HimalayasHimalayas logo
Syed Muhammed IfrahimSI
Open to opportunities

Syed Muhammed Ifrahim

@syedmuhammedifrahim

Principal GRC & cybersecurity consultant helping enterprises operationalize ISO 27001, SOC 2, NIST, and AI governance in cloud.

Pakistan
Message

What I'm looking for

I want to help enterprises lead security, risk, and compliance transformations—operationalizing ISO 27001/SOC 2/NIST and AI governance in cloud-native environments through scalable, risk-driven programs and board-ready reporting.

I’m a principal-level GRC and Cybersecurity Consultant with 8+ years of experience advising enterprise clients on security, risk, and compliance transformation. I specialize in ISO 27001, SOC 2, NIST, and AI governance (ISO 42001), with a focus on scalable compliance architectures that support real business growth.

At Zazmic Inc., I’ve led full-lifecycle ISO 27001 and SOC 2 Type II implementation programs for SaaS, healthcare, and AI-sector clients—driving successful certification outcomes and measurable compliance maturity improvements. I design enterprise risk management frameworks (risk registers, control libraries, treatment plans) aligned with ISO 27001, ISO 42001, and NIST CSF, translating regulatory requirements into practical, enforceable controls.

I also direct AI governance initiatives—aligning client organizations with ISO 42001 and EU AI Act obligations by embedding AI risk into existing GRC workflows and policy suites. Beyond that, I establish vendor risk management and third-party due diligence programs to strengthen supply chain security posture, particularly for regulated-sector clients.

Previously, I’ve built strong audit and cybersecurity depth through roles spanning IT risk, internal audit, cloud assessments, and penetration testing. From ITGC and BCDR reviews to OWASP-based testing (web, mobile, and APIs) and Azure cloud security assessments, my approach consistently prioritizes risk-driven governance, clear board reporting, and continuous compliance monitoring.

Experience

Work history, roles, and key accomplishments

ZI
Current

Principal GRC Consultant

Zazmic Inc.

Jan 2024 - Present (2 years 3 months)

Led full-lifecycle ISO 27001 and SOC 2 Type II implementation programs for SaaS, healthcare, and AI-sector clients, improving compliance maturity and certification readiness. Built enterprise risk management frameworks and AI governance aligned to ISO 42001 and EU AI Act obligations, and integrated controls into cloud-native environments and CI/CD pipelines.

AG

Assistant Manager, IT Risk

AJMS Global

Mar 2023 - Dec 2023 (9 months)

Planned and led IT audit and GRC implementation engagements across UAE banking, real estate, and government sectors using ISO 27001, UAE IA, and NCEMA frameworks. Delivered board-level audit findings and remediation roadmaps, and designed ISO 27001-compliant policies and procedures and ISO 22301-aligned BCM/DR assessments.

DA

Senior GRC & Internal Audit

Daraz

Sep 2022 - Feb 2023 (5 months)

Led ISO 27001 programs that enabled clients to achieve certification and unlock enterprise customer contracts. Supported audit readiness and compliance positioning for enterprise sales, and delivered security roadmaps aligned with business growth.

CL

GRC Analyst

Contour Software Pvt Ltd

Jan 2022 - Aug 2022 (7 months)

Managed the IT internal audit lifecycle, including annual audit planning, fieldwork execution, and reporting to internal audit leadership and the audit committee. Implemented ISO 27001 ISMS controls and PDPL data protection requirements, and designed automated dashboards adopted by 15+ auditors to improve audit tracking and efficiency.

KE

Cybersecurity Consultant

K-Electric

Mar 2018 - Dec 2021 (3 years 9 months)

Conducted IT audits and cybersecurity assessments across critical infrastructure utilities, covering infrastructure, applications, cloud, and business processes. Supported ISO 27001 surveillance audits, performed Azure cloud security assessments, executed OWASP-based penetration testing, and delivered business continuity and disaster recovery (BCDR) gap recommendations.

Education

Degrees, certifications, and relevant coursework

NED University of Engineering & Technology logoNT

NED University of Engineering & Technology

Postgraduate Diploma in Cyber Security, Cyber Security

2020 - 2022

Completed a Postgraduate Diploma in Cyber Security at NED University of Engineering & Technology from 2020 to 2022.

FAST-NUCES logoFA

FAST-NUCES

Bachelor of Science, Computer Science

2013 - 2018

Completed a Bachelor of Science in Computer Science at FAST-NUCES from 2013 to 2018.

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan