Skip to main content
NS
Open to opportunities

Naumaan Shaikh

@naumaanshaikh

Entry-level GRC & information security professional specializing in ISO 27001, NIST CSF, and SOC 2 compliance.

India
Message

What I'm looking for

I’m looking for remote GRC or compliance work where I can map risks to controls, produce audit-ready documentation (ISO 27001/NIST CSF/SOC 2), and collaborate cross-functionally to close security gaps with clear remediation plans.

I’m an entry-level GRC and information security professional with hands-on experience conducting governance, risk, and compliance assessments aligned to ISO 27001, NIST CSF, SOC 2, and CIS Controls. I focus on translating regulatory expectations into clear, actionable compliance documentation that teams can actually implement.

I’ve built a complete ISO 27001 compliance portfolio for a SaaS organization, including a 20-asset risk register (with Critical, High, and Medium risks), a 15-control Statement of Applicability (all controls assessed as applicable), and a 9-section information security policy. I’m deliberate about linking risks to controls and maintaining consistency across artifacts so nothing is left ambiguous.

In my GRC work, I support security policy development, risk register creation, and client-facing GRC advisory by identifying security gaps and mapping controls to ISO 27001 and NIST CSF. I apply SOC 2 Trust Service Criteria and ISO 27001 Annex A controls to real business challenges, balancing framework rigor with practical remediation planning.

I also bring research-to-delivery discipline by designing a structured NIST CSF cybersecurity risk assessment tool scoped for small-to-medium enterprises. Alongside my security work, I’ve developed a Python-based application with database integration and completed a Power BI job simulation to practice turning compliance data into executive-ready dashboards.

Experience

Work history, roles, and key accomplishments

SP
Current

ISO 27001 Portfolio Developer

Self-Directed Portfolio Project

Jan 2026 - Present (5 months)

Authored a full ISO 27001 compliance portfolio for a fictional SaaS, including a 20-asset risk register (6 Critical, 12 High, 2 Medium) with risk owners and Reduce treatment plans, plus a 15-control Statement of Applicability and an ISO/IEC 27001-aligned information security policy.

PC
Current

GRC & Compliance Analyst

PlutoSec - Cybersecurity Company

Nov 2025 - Present (7 months)

Conduct governance, risk, and compliance assessments for SME clients, aligning security controls with ISO 27001, NIST CSF, and CIS Controls. Support creation and review of security policies, risk registers, and SOC 2–aligned compliance documentation.

Education

Degrees, certifications, and relevant coursework

University of Chester logoUC

University of Chester

Master of Science, Advanced Cyber Security

2025 -

Activities and societies: Completed ISO 27001 risk register, SoA, and security policy; built vendor risk assessment elements for GRC coursework/research aligned to NIST CSF.

MSc in Advanced Cyber Security focused on governance, risk management, compliance, and information security frameworks, with portfolio deliverables including an ISO 27001 risk register, Statement of Applicability, and information security policy.

Parul University logoPU

Parul University

Bachelor of Computer Applications, Computer Applications

2022 - 2025

Activities and societies: Studied computer programming, Python, SQL, data analytics, web development, and databases.

Bachelor of Computer Applications (BCA) covering programming and data-focused coursework including Python, SQL, databases, and web development.

Tech stack

Software and tools used professionally

Find your dream job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan