Bola Mabawonku
Edmonton, AB · Canada
Edmonton, AB · Canada
• Open to work
// Senior Cybersecurity Leader · CISM · CRISC · CISSP · CCSP
Senior GRC Manager
& Cloud Security Architect
Five-plus years · Financial Services · Healthcare · Technology
I build security programs that protect organizations, govern cloud environments at scale, and give boards the visibility they need to make risk decisions.
CISM
CRISC
CISSP
CCSP
MBA
// Program outcomes
Years experience5+
Documented projects11
Active certifications4
Cloud platforms3
OCC examinationZero findings
// Flagship project — Project 00
Greenfield Cybersecurity Program Build — Community Financial Institution
Built the institution’s first cybersecurity program from zero as the sole security leader, covering strategy, 30+ policies, NIST CSF implementation, an ISO 27001-aligned ISMS, board governance, vulnerability management, and security awareness. The CBN examination cleared with four low-risk findings.
4
Low-risk findings
30+
Policies authored
18mo
Zero to board-ready
78%
Misconfiguration reduction — multi-cloud CSPM
340+
IAM users eliminated → federated SSO
65%
MTTD reduction — Sentinel + 18 KQL rules
9 days
SOC 2 + ISO 27001 evidence cycle
Selected Projects
View all 9 projects →
Cloud Security · CSPM
Enterprise Cloud Security Posture Management
Multi-cloud CSPM across AWS, Azure, and GCP covering 2,400+ assets — 78% critical misconfiguration reduction in 90 days, first clean internal audit in three years.
78% reduction2,400+ assetsClean audit
IAM · Least Privilege
Cloud IAM Governance & Least-Privilege Program
Eliminated 340+ individual IAM users across 18 AWS accounts — federated SSO, CyberArk JIT, zero standing privileged accounts for 12 consecutive months. ITGC finding closed.
340+ consolidated0 standing privilegesITGC closed
Compliance · Automation
SOC 2 & ISO 27001 Compliance Automation Pipeline
Evidence collection cycle compressed from 12 weeks to 9 business days. Concurrent SOC 2 + ISO 27001 certification in a single audit window with zero auditor exceptions.
12 weeks → 9 daysDual certified0 exceptions
SIEM · Detection Engineering
Cloud IR Playbooks & SIEM Detection Engineering
18 custom KQL detection rules mapped to MITRE ATT&CK for Cloud in Microsoft Sentinel. 65% MTTD reduction, 40% of alert responses automated via SOAR.
18 KQL rules65% MTTD reductionMITRE mapped
Core Specialisms
🔲
Governance, Risk & Compliance
Enterprise GRC program design, risk appetite frameworks, Board Risk Committee reporting, OCC and FFIEC regulatory examination management.
☁
Cloud Security Architecture
Multi-cloud CSPM, IAM governance at scale, policy-as-code via SCPs, continuous security posture management across AWS, Azure, and GCP.
🔍
Detection & Incident Response
Microsoft Sentinel, custom KQL detection rules, MITRE ATT&CK for Cloud mapping, SOAR automation, cloud IR playbooks aligned to NIST SP 800-61 Rev 3.
📋
Regulatory Compliance
NIST CSF 2.0 (all 6 functions including Govern), ISO 27001:2022, SOC 2 Type II, HIPAA, PCI DSS v4.0, FFIEC CAT, CBN Framework, NDPA 2023, PIPEDA.
🤝
Third-Party Risk Management
120+ vendor assessments, risk-tiered TPRM frameworks, SOC 2 attestation requirements, DORA Article 30 supply chain compliance, vendor offboarding.
🧠
AI Governance & Human Risk
AI risk management under NIST AI RMF and EU AI Act, deepfake-aware security awareness, phishing simulation — click rate reduced from 34% to 6%.
Frameworks & Standards
Thought Leadership
View all articles →
🤖
AI Governance
AI Risk Governance: The Framework Security Leaders Need Now
NIST AI RMF, EU AI Act risk tiers, shadow AI inventory, and practical implementation steps for security leaders governing AI adoption in regulated environments.
⚡
Regulatory · DORA
DORA is Live — and Most Financial Institutions Are Underprepared
The four most common DORA compliance gaps: ICT vendor registers, missing contract clauses, no tested exit strategy, and misunderstanding the TLPT scope requirement.
// Open to new opportunities
Let’s work together.
Senior GRC Manager, Cloud Security Architect, and CISO roles across Alberta and Canada — available from September 2026.