Sikander Shah
@sikandershah1
Information security and GRC analyst improving ISMS compliance, risk posture, and security awareness through measurable training.
What I'm looking for
I’m a Governance, Risk & Compliance Analyst with a strong focus on maintaining and improving an Information Security Management System (ISMS). I manage the day-to-day upkeep of information security policies, standards, and procedures, while ensuring risks, exceptions, and non-conformities are properly documented and handled through formal processes.
Across my roles, I’ve helped organizations strengthen their information security posture through targeted training and phishing simulation campaigns, including analysing user behaviour and driving follow-up actions. I also support governance and compliance by performing control testing, evidence collection, and gap analysis for recertification reviews, and by aligning activities across business units with internal policies, regulatory requirements, and industry best practice.
I bring hands-on audit and assurance experience from ISO27001 internal and external audit support, supplier assurance due diligence, vulnerability assessments and penetration test collaboration, and incident triage and response support. I’ve also contributed to access review and least-privilege practices, cyber security impact analysis for IT changes, and ongoing process documentation, helping teams adopt secure practices in BAU and project environments.
Experience
Work history, roles, and key accomplishments
Governance & Risk Analyst
N Brown Group
Aug 2025 - Present (9 months)
Managed day-to-day ISMS governance by maintaining security policies, standards, and procedures to support regulatory alignment and compliance. Performed control testing and evidence collection for IAM recertification, supported supplier assurance, and ran phishing simulation and training follow-ups to improve security awareness.
Information Security Analyst
Irwin Mitchell
Sep 2023 - May 2024 (8 months)
Improved information security practices through targeted awareness training, documentation audits, and phishing simulation testing. Conducted risk assessments and security testing, including vulnerability assessments and penetration tests, and supported incident triage and response.
Information Security Auditor
Clarke Willmott
Jan 2023 - Jun 2023 (5 months)
Supported ISO 27001 compliance by conducting internal IT-focused audits and assisting internal/external audit activity to maintain certification. Completed risk acceptance reviews and third-party assurance activities, and shared practical security guidance across the firm to improve awareness.
Contributed to group information/cyber security strategy and ensured IT changes complied with security standards through security impact analysis. Led access reviews and least-privilege evaluations, supported security policies and business continuity planning, and ran phishing simulations using SIEM and vulnerability management tools to reduce security risk.
Application Support Analyst
FirstGroup
Oct 2019 - Dec 2020 (1 year 2 months)
Administered and monitored application and software infrastructure, including provisioning access for starters and removing access for leavers. Managed Microsoft 365 (Active Directory, Azure Active Directory, and SharePoint), resolved IT support tickets in JIRA and Spiceworks, and provided advanced troubleshooting for end-user application access in the public transport sector.
Education
Degrees, certifications, and relevant coursework
Northumbria University
Master of Science (MSc) in Cyber Security, Cyber Security
2021 - 2022
Completed an MSc in Cyber Security at Northumbria University from 2021 to 2022.
University of Bradford
Bachelor of Science (BSc) in Computer Science, Computer Science
2014 - 2018
Completed a BSc in Computer Science at the University of Bradford from 2014 to 2018.
Sheffield City College
Business Level 3, Business
2012 - 2013
Completed the Peter Jones Enterprise Academy Business Level 3 programme at Sheffield City College from 2012 to 2013.
Rotherham College of Arts & Technology
BTEC Level 3 in Information Technology, Information Technology
2010 - 2012
Completed a BTEC in IT (Level 3) at Rotherham College of Arts & Technology from 2010 to 2012.
Oakwood Technology College
GCSEs (6 subjects), General Education
2005 - 2010
Completed GCSEs (6 subjects including English, Mathematics, and ICT) at Oakwood Technology College from 2005 to 2010.
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Sikander?
You can contact Sikander and 90k+ other talented remote workers on Himalayas.
Message SikanderFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
