Skip to main content
HimalayasHimalayas logo
MS
Open to opportunities

Michael Shihusa

@michaelshihusa

I’m an ICT risk analyst and information security auditor focused on enterprise IT risk, assurance, and secure delivery.

Kenya
Message

What I'm looking for

To work and grow with an organization in an integral, professional and adaptable manner, applying my information and cybersecurity skills to strengthen organizational improvement through IT risk assessment, assurance, and security advisory.

I’m an ICT Risk Analyst and information security professional who drives organizational improvement through practical IT risk assessment, security advisory, and assurance. Since September 2023, I’ve been conducting enterprise and IT risk assessment and follow-through on mitigation controls, including vulnerability assessment and penetration testing across bank IT infrastructure, web applications, and internet banking.

Previously, I served as an Information Systems Auditor and Head of Audit Department at Kenya Commerce Exchange Service Bureau, where I planned audits, audited the effectiveness of security controls for SWIFT services, and supported ISO/IEC 27001:2022 implementation and control reviews. Earlier, as an Information Assurance Consultant at Salaam Technology, I provided information systems audits (ERP, databases, operating systems, and IT governance), performed digital forensics, and delivered cybersecurity awareness trainings—backed by credentials such as ISO/IEC 27001 lead auditing and SWIFT security program certifications.

Experience

Work history, roles, and key accomplishments

CL
Current

ICT Risk Analyst

Co-operative Bank of Kenya Limited

Sep 2023 - Present (2 years 9 months)

Conducted enterprise and IT risk assessments, documenting findings and ensuring mitigation controls are followed through. Performed vulnerability assessments and penetration testing across IT infrastructure and web/internet banking applications, and supported ISO gap analysis and security advisory activities.

KL

Information Systems Auditor

Kenya Commerce Exchange Service Bureau Limited

Jul 2022 - Aug 2023 (1 year 1 month)

Planned and executed information systems audits, auditing the effectiveness of implemented security controls for SWIFT service bureau operations. Reviewed ISO/IEC 27001:2022 implementation, delivered security awareness training, and presented audit findings with recommendations and follow-up support.

UL

Information Technology Auditor

Uba Bank Kenya Limited

Apr 2021 - Jun 2022 (1 year 2 months)

Reviewed core banking and ancillary applications, including digital banking audit reviews. Conducted network and IT infrastructure reviews, performed revenue assurance review, investigated issues, and followed up on audit exceptions through documented audit reporting.

SL

Information Assurance Consultant

Salaam Technology Limited

Mar 2017 - Mar 2021 (4 years)

Provided information assurance through enterprise systems reviews, including ERP, databases, operating systems, network security, and IT governance assessments. Conducted digital forensic investigations, vulnerability assessments, penetration testing for multiple application types, and cybersecurity awareness trainings, including quality assurance over system implementations.

SU

Computer Lab Technician

Strathmore University

Apr 2015 - Dec 2016 (1 year 8 months)

Maintained computer lab hardware, installed and updated software, and troubleshot network and computer issues. Supported lab setup by fixing laptops and configuring computers for new laboratories, and maintained item usage records as store keeper.

KH

Intern

Kapsabet Referral Hospital

Apr 2014 - Jun 2014 (2 months)

Performed data entry tasks and provided basic IT support. Assisted with day-to-day technology support needs during the internship period.

Education

Degrees, certifications, and relevant coursework

Akamai University logoAU

Akamai University

Akamai University Certified Akamai Web Application and API Protection, Web Application and API Security

Completed the Akamai University certification in Web Application and API Protection (July 2025).

Securiti logoSE

Securiti

Securiti Certified AI Security and Governance, AI Security and Governance

Completed the Securiti certification in AI Security and Governance (November 2025).

PECB logoPE

PECB

PECB Certified ISO 31000 Lead Risk Manager, Risk Management

Earned the PECB credential as an ISO 31000 Lead Risk Manager (November 2024).

BSI Training Academy logoBA

BSI Training Academy

ISO/IEC 27001:2022 ISMS Lead Auditor, Information Security Management Systems (ISMS)

Completed training and certification as an ISO/IEC 27001:2022 ISMS Lead Auditor (November 2023).

BSI Training Academy logoBA

BSI Training Academy

ISO/IEC 27001:2022 ISMS Lead Implementer, Information Security Management Systems (ISMS)

Completed training and certification as an ISO/IEC 27001:2022 ISMS Lead Implementer (October 2023).

(ISC)2 logoIS

(ISC)2

(ISC)2 Certified in Cybersecurity, Cybersecurity

Earned the (ISC)2 certification in cybersecurity (January 2023).

SWIFT logoSW

SWIFT

SWIFT Customer Security Program V2022 - Expert, SWIFT Customer Security Program

Completed SWIFT Customer Security Program V2022 (Expert) certification (Aug–Sep 2020).

AA

API Academy

API Academy Certificate in API Security Architect, API Security Architecture

Completed the API Academy certificate in API Security Architect (Aug–Sep 2020).

ISACA logoIS

ISACA

ISACA Certificate in Cybersecurity Fundamentals, Cybersecurity Fundamentals

2017 -

Completed the ISACA certificate in cybersecurity fundamentals (Apr–May 2017).

CK

Christian Intermediate Training College, Kapsabet

Certificate in Computer Operation, Computer Operations

Grade: Distinction (84)

Completed Computer Operation training and received a distinction (Mar–Apr 2011).

KS

Kamobo Secondary School

Kenya Certificate of Secondary Education (KCSE), Secondary Education

2005 - 2008

Grade: Mean Grade B (64 points)

Completed secondary education and obtained a Kenya Certificate of Secondary Education (Jan 2005–Nov 2008).

Strathmore University logoSU

Strathmore University

IBM Cyber Security Specialist, Cybersecurity

2015 -

Completed the IBM Cyber Security Specialist training (July–Dec 2015).

OS

Ol-Bonata Primary School

Kenya Certificate of Primary Education, Primary Education

1996 - 2004

Grade: Scored 367/500 marks

Completed primary education and obtained a Kenya Certificate of Primary Education (1996–2004).

Strathmore University logoSU

Strathmore University

CCNA 2 - Routing and Switching Certificate, Networking

2016 -

Completed the CCNA 2 Routing and Switching certificate (Feb–Dec 2016).

ISACA logoIS

ISACA

Certified Information Systems Auditor (CISA), Information Systems Audit

2018 -

Earned the ISACA Certified Information Systems Auditor credential (Jan–Aug 2018).

SWIFT logoSW

SWIFT

SWIFT Customer Security Program V2023 - Expert, SWIFT Customer Security Program

Completed SWIFT Customer Security Program V2023 (Expert) certification (Oct–Dec 2022).

Strathmore University logoSU

Strathmore University

Bachelor of Business Information and Technology, Information and Technology

2013 - 2017

Completed a Bachelor of Business Information and Technology degree (2013–March 2017).

Strathmore University logoSU

Strathmore University

CCNA 1 - Introduction to Networks Certificate, Networking

2016 -

Completed the CCNA 1 Introduction to Networks certificate (Feb–Dec 2016).

Find your dream job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan