Bola Mabawonku
I build security programs that protect organizations, govern cloud environments at scale, and give boards the visibility they need to make risk decisions. Five-plus years across financial services, healthcare, and technology - spanning Nigeria and Canada.
My career in cybersecurity began in Nigeria, where I built a strong foundation in information security risk management within the financial services sector. Working in a heavily regulated environment under the Central Bank of Nigeria and NDPA 2023 gave me an early appreciation for what it means to build security that is both auditable and operational - not just documented.
My defining professional experience was building a cybersecurity program from absolute zero at a financial institution in Nigeria - as the sole security leader, with no prior security function to build on. In 12 to 18 months I developed the institution's first cybersecurity strategy, authored over 30 policies and procedures, implemented the NIST Cybersecurity Framework across all five functions, and designed an ISO 27001-aligned ISMS. I established board-level governance reporting, managed the CBN regulatory examination with 4 low-risk findings, and built the vulnerability management and security awareness capabilities from nothing.
That experience gave me a practitioner's understanding of what it actually takes to build security culture, regulatory credibility, and operational capability simultaneously - not in theory, but under real organizational and regulatory pressure. The examination cleared with zero material findings.
Beyond the program build, I have delivered enterprise cloud security posture management across AWS, Azure, and GCP, designed third-party risk frameworks for regulated environments, engineered compliance automation pipelines for concurrent SOC 2 and ISO 27001 certifications, led cloud IAM governance remediations across 18 AWS accounts, and built cloud-native incident response capabilities with custom SIEM detection engineering.
I bring to any organization the rare combination of board-level communication, regulatory engagement experience, and hands-on technical delivery - documented with evidence and measurable outcomes across every project in this portfolio.
Eleven documented projects. Four active certifications. Two regulatory environments. One consistent outcome - measurable security programs that protect organizations and satisfy regulators.