Toluwalope Odeku
@toluwalopeodeku
Results-driven cybersecurity professional specializing in GRC, ISO 27001/42001, and privacy compliance.
What I'm looking for
I am a results-driven cybersecurity professional with experience in Governance, Risk, and Compliance (GRC). I deliver measurable value by aligning security initiatives with business objectives, and I specialize in designing and implementing enterprise-wide security strategies in accordance with global standards, including ISO 27001, ISO 42001, NIST, GDPR, and NDPR.
In my current role as a Compliance Programs Officer, I serve as an ISMS co-owner alongside the CISO, ensuring the Statement of Applicability (SoA) is current and justified, managing the risk register, and coordinating internal audits and management reviews. I also support ISO 27701 privacy operations and ISO 42001 AI governance by maintaining policies, overseeing risk assessments, managing inventories, and ensuring auditable evidence—alongside SOC 2 control matrix building, evidence collection, and exception remediation.
Experience
Work history, roles, and key accomplishments
Compliance Programs Officer
Lustrew Dynamics
Nov 2025 - Present (5 months)
Co-owned the ISO 27001 ISMS, maintaining the Statement of Applicability, managing the risk register, and coordinating internal audits and management reviews. Led ISO 27701 privacy governance (RoPA, lawful basis, PII obligations, PIAs/DPIAs) and ISO 42001 AI governance (policies, AI risk assessments, inventory, human oversight, and audit readiness), supporting SOC 2 evidence mapping and exceptions
IMS Auditor
Infosafe Technologies
Mar 2024 - Present (2 years 1 month)
Developed audit programmes and audit plans, defined scope and criteria, and led opening/closing meetings with auditees. Gathered objective evidence via interviews, observation, and document review, assessing conformity against ISO and organisational requirements.
GRC Analyst
CyberTech Nexus
Nov 2024 - Mar 2025 (4 months)
Developed and maintained internal GRC policies, frameworks, and procedures, ensuring clear accountability structures. Performed risk identification, assessment, and prioritisation, maintained risk registers, and supported board-level reporting on risk and compliance posture.
Information Security Engineer
Peasters Nigeria Plc
Jan 2022 - Oct 2024 (2 years 9 months)
Monitored and responded to security incidents, applied patches, and mitigated threats. Owned vulnerability management and improved application security by integrating OWASP Top 10 practices into DevOps pipelines, implementing DLP controls and conducting email threat intelligence analysis.
Network Security Analyst
Cyclox Nigeria Ltd
Jan 2019 - Dec 2021 (2 years 11 months)
Designed, deployed, and managed network security infrastructure including firewalls, routers, and switches. Planned security architecture and network upgrades (LAN/WAN/VoIP/Wireless) and developed enforcement of security policies to meet PCI DSS and data privacy requirements.
Education
Degrees, certifications, and relevant coursework
BAZE University
Professional Diploma, Cyber Security
Completed a Professional Diploma in Cyber Security at BAZE University.
Samuel Adegboyega University
BSc (Hons)
Completed a BSc (Hons) at Samuel Adegboyega University.
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Toluwalope?
You can contact Toluwalope and 90k+ other talented remote workers on Himalayas.
Message ToluwalopeFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
