06/08/2026 updated
PL
100 % available
Enterprise Security & GRC Architect | ServiceNow IRM Architect | Global Control Framework Leader
Warrington, England, United Kingdom
Worldwide
Professional Certifications: ISO27001 Lead Implementer, Lead Auditor & Internal Auditor; Certified Data Privacy Solutions Engineer (CDPSE)About me
Enterprise GRC Architect, ISO 27001 Lead Consultant and ServiceNow IRM Architect with 25+ years' experience. Led the world's largest ISO 27001 programme (70+ countries, 300+ sites). Specialist in NIS2, DORA, cyber risk, governance, compliance and operational resilience.
ISO/IEC 27001Iso/iec
Enterprise Security Governance & GRC Architecture
Expertise in designing and implementing enterprise security governance frameworks, global control framework architecture, and GRC capabilities across critical infrastructure and highly regulated environments, including the world's largest ISO/IEC 27001 certification programme spanning 70+ countries and 300+ locations.
ServiceNow IRM Architecture
Deep technical expertise in ServiceNow IRM, architecting enterprise GRC data models and governance architectures including UCF-aligned common control frameworks, authority documents, compliance models, entity hierarchies, policies, issue management models, and risk models.
Regulatory Compliance & Cyber Risk Management
Extensive knowledge of international regulatory frameworks including ISO/IEC 27001:2022, NIST CSF 2.0, EU NIS2 Directive, DORA, Cyber Resilience Act, PCI-DSS, GDPR, CMMC 2.0, NERC CIP, and MLPS 2.0, enabling consistent governance and compliance assurance across global business units.
Global Common Control Framework Design
Design and implementation of a Global Common Control Framework (CCF) aligning 30+ international security, privacy, resilience, and regulatory standards, enabling standardised control validation and multi-standard compliance assessment across organisations.
Operational Resilience & Critical Infrastructure Protection
Delivery of cybersecurity governance and assurance programmes supporting critical national infrastructure, including authoring Covered Information Protection Plans under U.S. National Security Agreement requirements aligned to NIST SP 800-171 Rev. 3 and OT security controls.
ISO/IEC 27001 Audit & Certification Programmes
Certified ISO27001 Lead Implementer, Lead Auditor, and Internal Auditor with hands-on experience recovering and delivering delayed surveillance audit programmes, conducting gap analysis, internal audits, and validating compliance with ISO/IEC 27001 Clauses 4-10 and Annex A controls.
Supplier Assurance & Third-Party Cyber Risk
Establishment of Supplier Assurance Frameworks to assess and manage third-party cyber risk, including supplier security due diligence questionnaires aligned to ISO/IEC 27001 controls and leveraging SecurityScorecard for independent external security posture assessment.
Board-Level Cyber Risk Reporting & Governance Dashboards
Development of board-level cyber risk reporting including enterprise risk heatmaps, governance dashboards, compliance reporting, and executive cybersecurity dashboards for global cybersecurity leadership and C-Suite visibility.
OT Security & Identity Security
Subject matter expertise across Operational Technology (OT) security within global enterprise and critical infrastructure environments, as well as implementation of Privileged Access Management (PAM) solutions such as Thycotic to secure privileged accounts and enforce least-privilege access principles.
Data Protection & Privacy
Certified Data Protection Officer (C-DPO) and Certified Data Privacy Solutions Engineer (CDPSE) with expertise in GDPR, ISO27701 PIMS, California Consumer Privacy Act (CCPA), Japan APPI, and EU AI Act, supporting privacy governance and data protection compliance.
Expertise in designing and implementing enterprise security governance frameworks, global control framework architecture, and GRC capabilities across critical infrastructure and highly regulated environments, including the world's largest ISO/IEC 27001 certification programme spanning 70+ countries and 300+ locations.
ServiceNow IRM Architecture
Deep technical expertise in ServiceNow IRM, architecting enterprise GRC data models and governance architectures including UCF-aligned common control frameworks, authority documents, compliance models, entity hierarchies, policies, issue management models, and risk models.
Regulatory Compliance & Cyber Risk Management
Extensive knowledge of international regulatory frameworks including ISO/IEC 27001:2022, NIST CSF 2.0, EU NIS2 Directive, DORA, Cyber Resilience Act, PCI-DSS, GDPR, CMMC 2.0, NERC CIP, and MLPS 2.0, enabling consistent governance and compliance assurance across global business units.
Global Common Control Framework Design
Design and implementation of a Global Common Control Framework (CCF) aligning 30+ international security, privacy, resilience, and regulatory standards, enabling standardised control validation and multi-standard compliance assessment across organisations.
Operational Resilience & Critical Infrastructure Protection
Delivery of cybersecurity governance and assurance programmes supporting critical national infrastructure, including authoring Covered Information Protection Plans under U.S. National Security Agreement requirements aligned to NIST SP 800-171 Rev. 3 and OT security controls.
ISO/IEC 27001 Audit & Certification Programmes
Certified ISO27001 Lead Implementer, Lead Auditor, and Internal Auditor with hands-on experience recovering and delivering delayed surveillance audit programmes, conducting gap analysis, internal audits, and validating compliance with ISO/IEC 27001 Clauses 4-10 and Annex A controls.
Supplier Assurance & Third-Party Cyber Risk
Establishment of Supplier Assurance Frameworks to assess and manage third-party cyber risk, including supplier security due diligence questionnaires aligned to ISO/IEC 27001 controls and leveraging SecurityScorecard for independent external security posture assessment.
Board-Level Cyber Risk Reporting & Governance Dashboards
Development of board-level cyber risk reporting including enterprise risk heatmaps, governance dashboards, compliance reporting, and executive cybersecurity dashboards for global cybersecurity leadership and C-Suite visibility.
OT Security & Identity Security
Subject matter expertise across Operational Technology (OT) security within global enterprise and critical infrastructure environments, as well as implementation of Privileged Access Management (PAM) solutions such as Thycotic to secure privileged accounts and enforce least-privilege access principles.
Data Protection & Privacy
Certified Data Protection Officer (C-DPO) and Certified Data Privacy Solutions Engineer (CDPSE) with expertise in GDPR, ISO27701 PIMS, California Consumer Privacy Act (CCPA), Japan APPI, and EU AI Act, supporting privacy governance and data protection compliance.
Languages
EnglishNative speaker
Project history
Lead consultant and architect for the world's largest ISO/IEC 27001 certification programme spanning 70+ countries and 300+ locations. Designed and implemented a Global Common Control Framework (CCF) aligning multiple international standards. Architected enterprise cyber risk model in ServiceNow IRM, developed board-level cyber risk reporting, authored global information security policies and standards, and delivered cybersecurity governance supporting U.S. National Security Agreement requirements.
Field Service Engineer specialising in Windows technologies for IBM for approximately 2 years.
Assistant IT Helpdesk Manager at Railtrack for approximately 1 year.