IT Audit · ISO 27001 · CEH

Saifullah Hashmi

Information security and IT audit consultant at Adrem Technologies. ISO 27001, IT audit, pentest and PDPL — previously KPMG, and 50+ clients certified to ISO 27001.

I don’t sell a binder. I leave a system an auditor can sample.

Most people pick a lane: GRC paperwork, or a pentest report. The useful work sits in the overlap — controls that operate, evidence that exists, and a finding someone can close.

That is the through-line from 50+ ISO 27001 certifications to GITC files at KPMG and the ISMS at Adrem Technologies: a control an auditor can sample, not a slide pack they have to take on trust.

ISO 27001 implementation

Gap assessment, ISMS build, internal audit and certification readiness — written so a certification body can sample it.

Learn more

IT audit · GITC / ITAC

Access, change and operations tested inside live audit files. Design and operating effectiveness, not a slide pack.

Learn more

Internal audit

Walkthroughs, sampling and reports the external auditor will actually read. Findings with owners and dates.

Learn more

VAPT & assessments

Scoped tests with Burp, Nmap and the rest — then a remediation report engineering can schedule against.

Learn more

Experience

A track record across ISO compliance, IT audit and hands-on security.

  1. Aug 2026 — Present

    Information Security and IT Audit Consultant · Adrem Technologies

    Information security and IT audit consultant at Adrem Technologies Middle East. Running the ISO 27001 programme — KPIs, disaster recovery, and external audits — plus IT audits, penetration testing, and data privacy under PDPL.

    Engagement detail
  2. Dec 2025 — Aug 2026

    IT Audit Associate 2 · KPMG Pakistan

    Eight months at KPMG on GITC and ITAC assessments inside financial-statement and SOX-style audits. The book included telecom, NADRA (national database), oil and gas, and overseas assignments. Left in August 2026.

    Engagement detail
  3. Oct 2024 — Nov 2025

    ISO 27001 Consultant · ISO Arabia

    End-to-end ISO 27001 consulting for organisations preparing for certification: gap assessments, ISMS build, internal audit, and external-audit support. Also worked across ISO 9001, 42001, 45001, 20000-1 and 14001 where the engagement required it.

    Engagement detail
  4. Jan 2024 — Sep 2024

    Cyber Security Analyst · Scorpbit Technologies

    Security analyst work spanning policy, ISMS documentation, audit evidence, and hands-on vulnerability assessment. The brief was to make the security programme something an auditor could follow, and a tester could break.

    Engagement detail
  5. Jan 2024 — Mar 2024

    Cyber Security trainee · Knowledge Streams

    Three-month cyber security bootcamp built around PortSwigger labs and TryHackMe. Web application security, reconnaissance, and the habit of writing findings so someone else can act on them.

    Engagement detail
  6. Oct 2023 — Jan 2024

    Lecturer · SZABIST

    Lectured on routing and switching with Packet Tracer in the room, not only on the slide. The aim was that students could configure a path, not just name the protocol.

    Engagement detail
  7. Jul 2023 — Jan 2024

    Cyber Security Analyst · Syntax Technologies

    Cyber security analyst at Syntax — findings, controls, and the security work that sat next to delivery rather than in a binder on the side.

    Engagement detail

Organisations

Where I’ve worked

Select an organisation to read the full engagement: scope, responsibilities, focus areas, and the tooling behind it.

7 engagements

AT

Adrem Technologies

Information Security and IT Audit Consultant

Information security and IT audit consultant at Adrem Technologies Middle East. Running the ISO 27001 programme — KPIs, disaster recovery, and external audits — plus IT audits, penetration testing, and data privacy under PDPL.

Aug 2026 — Present Current role
KP

KPMG Pakistan

IT Audit Associate 2

Eight months at KPMG on GITC and ITAC assessments inside financial-statement and SOX-style audits. The book included telecom, NADRA (national database), oil and gas, and overseas assignments. Left in August 2026.

Dec 2025 — Aug 2026 IT audit
IA

ISO Arabia

ISO 27001 Consultant

End-to-end ISO 27001 consulting for organisations preparing for certification: gap assessments, ISMS build, internal audit, and external-audit support. Also worked across ISO 9001, 42001, 45001, 20000-1 and 14001 where the engagement required it.

Oct 2024 — Nov 2025 50+ clients
SB

Scorpbit Technologies

Cyber Security Analyst

Security analyst work spanning policy, ISMS documentation, audit evidence, and hands-on vulnerability assessment. The brief was to make the security programme something an auditor could follow, and a tester could break.

Jan 2024 — Sep 2024 ISMS + VAPT
KS

Knowledge Streams

Cyber Security trainee

Three-month cyber security bootcamp built around PortSwigger labs and TryHackMe. Web application security, reconnaissance, and the habit of writing findings so someone else can act on them.

Jan 2024 — Mar 2024 Bootcamp
SZ

SZABIST

Lecturer

Lectured on routing and switching with Packet Tracer in the room, not only on the slide. The aim was that students could configure a path, not just name the protocol.

Oct 2023 — Jan 2024 Teaching
SX

Syntax Technologies

Cyber Security Analyst

Cyber security analyst at Syntax — findings, controls, and the security work that sat next to delivery rather than in a binder on the side.

Jul 2023 — Jan 2024 Cyber

Projects

Tests, research, and control mapping.

VAPT

Web application penetration test

View case study

Full-scope test of a production website: recon, authenticated and unauthenticated paths, and a report the engineering team could actually schedule against.

  • Tooling: Nmap, Gobuster, Burp Suite, SQLMap.
  • Findings included reflected and stored XSS, IDOR, file inclusion, RCE, weak encryption, and SQL injection.
  • Delivered a written report with remediation, not a screenshot dump.

Research

Router brute-force research

View case study

Research on hardening routers against brute-force authentication, including the use of algebraic properties in the auth path. Written for operators, vendors, and anyone who still ships a default password.

  • Audience: network admins, manufacturers, researchers, policymakers.
  • Applied commutative and associative properties to authentication design.
  • Emphasis on practical controls, not only the maths.

GRC

NIST CSF mapping for SaaS APIs

View case study

Part-time control mapping of the NIST Cybersecurity Framework to SaaS applications and their APIs. Over 50 applications aligned so cloud estates had a common language with the framework.

  • NIST CSF controls mapped to application and API surfaces.
  • Coverage across 50+ SaaS products.
  • Used for compliance alignment and a clearer security posture in cloud.

Skills

Technical skills and how the work actually runs.

Technical

18
  • ISO 27001
  • ISO 27701
  • ISO 42001
  • PDPL
  • GITC
  • ITAC
  • SOX
  • Internal audit
  • Gap assessments
  • ISMS implementation
  • Disaster recovery
  • Penetration testing
  • Nmap
  • Burp Suite
  • SQLMap
  • Nessus
  • OWASP ZAP
  • CCNA

Practice

8
  • Audit reporting
  • Evidence discipline
  • Stakeholder workshops
  • Control ownership
  • Risk treatment
  • Policy writing
  • Teaching
  • Operations

Certifications

Certificates that sit behind the file.

  • Certified Ethical Hacker (CEH) EC-Council
    Sep 2025 — Nov 2025
  • ISO 27001 Lead Auditor SGS
    Feb 2026
  • ISO 42001 Lead Implementer — AI MS SGS
    Sep 2025
  • ISO 27701 Lead Auditor SGS
  • Cyber security & web pentesting Knowledge Streams
    Jan — Mar 2024
  • CCNA Corvit Rawalpindi
    Jan 2018

Education

The degrees underneath the work.

Masters in Cyber Security

SZABIST Islamabad

Islamabad · Feb 2023 — Jan 2026

Bachelor in Computer Science

Capital University of Science and Technology

Islamabad · Feb 2018 — Jan 2023

Need an audit, a gap assessment, or a second opinion?

ISO 27001, internal audit, GITC/ITAC, or a scoped test. Short brief. Straight reply.