At Nandzu Trade and General Projects, I identified and remediated five control exceptions, including an active ex-employee account, shared administrator credentials, firewall rules with any-any access, and unapproved changes. I reported the results to management and introduced quarterly user access reviews and a change approval step; the next review found no repeat exceptions.
I improved access and security monitoring, reducing unauthorized access incidents by 40%. I also implemented centralised SIEM and log management, supporting audit readiness and reducing incident response time by 20%.
At VM Holdings, I reviewed IT general controls, gathered evidence and documented observations in audit working papers. My review of intrusion prevention and related security configurations contributed to initiatives associated with a 30% reduction in breach incidents.
At Depromat Consulting, I performed compliance and control-focused reviews and coordinated incident-response tabletop exercises that improved response time by 25%. I also developed cybersecurity policies and procedures and led security and compliance training for more than 50 analysts.

