STEPHANE ESSOMBA
@stephaneessomba
Senior IT audit and cybersecurity governance consultant, delivering PCI-DSS/SOC 2 compliance and risk-based control improvements.
What I'm looking for
I’m a Cybersecurity, risk, and compliance leader with over 20 years of experience in IT audit, technology risk management, regulatory compliance, and information security in highly regulated environments. I lead PCI-DSS, SOC 2 Type 2, and Interac assessments, advising executive stakeholders and improving governance, control effectiveness, and organizational resilience.
What sets me apart is how I translate complex technical and compliance findings into practical, risk-based recommendations—so teams can prioritize remediation and raise security maturity. I also build and strengthen security capabilities across control design and security architecture, SIEM monitoring (ArcSight ESM, Splunk), and vulnerability management/penetration testing, while tracking findings through closure. With CISSP, CISA, and PCI-DSS QSA credentials, I’m committed to clear, actionable reporting and stakeholder-ready advisory that supports strategic decision-making.
Experience
Work history, roles, and key accomplishments
Sr Information Security Consultant
UBITRAK
Jun 2017 - Present (9 years 1 month)
Leads IT audit and PCI-DSS qualified security assessor (QSA) engagements, assessing governance, control design, and operational effectiveness. Delivers structured compliance reporting and performs risk/vulnerability assessments aligned with PCI-DSS, CIS, and NIST, supporting remediation and security posture improvement.
Cloud Security Expert
Fortica Cybersecurity
Aug 2021 - Feb 2022 (6 months)
Developed cloud security architecture and supported implementation of cloud security controls across Azure, Office 365, and AWS environments. Authored cloud security governance policies and advised teams on risk, threats, remediation planning, and secure cloud usage.
Sr Information Security Consultant
Gryphons Consulting Inc
Aug 2015 - Jun 2017 (1 year 10 months)
Designed and deployed security architectures and SIEM solutions using ArcSight and Splunk to improve monitoring, traceability, and audit evidence generation. Coordinated penetration testing, vulnerability management, and risk assessments, and developed SIEM operational processes for detection, analysis, response, and governance.
Information Security Analyst
CGI Inc
May 2010 - Jul 2015 (5 years 2 months)
Supported senior management in designing and implementing information security policies, standards, and procedures aligned with regulatory and governance requirements. Oversaw SIEM processes and conducted security event analysis, incident coordination, and penetration testing, including Tripwire/nCircle CCM integrity monitoring and vulnerability tracking.
IT Analyst Consultant
IBM Canada
Nov 2008 - May 2010 (1 year 6 months)
Provided real-time monitoring and analysis of incidents affecting technical infrastructure and critical software systems. Monitored HPE NonStop servers using HP WebViewPoint and supported troubleshooting for banking processes in Tandem environments, including link/node diagnostics using TACL and system management in complex multi-vendor environments.
Education
Degrees, certifications, and relevant coursework
American Military University (AMU)
Certificate, Terrorism Studies
Completed a Certificate in Terrorism Studies in 2024 at AMU.
Polytechnique Montréal
Certificate, Cyber-investigation
Completed a Certificate in Cyber-investigation at Polytechnique Montréal in 2020.
Institute Descartes
AEC, Analyst-Programmer
Completed an Analyst-Programmer program (AEC) at the Institute Descartes in 2003.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring STEPHANE?
You can contact STEPHANE and 90k+ other talented remote workers on Himalayas.
Message STEPHANEGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
