ISO 27001 implementation
Gap assessment, ISMS build, internal audit and certification readiness — written so a certification body can sample it.
Learn moreIT Audit · ISO 27001 · CEH
Information security and IT audit consultant at Adrem Technologies. ISO 27001, IT audit, pentest and PDPL — previously KPMG, and 50+ clients certified to ISO 27001.
Most people pick a lane: GRC paperwork, or a pentest report. The useful work sits in the overlap — controls that operate, evidence that exists, and a finding someone can close.
That is the through-line from 50+ ISO 27001 certifications to GITC files at KPMG and the ISMS at Adrem Technologies: a control an auditor can sample, not a slide pack they have to take on trust.
Gap assessment, ISMS build, internal audit and certification readiness — written so a certification body can sample it.
Learn moreAccess, change and operations tested inside live audit files. Design and operating effectiveness, not a slide pack.
Learn moreWalkthroughs, sampling and reports the external auditor will actually read. Findings with owners and dates.
Learn moreScoped tests with Burp, Nmap and the rest — then a remediation report engineering can schedule against.
Learn moreExperience
Aug 2026 — Present
Information security and IT audit consultant at Adrem Technologies Middle East. Running the ISO 27001 programme — KPIs, disaster recovery, and external audits — plus IT audits, penetration testing, and data privacy under PDPL.
Engagement detailDec 2025 — Aug 2026
Eight months at KPMG on GITC and ITAC assessments inside financial-statement and SOX-style audits. The book included telecom, NADRA (national database), oil and gas, and overseas assignments. Left in August 2026.
Engagement detailOct 2024 — Nov 2025
End-to-end ISO 27001 consulting for organisations preparing for certification: gap assessments, ISMS build, internal audit, and external-audit support. Also worked across ISO 9001, 42001, 45001, 20000-1 and 14001 where the engagement required it.
Engagement detailJan 2024 — Sep 2024
Security analyst work spanning policy, ISMS documentation, audit evidence, and hands-on vulnerability assessment. The brief was to make the security programme something an auditor could follow, and a tester could break.
Engagement detailJan 2024 — Mar 2024
Three-month cyber security bootcamp built around PortSwigger labs and TryHackMe. Web application security, reconnaissance, and the habit of writing findings so someone else can act on them.
Engagement detailOct 2023 — Jan 2024
Lectured on routing and switching with Packet Tracer in the room, not only on the slide. The aim was that students could configure a path, not just name the protocol.
Engagement detailJul 2023 — Jan 2024
Cyber security analyst at Syntax — findings, controls, and the security work that sat next to delivery rather than in a binder on the side.
Engagement detailOrganisations
Every mark opens a page. Colour stays on a white tile so the logos stay readable on the dark layout.
Organisations
Select an organisation to read the full engagement: scope, responsibilities, focus areas, and the tooling behind it.
7 engagements
Information Security and IT Audit Consultant
Information security and IT audit consultant at Adrem Technologies Middle East. Running the ISO 27001 programme — KPIs, disaster recovery, and external audits — plus IT audits, penetration testing, and data privacy under PDPL.
IT Audit Associate 2
Eight months at KPMG on GITC and ITAC assessments inside financial-statement and SOX-style audits. The book included telecom, NADRA (national database), oil and gas, and overseas assignments. Left in August 2026.
ISO 27001 Consultant
End-to-end ISO 27001 consulting for organisations preparing for certification: gap assessments, ISMS build, internal audit, and external-audit support. Also worked across ISO 9001, 42001, 45001, 20000-1 and 14001 where the engagement required it.
Cyber Security Analyst
Security analyst work spanning policy, ISMS documentation, audit evidence, and hands-on vulnerability assessment. The brief was to make the security programme something an auditor could follow, and a tester could break.
Cyber Security trainee
Three-month cyber security bootcamp built around PortSwigger labs and TryHackMe. Web application security, reconnaissance, and the habit of writing findings so someone else can act on them.
Lecturer
Lectured on routing and switching with Packet Tracer in the room, not only on the slide. The aim was that students could configure a path, not just name the protocol.
Cyber Security Analyst
Cyber security analyst at Syntax — findings, controls, and the security work that sat next to delivery rather than in a binder on the side.
Projects
Full-scope test of a production website: recon, authenticated and unauthenticated paths, and a report the engineering team could actually schedule against.
Research on hardening routers against brute-force authentication, including the use of algebraic properties in the auth path. Written for operators, vendors, and anyone who still ships a default password.
Part-time control mapping of the NIST Cybersecurity Framework to SaaS applications and their APIs. Over 50 applications aligned so cloud estates had a common language with the framework.
Skills
Certifications
Education
SZABIST Islamabad
Capital University of Science and Technology
ISO 27001, internal audit, GITC/ITAC, or a scoped test. Short brief. Straight reply.