Securing enterprises through ISO 27001 frameworks, proactive risk management, and cutting-edge cybersecurity assurance across East Africa and beyond.
I am a Cybersecurity GRC Specialist with deep expertise in securing financial institutions, critical infrastructure, and enterprise environments across East Africa.
With hands-on experience implementing SIEM solutions, leading PCI DSS certifications, deploying Privileged Access Management (PAM) systems, and conducting comprehensive VAPT assessments, I bridge the gap between technical security and strategic business risk.
My approach integrates internationally recognized frameworks — ISO/IEC 27001, ISO/IEC 27701, and ISO/IEC 42001 — with practical, ground-level implementation to drive measurable organizational resilience.
Risk frameworks, audit programs, compliance monitoring
VAPT, ethical hacking, API penetration testing
SIEM deployment, threat hunting, incident response
ICT training programs, phishing simulations, user education
ISO 27001/27701/42001 implementation, audit programs, risk registers, regulatory alignment
Cybersecurity program design, stakeholder alignment, security roadmaps and governance charters
Web application VAPT, API security testing, network pen tests, red team engagements
Security operations center setup, Wazuh/SIEM deployment, threat hunting, log analysis
Firewall policy, IDS/IPS configuration, network segmentation, VPN and Zero Trust architecture
PAM implementation (Arcon), session monitoring, credential vaulting, least privilege enforcement
OS hardening, endpoint security configuration, Endpoint Central deployment, patch management
Security awareness campaigns, phishing simulations, management reporting, board-level briefings
Led security assurance for USSD, Mobile App, Internet Banking, and E-KYC platforms serving retail customers
Drove end-to-end Payment Card Industry Data Security Standard compliance program
Secured Management Information System rollout with access controls and data classification
Security oversight for Temenos T24 FCM system reducing financial fraud exposure
Deployed Privileged Access Management platform controlling 200+ privileged accounts across the bank
Enterprise-wide endpoint management and patch automation reducing vulnerability exposure by 60%
Deployed open-source SIEM with custom detection rules, dashboards and 24/7 alerting
Comprehensive mobile application penetration testing for field agent banking platforms
25 verified badges across cybersecurity, GRC, cloud, and API security — validated on Credly
Breaking down complex cybersecurity concepts for everyone — from boardrooms to classrooms
A community-driven tech education platform where cybersecurity meets accessibility. Covering threat intelligence, GRC insights, career advice, and the latest in tech — in a language everyone understands.
Whether it's a security audit, a consulting engagement, or a collaboration — I'm ready to help.
Based in Kampala, Uganda — working with clients across East Africa, Europe, and beyond. Let's talk security.