This profile and the repositories linked from it reflect my personal research, ideas, experiments, and opinions, published in a personal capacity.
I work in cybersecurity risk, GRC, and assurance.
Most of my work sits between methodology, evidence, controls, and practical tooling. I am interested in how risk assessments can become more structured, traceable, and useful without removing human judgment from the process.
- ToBeDecidedLater — early-stage research and engineering workspace for threat-informed, OSCAL-oriented cyber assurance.
- cybersecurity risk assessment methodologies
- ICT and third-party risk
- incident response playbooks
- audit-ready evidence flows
- threat-informed risk scenarios
- NIS2, DORA, ISO 27001, and operational resilience
- AI-assisted, human-owned cyber risk work
I use GitHub mainly as a working space for small tools, research notes, and experiments around:
- cyber risk assessment as code
- incident response workflows
- assurance and evidence management
- MITRE ATT&CK / D3FEND mappings
- OSCAL-based assessment ideas
- local-first knowledge tools
Some repositories are intentionally exploratory: I use them to make reasoning, assumptions, and trade-offs visible while an idea is still being shaped.
Cybersecurity Risk & Compliance specialist with a diploma in Electrical and Computer Engineering, an M.Sc. in Applied Mathematics, and experience across banking, telecommunications, and technology environments.
My path includes hands-on RF/IP network engineering, network operations leadership, security governance, and previous CISO responsibility. I like both the governance side of security and the practical side: building small tools, understanding how systems fail, and using CTF-style practice to keep technical intuition alive.
I am interested in the leadership layer of security as well: how technical risk, regulatory pressure, business constraints, and evidence come together in decisions that security leaders and CISOs have to own.
I care about work that is:
- clear enough to be reviewed;
- structured enough to be repeated;
- practical enough to be used;
- honest enough to show uncertainty.
I use AI as an assistant for implementation, drafting, review, and structuring ideas.
The problem framing, methodology, risk logic, validation, and final decisions remain human-owned.