Enter your keyword

// Portfolio - Documented with evidence and measurable outcomes

Eleven Security Programs.
Eleven Sets of Evidence.

Every project on this page was built, not theorized. Each one has a problem statement, a documented approach, measurable outcomes, and downloadable evidence artifacts. This is what five-plus years of hands-on security program delivery looks like.

11
Documented projects
3
Cloud platforms covered
5+
Years of delivery
4
Low-risk CBN findings
// Flagship project PROJECT 01
Greenfield Cybersecurity Program Build - Community Financial Institution
Built the institution's first cybersecurity program from absolute zero as the sole security leader. Cybersecurity strategy, 30+ policies, NIST CSF implementation across all five functions, ISO 27001-aligned ISMS, board KRI reporting, vulnerability management, security awareness, and CBN examination management, all within 12 to 18 months.
Greenfield program build Sole security leader NIST CSF ISO 27001 CBN examination Board governance
View project details ↓
4
CBN findings
30+
Policies authored
18mo
Zero to board-ready
Cloud Security & Posture Management
PROJECT 02
Cloud Security · CSPM · Multi-Cloud
Enterprise Cloud Security Posture Management Program
Designed and deployed a multi-cloud CSPM program across AWS, Azure, and GCP covering 2,400+ assets at a global financial services firm. Eliminated a three-year pattern of recurring audit findings by implementing continuous misconfiguration detection, policy-as-code enforcement, and automated remediation workflows. Achieved the first clean internal audit result in three years within 90 days of deployment.
78% misconfiguration reduction 2,400+ assets Clean audit - 90 days AWS · Azure · GCP
PROJECT 06
SIEM · Detection Engineering · Incident Response
Cloud IR Playbooks & SIEM Detection Engineering
Built a cloud-native incident response capability for a regulated financial institution by integrating AWS and Azure telemetry into Microsoft Sentinel with 18 custom KQL detection rules mapped to MITRE ATT&CK for Cloud. Developed four cloud IR playbooks covering S3 exfiltration, EC2 cryptomining, IAM credential compromise, and ransomware aligned to NIST SP 800-61 Rev 3.
65% MTTD reduction 18 custom KQL rules 40% alert automation MITRE ATT&CK mapped
IAM Governance & Identity
PROJECT 05
IAM · Least Privilege · Cloud Identity
Cloud IAM Governance & Least-Privilege Program
Designed and implemented a least-privilege IAM governance framework across 18 AWS accounts, eliminating 340+ individual IAM users, all standing privileged access, and the top ITGC audit risk finding within 12 months. Migrated all human identities to federated SSO via IAM Identity Center, implemented CyberArk JIT for privileged access, and enforced governance through Permission Boundaries and Service Control Policies.
340+ users consolidated 0 standing privileges - 12mo ITGC finding closed 98% access review rate
PROJECT 09
IAM · Governance Documentation · RBAC
Cloud IAM Governance Playbook & RBAC Matrix
Designed and documented the complete IAM governance framework for an 18-account AWS Organizations environment - including the eight-tier RBAC model, job function to permission set mappings, Permission Boundary design rationale, JIT access policy, quarterly access review procedures, and joiner-mover-leaver lifecycle process. Built as the governance foundation that gave the technical IAM remediation programme durability and prevented the environment drifting back toward excessive permissions.
8-tier RBAC model 18 AWS accounts Exception requests ↓ 70% Governance playbook
Compliance & Risk Management
PROJECT 03
TPRM · HIPAA · Vendor Risk
Third-Party Cloud Risk Assessment Framework
Built an end-to-end third-party risk management program targeting 120+ SaaS and IaaS vendors in a HIPAA-regulated healthcare technology environment, achieving HIPAA Security Rule compliance and directly supporting a SOC 2 Type II audit outcome. Risk-tiered vendor assessment process identified three high-risk vendors that were offboarded before causing a compliance or security incident.
120+ vendors assessed SOC 2 audit credit 3 high-risk vendors offboarded HIPAA compliant
PROJECT 04
Compliance · Automation · SOC 2 · ISO 27001
SOC 2 & ISO 27001 Compliance Automation Pipeline
Engineered a continuous compliance automation pipeline that reduced manual audit evidence collection from 12 weeks to 9 business days, enabling concurrent SOC 2 Type II and ISO 27001 certification within a single 12-month audit window with zero auditor exceptions. Built a common control framework mapping both standards to a single evidence library, eliminating redundant collection work.
12 weeks → 9 days Dual certified 0 auditor exceptions Common control framework
PROJECT 07
Incident Response · Cloud IR Plan · NIST SP 800-61
Cloud Incident Response Plan - AWS Environment
Designed and documented a comprehensive Cloud Incident Response Plan for an AWS environment aligned to NIST SP 800-61 Rev 3 (April 2025). Defines the full IRT structure with six core members and executive advisors, six-phase IR lifecycle with formal entry and exit criteria and named decision owners, SitRep cadence, and external notification obligations covering OCC, FFIEC, card brands, and cyber insurer.
NIST SP 800-61 Rev 3 6-phase lifecycle Phase exit decision gates IRT structure documented
PROJECT 08
GRC · NIST CSF 2.0 · Governance
NIST CSF Implementation Workbook - v1.1 & v2.0
Designed and built a comprehensive NIST CSF implementation workbook covering all 108 subcategories in v1.1 and all six functions in v2.0 - including the new Govern function - with standardised maturity scoring, automated gap analysis, remediation roadmap, and a 37-artifact evidence register. Used as the assessment and governance tool underpinning the flagship cybersecurity programme build at a regulated financial institution.
108 subcategories All 6 CSF 2.0 functions Govern function included 37 evidence artifacts
PROJECT 10
Security Awareness · Human Risk · AI-Era Threats
Next-Generation Security Awareness & Human Risk Management Programme
Designed and delivered a next-generation security awareness program addressing AI-era threats including deepfake social engineering, AI-generated phishing, and business email compromise. Built an 8-KPI human risk management framework, phishing simulation programme, AI threat literacy curriculum, and a board-level human risk dashboard. Achieved 97% completion rate and reduced phishing click rate from 34% to under 6% within two simulation cycles.
34% → 6% click rate 97% completion 100% board completion AI-era threats
PROJECT 11
AI Governance · Risk Management · MSP Security
AI Risk Governance Framework
Built an enterprise AI risk governance framework for a managed services provider, inventorying 15 AI-enabled features embedded across RMM and PSA platforms with no prior oversight. Classified all use cases under NIST AI RMF 1.0 and EU AI Act risk categories, implemented data handling guardrails across 100% of managed endpoints, and cut client AI-governance questionnaire turnaround from three business days to same-day.
15 AI use cases 100% endpoint coverage NIST AI RMF 1.0
Flagship - Greenfield Program Build
PROJECT 01 - FLAGSHIP
Greenfield Cybersecurity Program Build - Community Financial Institution
0
OCC findings
30+
Policies
18mo
Zero to board-ready
The Challenge

A community financial institution with no existing security function, no policies, no board reporting, no vulnerability management, and an OCC examination on the horizon. As the sole security hire, I had 12 to 18 months to build a defensible, auditable program from absolute zero.

The Outcome

Complete cybersecurity program built and operational. 30+ policies, NIST CSF implementation, ISO 27001-aligned ISMS, Board Risk Committee quarterly reporting with 12 KRIs, vulnerability management, and security awareness achieving 97% completion. OCC examination cleared with zero material findings - first clean examination in the institution's history.

NIST CSF ISO 27001 FFIEC CAT OCC Examination Board Governance Vulnerability Management Security Awareness Zero OCC findings Sole security leader
Tenable/Nessus · NIST CSF · ISO 27001 · KnowBe4 · ServiceNow Read full case study →
// Evidence vault - downloadable artifacts
Every project has proof.

Policies, playbooks, workbooks, dashboards, and detection rules - nine evidence artifacts available for download. Not claims. Documented, verifiable deliverables from real programs at regulated organizations.

Access Evidence Vault →
// Open to new opportunities
Want to discuss any of these projects?

Available for Senior GRC Manager, Cloud Security Architect, and CISO roles across Alberta and Canada from September 2026. Happy to walk through any project in detail.

bmabawonku@bolamabawonku.com
Get in Touch