Capabilities

Core skills

AI Security, Copilot & Data Governance

  • M365 Copilot Security
  • Security Copilot
  • GitHub Copilot governance
  • Purview DSPM
  • Insider Risk
  • Power Platform DLP
  • Responsible AI
  • Agentic AI / Onyx
  • GenAI SaaS governance

Cloud & Microsoft Security

  • Azure Security
  • Defender for Cloud (CSPM/CWP)
  • Defender XDR
  • Microsoft Sentinel
  • Azure Policy
  • KQL / Log Analytics
  • Event Hub / AMA / DCR
  • Intune
  • Entra ID

Identity, Access & SaaS Security

  • Conditional Access
  • MFA
  • Entra ID Protection
  • SSO / OAuth2 / OIDC
  • Identity Governance
  • Defender for Cloud Apps
  • Zscaler / CASB
  • DLP
  • SSPM

GRC, Audit & Compliance

  • ISO 27001 (impl. & cert. audits)
  • ISO 27017 / 27018 / 27005 / 27006
  • SOC 1 / SOC 2
  • NIST CSF 2.0
  • CIS Controls & Benchmarks
  • COBIT
  • OSFI / FFIEC / OCC
  • Third-Party Risk
  • SOX / CDIC

Data Assurance & Analytics

  • Data governance
  • Master data management
  • Data migration / integration testing
  • CAAT / ACL / IDEA
  • SQL Server / SSIS / Informatica
  • Power Query
  • Tableau / QlikView
  • Excel / VBA

SecOps, IR & Programs

  • Incident response
  • Ransomware / OT IR support
  • QRadar / RSA
  • CyberArk PAM
  • vCISO
  • Vulnerability mgmt
  • Secure SDLC
  • Security metrics / KRIs
  • Training & enablement

See selected projects →

What people say

Trusted by clients & leaders

A few words from 75+ recommendations by CTOs, CIOs, CISOs, and programme leaders.

Waqar's team performed an excellent job evaluating existing processes and provided a comprehensive analysis and roadmap to required maturity levels. They integrated seamlessly into our workforce and really felt like an extension of our own resources. We were able to achieve simultaneous certifications and complete concurrent audits with the Canadian Cyber team — we would be delighted to recommend Waqar and his team to any organization that needs to establish, evolve or maintain their cybersecurity program.
Alexei VlassovCTO, GlobalTrade CorporationClient · 2022
Canadian Cyber performed an excellent review of our existing process, policies and operational workflows, and delivered all the necessary recommendations to attain ISO 27001 certification in a very short span of time. We strongly recommend their service — an organization of any size can trust them as a long-term, reliable cybersecurity & digitization partner.
Meer AnwarBoard Member / Former Client, BISPClient · 2022
Waqar and his team are extremely knowledgeable, diligent, and tireless. I brought Waqar on to design and implement an ISO 27001 program; with shifting priorities this grew to include SOC 1 and SOC 2 Type II. They have been instrumental in helping design, plan, implement, and operate all the policies, procedures, and controls required to satisfy an audit. His team integrates so well that we are genuinely working as one team.
Dale Boudreau, PMPProgram & Risk Management LeaderClient · 2021

Read all recommendations →