Michael Shihusa
@michaelshihusa
I’m an ICT risk analyst and information security auditor focused on enterprise IT risk, assurance, and secure delivery.
What I'm looking for
I’m an ICT Risk Analyst and information security professional who drives organizational improvement through practical IT risk assessment, security advisory, and assurance. Since September 2023, I’ve been conducting enterprise and IT risk assessment and follow-through on mitigation controls, including vulnerability assessment and penetration testing across bank IT infrastructure, web applications, and internet banking.
Previously, I served as an Information Systems Auditor and Head of Audit Department at Kenya Commerce Exchange Service Bureau, where I planned audits, audited the effectiveness of security controls for SWIFT services, and supported ISO/IEC 27001:2022 implementation and control reviews. Earlier, as an Information Assurance Consultant at Salaam Technology, I provided information systems audits (ERP, databases, operating systems, and IT governance), performed digital forensics, and delivered cybersecurity awareness trainings—backed by credentials such as ISO/IEC 27001 lead auditing and SWIFT security program certifications.
Experience
Work history, roles, and key accomplishments
ICT Risk Analyst
Co-operative Bank of Kenya Limited
Sep 2023 - Present (2 years 9 months)
Conducted enterprise and IT risk assessments, documenting findings and ensuring mitigation controls are followed through. Performed vulnerability assessments and penetration testing across IT infrastructure and web/internet banking applications, and supported ISO gap analysis and security advisory activities.
Information Systems Auditor
Kenya Commerce Exchange Service Bureau Limited
Jul 2022 - Aug 2023 (1 year 1 month)
Planned and executed information systems audits, auditing the effectiveness of implemented security controls for SWIFT service bureau operations. Reviewed ISO/IEC 27001:2022 implementation, delivered security awareness training, and presented audit findings with recommendations and follow-up support.
Information Technology Auditor
Uba Bank Kenya Limited
Apr 2021 - Jun 2022 (1 year 2 months)
Reviewed core banking and ancillary applications, including digital banking audit reviews. Conducted network and IT infrastructure reviews, performed revenue assurance review, investigated issues, and followed up on audit exceptions through documented audit reporting.
Information Assurance Consultant
Salaam Technology Limited
Mar 2017 - Mar 2021 (4 years)
Provided information assurance through enterprise systems reviews, including ERP, databases, operating systems, network security, and IT governance assessments. Conducted digital forensic investigations, vulnerability assessments, penetration testing for multiple application types, and cybersecurity awareness trainings, including quality assurance over system implementations.
Computer Lab Technician
Strathmore University
Apr 2015 - Dec 2016 (1 year 8 months)
Maintained computer lab hardware, installed and updated software, and troubleshot network and computer issues. Supported lab setup by fixing laptops and configuring computers for new laboratories, and maintained item usage records as store keeper.
Intern
Kapsabet Referral Hospital
Apr 2014 - Jun 2014 (2 months)
Performed data entry tasks and provided basic IT support. Assisted with day-to-day technology support needs during the internship period.
Education
Degrees, certifications, and relevant coursework
Akamai University
Akamai University Certified Akamai Web Application and API Protection, Web Application and API Security
Completed the Akamai University certification in Web Application and API Protection (July 2025).
Securiti
Securiti Certified AI Security and Governance, AI Security and Governance
Completed the Securiti certification in AI Security and Governance (November 2025).
PECB
PECB Certified ISO 31000 Lead Risk Manager, Risk Management
Earned the PECB credential as an ISO 31000 Lead Risk Manager (November 2024).
BSI Training Academy
ISO/IEC 27001:2022 ISMS Lead Auditor, Information Security Management Systems (ISMS)
Completed training and certification as an ISO/IEC 27001:2022 ISMS Lead Auditor (November 2023).
BSI Training Academy
ISO/IEC 27001:2022 ISMS Lead Implementer, Information Security Management Systems (ISMS)
Completed training and certification as an ISO/IEC 27001:2022 ISMS Lead Implementer (October 2023).
(ISC)2
(ISC)2 Certified in Cybersecurity, Cybersecurity
Earned the (ISC)2 certification in cybersecurity (January 2023).
SWIFT
SWIFT Customer Security Program V2022 - Expert, SWIFT Customer Security Program
Completed SWIFT Customer Security Program V2022 (Expert) certification (Aug–Sep 2020).
API Academy
API Academy Certificate in API Security Architect, API Security Architecture
Completed the API Academy certificate in API Security Architect (Aug–Sep 2020).
ISACA
ISACA Certificate in Cybersecurity Fundamentals, Cybersecurity Fundamentals
2017 -
Completed the ISACA certificate in cybersecurity fundamentals (Apr–May 2017).
Christian Intermediate Training College, Kapsabet
Certificate in Computer Operation, Computer Operations
Grade: Distinction (84)
Completed Computer Operation training and received a distinction (Mar–Apr 2011).
Kamobo Secondary School
Kenya Certificate of Secondary Education (KCSE), Secondary Education
2005 - 2008
Grade: Mean Grade B (64 points)
Completed secondary education and obtained a Kenya Certificate of Secondary Education (Jan 2005–Nov 2008).
Strathmore University
IBM Cyber Security Specialist, Cybersecurity
2015 -
Completed the IBM Cyber Security Specialist training (July–Dec 2015).
Ol-Bonata Primary School
Kenya Certificate of Primary Education, Primary Education
1996 - 2004
Grade: Scored 367/500 marks
Completed primary education and obtained a Kenya Certificate of Primary Education (1996–2004).
Strathmore University
CCNA 2 - Routing and Switching Certificate, Networking
2016 -
Completed the CCNA 2 Routing and Switching certificate (Feb–Dec 2016).
ISACA
Certified Information Systems Auditor (CISA), Information Systems Audit
2018 -
Earned the ISACA Certified Information Systems Auditor credential (Jan–Aug 2018).
SWIFT
SWIFT Customer Security Program V2023 - Expert, SWIFT Customer Security Program
Completed SWIFT Customer Security Program V2023 (Expert) certification (Oct–Dec 2022).
Strathmore University
Bachelor of Business Information and Technology, Information and Technology
2013 - 2017
Completed a Bachelor of Business Information and Technology degree (2013–March 2017).
Strathmore University
CCNA 1 - Introduction to Networks Certificate, Networking
2016 -
Completed the CCNA 1 Introduction to Networks certificate (Feb–Dec 2016).
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Michael?
You can contact Michael and 90k+ other talented remote workers on Himalayas.
Message MichaelFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
