Yaasir Nizwer
@yaasirnizwer
GRC analyst specializing in cyber risk and data privacy, translating controls and compliance into executive-ready decisions.
What I'm looking for
I’m a cybersecurity GRC and privacy professional with 5+ years of experience, including Big 4 consulting at Deloitte, delivering enterprise risk assessments, compliance programs, and privacy frameworks for regulated industries.
I specialize in NIST CSF/RMF and ISO 27001/27701, with proven expertise across SOC 2, PCI DSS, and major privacy regimes including GDPR, HIPAA, and CCPA, consistently translating technical risks into business-focused recommendations for executives.
At Deloitte, I led NIST CSF-based maturity and gap assessments across 5+ enterprise clients, identifying 40+ critical control deficiencies and building prioritized remediation roadmaps. I also supported SOC 2 readiness through Trust Services Criteria mapping, strengthening audit preparedness and evidence traceability, and created ISO 27001-aligned risk control matrices for enterprise ERP environments.
Most recently, I’ve been training and mentoring 200+ global professionals in SOC 2 and ISO 27001-aligned control mapping, risk assessment methodologies, and audit readiness workflows, helping practitioners turn frameworks into operational GRC deliverables. I bring additional experience in third-party risk management and privacy impact assessments (PIA/DPIA), and I’m currently progressing through a certified cyber security track while serving in remote, cross-border GRC engagements.
Experience
Work history, roles, and key accomplishments
GRC Mentor & Trainer
Better Cyber Career
Oct 2024 - Present (1 year 8 months)
Delivered structured GRC and cybersecurity compliance training for 200+ professionals across ISO 27001, SOC 2, PCI DSS, and HIPAA. Developed SOC 2/ISO 27001-aligned modules for control mapping, risk assessment, and audit readiness, and coached practitioners on risk registers and control documentation.
Senior Associate - Cyber Strategy
Deloitte
Jun 2022 - Jul 2024 (2 years 1 month)
Led NIST CSF-based cybersecurity maturity and gap assessments for 5+ enterprise clients, identifying 40+ critical control deficiencies and producing prioritized remediation roadmaps. Supported SOC 2 readiness, built ISO 27001 risk control matrices for enterprise ERP environments, and delivered GDPR/CCPA/HIPAA/PDPA compliance initiatives including PIAs and regulatory gap analysis.
Research Analyst - Information Security
Digital Research Solutions
May 2021 - Apr 2022 (11 months)
Conducted security risk assessments across cloud and on-premise environments, identifying control weaknesses across IAM, data protection, and access management. Evaluated systems against CIS Controls and NIST RMF to produce ISMS-aligned security controls and prioritized remediation roadmaps to improve governance and audit readiness.
Governance Operations Administrator
Soul Hive
Sep 2018 - Mar 2022 (3 years 6 months)
Supported governance operations by aligning internal processes with international governance, risk, and information security control standards. Implemented standardized project governance templates, monitored KPIs, and maintained audit-ready compliance documentation to support continuous control evaluation.
Education
Degrees, certifications, and relevant coursework
EC-Council
EC-Council Certified Cyber Security Professional (CCSP), Cyber Security
In progress: EC-Council Certified Cyber Security Professional Program (CCSP), including CND, CEH, and CHFI.
University of the West of England, Bristol
Master of Business Administration (MBA), Business Administration
Pursuing a Master of Business Administration (MBA) at the University of the West of England, Bristol, expected in 2026.
University of Gloucestershire
BSc (Hons) in Cyber Security, Cyber Security
Completed a BSc (Hons) in Cyber Security at the University of Gloucestershire in 2025.
Data Protection Authority of Sri Lanka
Certified Data Protection Officer (DPO), Data Protection
Certified as a Data Protection Officer (DPO) by the Data Protection Authority of Sri Lanka in 2025.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Salary expectations
Job categories
Skills
Interested in hiring Yaasir?
You can contact Yaasir and 90k+ other talented remote workers on Himalayas.
Message YaasirFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
