ISO 27001 Controls Made Practical
Translating 'Access Control' and 'Asset Management' into real-world IT actions.
Cybersecurity Engineer & GRC Specialist
I bridge the gap between complex security regulations and practical, automated technical controls. Specializing in GRC, Security Automation, and Infrastructure.
Initializing scanner...
Loading compliance modules [ISO 27001, NIS2]...
Checking container security...
✓ Vulnerability assessment complete
✓ Compliance checks passed
ISO 27001, NIS2, GDPR, EU AI Act. Translating regulations into technical controls.
Python, Bash, CI/CD pipelines. Automating threat intelligence and reporting.
Docker, Kubernetes, Networking (TCP/IP, DNS, TLS). Hardening systems.
Wazuh, Suricata, ELK Stack. Monitoring, detection, and incident response.
Designed the content structure and user journey for an ISO 27001 compliant security awareness training platform.
Automated pipeline for tracking regulatory changes using RSS feeds, LLM summarization, and Slack notifications.
Serverless pipeline for ingesting and correlating threat intelligence indicators (IOCs) using GCP Cloud Run and BigQuery.
Translating 'Access Control' and 'Asset Management' into real-world IT actions.
Setting up your first Intrusion Detection System with Suricata. Writing basic rules.
A deep dive into how the TLS 1.3 handshake works, packet by packet. No magic, just bytes.
I'm always open to discussing security automation, compliance challenges, or new opportunities.
Get in Touch