Sam Atique
@samatique
Experienced security professional specializing in cloud compliance strategies.
What I'm looking for
I am an experienced and results-oriented security professional with a proven track record in leading cloud compliance strategies and aligning risk governance with business objectives. My expertise lies in automating regulatory validation across multi-industry environments, ensuring that organizations not only meet but exceed compliance standards.
Throughout my career, I have successfully led GRC implementations and delivered audit excellence, integrating DevSecOps best practices into SDLC lifecycles. At IBM, I facilitated cloud services teams in achieving and maintaining industry certifications, achieving 100% compliance with frameworks such as NIST and ISO. My ability to design and map security controls has significantly enhanced security postures and reduced risks across various cloud services.
In my previous roles, I have conducted comprehensive compliance assessments and audits, providing actionable insights that improve client adherence to regulatory requirements. I am passionate about leveraging technology to streamline compliance processes and enhance security measures, ultimately contributing to the overall success of the organizations I work with.
Experience
Work history, roles, and key accomplishments
Security Specialist
IBM USA
Oct 2021 - Apr 2025 (3 years 6 months)
Facilitated IBM Cloud services teams in achieving and maintaining industry certifications (FedRAMP, SOC 2, HIPAA, PCI-DSS, C5, ENS, ISMAP), ensuring 100% compliance with frameworks such as NIST 800-53, ISO 27001, ISO 27017, ISO 27018, CIS Benchmarks, CSA Control Matrix. Led the implementation of CIS and ISO 27017 standards related to data security, encryption, network security, and identity access
Compliance Engineer
Apple Inc.
Mar 2021 - Oct 2021 (7 months)
Led compliance initiatives for Apple’s WP&C, ensuring 100% adherence to internal policies and regulatory requirements across multiple projects. Conducted over 5 privacy impact assessments for transit and access projects, providing actionable guidance to engineering teams and ensuring compliance with GDPR, HIPAA, and other privacy regulations.
Senior Consultant – IT Risk
A-LIGN USA
Sep 2020 - Mar 2021 (6 months)
Conducted SOC 1, SOC 2 (Type I and Type II), and HIPAA compliance attestations for global organizations with complex IT infrastructures, including cloud services hosted on AWS, GCP, and Azure. Successfully completed 8 SOC 2 attestations for SaaS providers and BPO companies, evaluating compliance against common criteria, including availability, confidentiality, and privacy.
IT Auditor
ASCEND TECHNOLOGY INC.
Jan 2019 - Sep 2020 (1 year 8 months)
Conducted IT General Controls (ITGC), IT infrastructure, IT operations, and cybersecurity audits, ensuring compliance with industry standards and regulatory requirements. Provided policy guidance aligned with frameworks such as NIST, SOC 2, and ISO 27000 series, resulting in a significant improvement in compliance adherence.
Senior Consultant
Grant Thornton USA
Sep 2019 - Mar 2020 (6 months)
Conducted comprehensive evaluations of IT General Controls (ITGC), business processes, and application security across the Cal State Financial Information System, identifying high-risk areas. Partnered with senior-level management at the Department of FI$Cal to conduct walkthroughs for over 30 processes, perform testing, and track risk register updates.
IT Internal Auditor
GOLDEN 1 CREDIT UNION USA
Jul 2018 - Dec 2018 (5 months)
Successfully performed and managed the full audit lifecycle for X audits, including Patch Management, ATM Operations, Anti-Malware, and IDS/IPS audits, achieving a 20% improvement in audit efficiency. Prescribed updates to policies and procedures based on audit findings, resulting in a measurable enhancement of data security and privacy controls compliant with NIST, ISO standards.
IT Audit & Security Intern
VERSACOM LP USA
Mar 2018 - Jul 2018 (4 months)
Researched industry-specific Information Security policies/ frameworks such as COBIT, ISO 27000 series, etc., for company-wide deployment. Evaluated IT infrastructures, IT applications, and ERP of the company to assess IT control gaps.
Education
Degrees, certifications, and relevant coursework
Pennsylvania State University - University Park
PhD, Information Systems
Pursued advanced studies in Information Systems, focusing on theoretical and applied aspects of information technology and its impact on organizations. Engaged in research and coursework to deepen understanding of complex systems.
University of Dhaka
MBA, Business
Completed an MBA in Business, focusing on core business principles, management strategies, and organizational leadership. Developed strong analytical and decision-making skills applicable across various industries.
Johns Hopkins University
Certification, AI for Cybersecurity
Completed a specialized certification program in AI for Cybersecurity, gaining expertise in leveraging artificial intelligence to enhance cybersecurity measures and address emerging threats. Focused on practical applications and cutting-edge techniques.
University of Texas - Dallas
Master's, Information Systems
Obtained a Master's degree in Information Systems, developing a comprehensive understanding of information technology management, data analysis, and system design. Engaged in coursework covering various aspects of IT infrastructure and business applications.
Availability
Location
Authorized to work in
Job categories
Interested in hiring Sam?
You can contact Sam and 90k+ other talented remote workers on Himalayas.
Message SamFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
