Skip to content

Career

Experience

25+ years spanning global banking, manufacturing, public sector, and Big 4 consulting — from hands-on cloud and AI security today, back to security leadership and software development.

Download full CV (.docx)

25 years at a glance

A quarter-century in security

  1. 2000

    Into security & software

    Began in information security and software engineering after a BCS in Pakistan.

  2. 2003

    Banking security, Dubai

    Security consultant for internet banking and IAM at Commercial Bank of Dubai.

  3. 2005

    CISSP & CISA

    Earned CISSP and CISA while running the IS audit program at ADCB; MBA followed in 2006.

  4. 2007

    Regional risk leadership

    Information Security Risk Manager across Barclays Africa & Emerging Markets; CISM in 2008.

  5. 2011

    Big 4 — PwC Canada

    Moved to Canada as Manager, Risk Assurance — banking & pension audit and data assurance.

  6. 2014

    Founded Canadian Cyber

    Launched a cybersecurity consultancy — vCISO, ISO 27001/SOC, audits; CSSLP & ISO 27001 Lead Auditor.

  7. 2020

    Cloud pivot

    CCSP and AZ-900 — formalizing cloud security as the foundation for what came next.

  8. 2023

    Enterprise security in food & beverage

    Joined a global manufacturer as Cybersecurity Specialist across Microsoft security, cloud and GRC.

  9. 2024

    Secret clearance + securing AI

    Government of Canada Secret Clearance; led the secure launch of Microsoft 365 Copilot.

  10. 2025

    Governing agentic AI

    Operationalized Microsoft Security Copilot and built agentic-AI governance; SC-200 SOC Analyst.

Detailed history

Roles & impact

Cybersecurity Specialist

Global Food & Beverage Manufacturer · Toronto, Canada

Dec 2023 – Present

Hands-on cloud & AI security for a global food & beverage manufacturer — driving Microsoft security platform maturity across IT and OT environments.

  • Led the secure launch of Microsoft 365 Copilot (Purview, SharePoint Advanced Management); built DLP for Power Platform AI agents and agentic-AI guardrails via Onyx; operationalized Security Copilot for conditional-access optimization; red-teamed Copilot for data oversharing.
  • Matured Microsoft Defender for Cloud (CSPM/CWP) across multiple subscriptions; partnered with PwC to align Azure Policy with NIST SP 800-53, ISO 27001:2022, and the Azure Cloud Security Benchmark.
  • Refreshed CASB policies and use cases, cutting false-positive rates by up to 75%; deployed Zscaler DLP/CASB and Defender for Cloud Apps across the SaaS estate (Workday, Office 365, SharePoint).
  • Overhauled Conditional Access and Entra ID Protection (sign-in / user-risk) policies; briefed CIO, VPs, and Directors on MFA strategy and risk-based access.
  • Supported Tenable OT sensor rollout across plants; contributed to a NIST CSF 2.0 upgrade workshop incorporating OT, and co-led incident response for an OT cybersecurity incident with legal and external retainers (Dragos, IBM).
  • Engineered SAP-to-QRadar log pipelines (Event Hub, Azure Monitor / AMA, DCRs) for the SAP cloud-migration security workstream.

Cybersecurity Leader / Lead Consultant

Canadian Cyber Inc. · Canada

Jun 2014 – Nov 2023

Founded and led a boutique cybersecurity consultancy delivering virtual CISO, certification, and assessment services internationally.

  • Delivered vCISO, ISO 27001 / SOC 1 / SOC 2, and CIS Controls programs for 20+ clients across Canada, the US, Pakistan, and Norway.
  • Directed a team of 20+ consultants; authored 140+ ISMS policies and procedures supporting successful ISO 27001 certification audits.
  • Modernized Microsoft 365 / Entra environments: Conditional Access, SSPR, Purview DLP & sensitivity labels, Intune MDM, and SSO via OAuth2 / OIDC.
  • Began embedding AI into delivery — GPT-4 / Copilot for client deliverables, macro automation, and ISO 27005 risk-assessment coaching.

Manager, Risk Assurance

PwC Canada · Toronto, Canada

Oct 2011 – Jun 2014

Risk-based IT and data audits plus large-scale data-quality and migration assurance for banking and pension clients.

  • Led CDIC, SOX, and Volcker Rule audits and risk-based reviews across 11 mainframe banking applications.
  • Built ETL / data-migration and quality-assurance programs (Oracle Unifier, SSIS, T-SQL, Informatica) consolidating legacy data into unified models.

Regional Head, Data Quality

Barclays Bank · EMEA / Africa

Dec 2007 – Sep 2011

Established data governance and information-security risk programs across multiple countries.

  • Ran information-security risk assessments and onsite privacy reviews across Kenya, UAE, India, Uganda, and Egypt.
  • Built logical access management and records-management frameworks; delivered 20+ security-awareness sessions; served as a Certified Ethical Hacker trainer.

Asst. Security Manager / Senior IS Auditor

ADCB Bank · Abu Dhabi, UAE

Aug 2004 – Dec 2007

Owned the bank’s IS audit program and security policy estate.

  • Planned and ran a 24-review annual IS audit program; maintained 19 security policies aligned to regulatory standards.
  • Built application-security audit-log requirements and ran risk assessments on core banking applications.

Security Consultant

CBD Bank · Dubai, UAE

Feb 2003 – Jul 2004
  • Built IAM software for internet banking and led secure code reviews (SQLi / XSS) for HR systems.
  • Authored security procedures and performed application vulnerability assessments.

Information Security Manager

Arbros Forest Resources

Jun 2000 – Jan 2003
  • Managed network and application security administration; led a 100 man-month ERP automation project (VB / MS SQL Server).