Enter your keyword

Bola Mabawonku
Bola Mabawonku
Edmonton, AB · Canada
CISM CRISC CISSP CCSP
// About me - Senior Cybersecurity Leader

Bola Mabawonku

Senior GRC Manager & Cloud Security Architect

I build security programs that protect organizations, govern cloud environments at scale, and give boards the visibility they need to make risk decisions. Five-plus years across financial services, healthcare, and technology - spanning Nigeria and Canada.

5+
Years building security programs
11
Documented projects with evidence
4
Active certifications
4
CBN low-risk findings
My Story
The practitioner behind eleven documented security programs - built, not theorized.

My career in cybersecurity began in Nigeria, where I built a strong foundation in information security risk management within the financial services sector. Working in a heavily regulated environment under the Central Bank of Nigeria and NDPA 2023 gave me an early appreciation for what it means to build security that is both auditable and operational - not just documented.

My defining professional experience was building a cybersecurity program from absolute zero at a financial institution in Nigeria - as the sole security leader, with no prior security function to build on. In 12 to 18 months I developed the institution's first cybersecurity strategy, authored over 30 policies and procedures, implemented the NIST Cybersecurity Framework across all five functions, and designed an ISO 27001-aligned ISMS. I established board-level governance reporting, managed the CBN regulatory examination with 4 low-risk findings, and built the vulnerability management and security awareness capabilities from nothing.

That experience gave me a practitioner's understanding of what it actually takes to build security culture, regulatory credibility, and operational capability simultaneously - not in theory, but under real organizational and regulatory pressure. The examination cleared with zero material findings.

Beyond the program build, I have delivered enterprise cloud security posture management across AWS, Azure, and GCP, designed third-party risk frameworks for regulated environments, engineered compliance automation pipelines for concurrent SOC 2 and ISO 27001 certifications, led cloud IAM governance remediations across 18 AWS accounts, and built cloud-native incident response capabilities with custom SIEM detection engineering.

I bring to any organization the rare combination of board-level communication, regulatory engagement experience, and hands-on technical delivery - documented with evidence and measurable outcomes across every project in this portfolio.

"The greenfield program build that cleared CBN examination with 4 low-risk findings - as the sole security leader - is the outcome I am most proud of. It demonstrated that governance depth and technical delivery are not in tension. They reinforce each other."
- Bola Mabawonku
Career geography
Nigeria → Canada. Cross-regulatory experience spanning CBN Framework, NDPA 2023, OSFI, HIPAA, ISO 27001, NIST CSF 2.0, and PCI DSS v4.0. Two regulatory environments. One consistent standard of delivery.
What makes me different
Most senior security professionals have governance depth or technical depth. I have both, with four active certifications across both dimensions, and eleven documented projects with downloadable evidence artifacts to prove it at every level.
Career Timeline
A progression from analyst to program builder to cloud security architect - across two continents and three sectors.
2024 – Till Date
Canada
Senior GRC Manager / Cloud Security Architect
Technology Service Sector
Building enterprise GRC programs and cloud security architecture across financial services, healthcare, and technology. Multi-cloud CSPM, IAM governance at scale, compliance automation, SIEM detection engineering, and third-party risk management.
78% misconfiguration reduction 340+ IAM users consolidated SOC 2 + ISO 27001 concurrent 65% MTTD reduction
2024 – Till Date
Nigeria
vCISO & IT Advisor
Financial Institution
Provide ongoing virtual CISO advisory on a part-time retainer basis following a full-time CISO tenure at the institution, maintaining continuity of the ISO 27001-aligned ISMS and governance framework built during that engagement. Led the rollout of NIST CSF 2.0 and continue to advise leadership on cybersecurity strategy, emerging risk, regulatory developments, and IT strategic planning.
NIST CSF 2.0 rollout ISO 27001 continuity Retainer advisory
2019 – 2024
Nigeria
Chief Information Security Officer (CISO)
Financial Institution
Built the institution's first cybersecurity program from zero as sole security leader. 30+ policies, NIST CSF implementation, ISO 27001-aligned ISMS, board KRI reporting, vulnerability management, security awareness, and CBN examination management.
4 low-risk CBN findings Sole security leader 97% training completion 34% → 6% phishing click rate
2017 – 2019
Nigeria
Information Security Manager / Senior GRC Analyst
Financial Institution
Information security risk assessments, gap analyses, policy development, and compliance monitoring aligned to ISO 27001 and CBN Cybersecurity Framework across multiple financial services clients.
ISO 27001 CBN Framework NDPA 2023 Third-party risk
Core Competencies
My practice spans two interconnected disciplines - governance, risk, and compliance at the program level, and cloud security architecture at the technical level. I operate fluently across both.
🔲
GRC & Governance
Cybersecurity strategy and program development
Information security policy framework authoring (30+ policies)
Enterprise risk management and risk registers
Board and executive cybersecurity reporting - KRI dashboards
Regulatory engagement - OCC, FFIEC, CBN, NDPA, PIPEDA
Third-party and vendor risk management (120+ vendors)
Compliance automation - SOC 2, ISO 27001 concurrent
Cloud Security Architecture
Cloud security posture management - AWS, Azure, GCP
IAM governance and least-privilege architecture at scale
Policy-as-code via SCPs and Permission Boundaries
SIEM detection engineering - Microsoft Sentinel, KQL
MITRE ATT&CK for Cloud mapping and custom detection rules
Cloud IR playbooks - four scenarios, NIST SP 800-61 Rev 3
SOAR automation and alert response
📋
Regulatory Compliance
NIST CSF 2.0 - all six functions including Govern
ISO 27001:2022 - ISMS design and implementation
SOC 2 Type II - evidence pipeline and audit management
HIPAA Security Rule and HITECH
PCI DSS v4.0 - CDE scoping, controls, and assessment
FFIEC CAT - examination preparation and response
DORA, NDPA 2023, PIPEDA, CBN Framework
🧠
Emerging & Forward-Looking
AI risk governance - NIST AI RMF and EU AI Act
Deepfake-aware security awareness program design
Human risk management - 8-KPI behavioural framework
AI tool governance and shadow AI inventory
DORA supply chain risk - Article 30 contract compliance
NIST SP 800-61 Rev 3 - updated April 2025
Education & Credentials
Academic qualifications evaluated by World Education Services (WES) with Canadian equivalency confirmed.
🎓
Master of Business Administration (MBA)
UNICAF University, Malawi
2020
Business administration with a focus on strategic management and organizational leadership.
🏫
Bachelor of Science - Computer Science
Olabisi Onabanjo University, Nigeria
2008
Foundation in computer science, software engineering, and information systems. WES evaluated - Canadian equivalency confirmed.
CISM
Certified Information Security Manager
ISACA
✓ Active
CRISC
Certified in Risk & Information Systems Control
ISACA
✓ Active
CISSP
Certified Information Systems Security Professional
ISC2
✓ Active
CCSP
Certified Cloud Security Professional
ISC2
✓ Active
Beyond Security
The person behind the certifications.
🌎
Two continents, one standard
My career spans Nigeria and Canada - two very different regulatory environments, two different technology landscapes, and two different organizational cultures. That cross-continental experience gives me a perspective on security that purely domestic practitioners rarely develop.
📚
Continuous learner
Four active certifications across both governance and technical dimensions. I stay current on the frameworks that matter - NIST CSF 2.0, NIST SP 800-61 Rev 3, EU AI Act, PCI DSS v4.0 - and publish thought leadership on what they mean in practice for security leaders.
🏠
Based in Alberta
Edmonton, AB, Canada. Open to Senior GRC Manager, Cloud Security Architect, and CISO roles across Alberta and Canada - available from September 2026. Alberta and Canadian government, financial services, healthcare, and technology sectors are all target markets.
// Open to new opportunities
Ready to build something together?

Eleven documented projects. Four active certifications. Two regulatory environments. One consistent outcome - measurable security programs that protect organizations and satisfy regulators.

bmabawonku@bolamabawonku.com
View Portfolio & Projects Get in Touch