Data security and privacy
Data protection requirements, DLP policy design, access and sharing controls, privacy risk, and evidence of control effectiveness.
Founder · Security advisor · Product builder
Data security and AI governance
I help organisations turn security, privacy and AI governance requirements into practical controls and evidence they can rely on.
01 / Expertise
My work combines architecture assurance, privacy engineering and risk management with experience leading client programmes and building trust software.
Data protection requirements, DLP policy design, access and sharing controls, privacy risk, and evidence of control effectiveness.
AI use-case risk, accountability, human oversight, supplier due diligence and assurance requirements informed by ISO/IEC 42001.
Discovery workshops, control design, implementation priorities, stakeholder alignment, audit coordination and clear residual-risk decisions.
Microsoft Purview programme focus
I bring policy design, privacy and risk assessment, stakeholder engagement and control validation to Purview Information Protection, DLP and Copilot data-security workstreams. This builds on my established architecture and assurance experience.
02 / International experience
January 2011 – October 2014
Manager, Risk Assurance. UK client engagement, control assessment and assurance reporting.
Banking · Transport · Government · Technology
National programme advisory, supplier security, architecture reviews and fractional security leadership.
PwC · Deloitte · Grant Thornton
IT advisory, risk assurance and cyber consulting, progressing to Associate Director.
Lead Security Advisor, NTS Programme
Security advisory, system-level risk assessment and residual-risk advice for the National Ticketing Solution programme and public transport integration.
Principal Security Advisor
Third-party risk framework, supplier security assessments, control design and risk reporting across transport technology.
Senior Cyber Security Architect
Architecture assurance and vendor security advice for high-availability enterprise platforms, aligned with NIST 800-53.
Fractional Security and Compliance Officer
SOC 2 audit coordination, control and evidence readiness, privacy and security policies, and vendor risk assessments.
Senior Information Security Consultant
More than 100 critical-supplier security assessments, IAM assurance supervision and senior-leadership risk reporting.
Associate Director, Risk Consulting Cyber
Senior Manager, Risk Assurance
Associate Director, IT Advisory and Cyber Security
Manager, Risk Assurance
Senior Consultant, Risk and Regulatory Services
Senior Analyst, Enterprise Risk Services
Some consulting appointments overlap. CybrGen and MyTrustForge are concurrent founder-led activities. Earlier Auckland Transport reviews took place in 2019 and 2024.
03 / Selected assurance work
Examples are summarised without confidential client architecture or supplier details.
Identified that a symmetric JWT signing design lacked a shared-secret distribution approach. The design subsequently changed to asymmetric signing.
Focus: key distribution and trust boundaries.
Challenged proposed 24-hour confirmation codes and email-based MFA, recommending shorter token lifetimes and stronger authentication controls.
Focus: practical safeguards against credential misuse.
Completed more than 100 critical-supplier assessments using CPS 234, NZISM and ISO 27001-aligned criteria, with senior-leadership reporting.
Focus: evidence, treatment priorities and residual risk.
04 / Professional foundation
Lead Auditor
AI management systemsCertified Data Privacy Solutions Engineer
Privacy and data protectionCertified in Risk and Information Systems Control
Technology risk and controlsCertified Ethical Hacker
Security assessmentPost Graduate Diploma in Business Administration
ICFAI Business School, Hyderabad, India
Bachelor of Science
Nagarjuna University, Andhra Pradesh, India
05 / Founder and product perspective
I founded MyTrustForge to connect framework requirements with reusable controls, risks, ownership and evidence. My product work includes AI readiness and AI-assisted policy generation.
Illustrative delivery approach. Any use alongside Purview would be scoped to complement the client’s existing tools; this does not represent an existing product integration.
Client engagements and delivery partnerships
Based in Auckland, with UK and New Zealand delivery experience and an engagement focus across the UK, Australia and New Zealand.