At Paymob, I lead enterprise risk, policy, audit, and control-testing programs across FedRAMP, SOC 2, ISO 27001, and PCI environments.
I've built a Python-based AWS Lambda control-testing framework mapped to CIS Controls, automating evidence pipelines through AWS Config snapshots, CloudWatch, and Jenkins CI/CD gates. I also author System Security Plans and lead cloud incident response and forensic investigations.
I manage and mentor eight GRC analysts while coordinating audit evidence with Security, Engineering, IT, Legal, Internal Audit, Authorizing Officials, and 3PAOs. Previously, I delivered NIST CSF, ISO 27001, and SOC 2 gap assessments and supported Azure GCC High and CyberArk PAM designs.

