Director / Principal Consultant
Greater London, UK ยท Hybrid
- Founder of a specialist consultancy providing security architecture, technology risk management, and AI transformation services to clients in Fintech, Banking, and Insurance. All subsequent contract roles from March 2015 onward were delivered through ENFTC.
- AI-Compliance Platform โ Founder & Product Lead (Jan 2026 โ Present): Designed and built a multi-tenant EU AI Act compliance assessment platform mapping 55 EU AI Act obligations against 110 ISO/IEC 42001 & NIST AI RMF controls โ with deterministic risk classification, LLM-assisted evidence review, penalty-tier-weighted scoring, and automated regulatory deadline monitoring. 55 obligations ยท 110 controls ยท 48 API endpoints
- Compliance Engine โ Regulation-to-Control Mapping (2026): Built a CLI/database engine mapping 2,167 regulatory requirements across 15 frameworks โ DORA with all 6 Level 2 RTS, PCI DSS 4.0.1, NIST CSF 2.0, ISO 27001:2022, UK FCA/PRA โ to 487 implementation controls (CIS Controls v8.1.2, NIST SP 800-53r5) with 4,679 verified mappings, dual-engine automated validation (1,359 Checkov + 916 Rego/OPA policies), and auditor-ready evidence mapping. 2,167 reqs ยท 487 controls ยท 2,275 policies
- LLM-Assisted Review Engineering: Engineered a structured LLM review pipeline with JSON-mode output validation, prompt-injection defence, and per-review cost telemetry; developed end-to-end using AI-assisted development workflows (Claude Code).
- Production Hardening: Led the production hardening cycle โ repairing PostgreSQL row-level security, migration-chain, and async-worker defects that SQLite-only testing had masked; delivered 430 automated tests and a CI pipeline verifying multi-tenant isolation against real PostgreSQL on every push. 430 automated tests
- Architected RAG-model solutions using Large Context Window LLMs to automate policy uplift and regulatory compliance mapping, achieving up to 85% automation rates.
- Delivered Compliance-as-Code frameworks integrating regulatory checks into CI/CD pipelines for major financial institutions.
Technology Risk & Regulatory Compliance SME
City of Westminster, London, UK ยท Hybrid
- DORA Compliance Programme: Spearheaded the DORA implementation programme by architecting a RAG-model solution (using Large Context Window LLMs) to automate policy uplift, ensuring accurate coverage of IT Asset, Change, Access Management, and Vulnerability Management standards. Automated 85% of compliance mapping
- Compliance as Code: Designed a full set of automated controls, working with DevOps teams to integrate regulatory compliance checks early in the CI/CD pipeline for all major projects.
- Regulatory Remediation (PAM): Remediated critical, long-standing Privileged Access Management (PAM) non-compliance, bridging Technical/CISO teams and Regulatory Auditors to close a multi-year audit finding. The external auditor validated the remediation and the regulator subsequently lifted all new client onboarding restrictions. โ
Restrictions lifted
- Resilience Strategy: Partnered with the CIO to map key business services and dependencies, delivering a prioritized Business Continuity Planning (BCP) and Technology Resilience strategy. BCP & Resilience plan delivered
Technology Risk Consultant
City of London, UK
- Led validation of a major risk remediation programme, ensuring all critical findings were properly addressed and control gaps closed.
- Conducted a comprehensive technology risk and controls framework review, identifying areas for improvement in the control environment.
- Assessed policy compliance against regulatory requirements and internal standards, providing actionable remediation recommendations.
Subject Matter Expert โ Technology Risk & Architecture
Greater London, UK ยท Remote
- Cloud Security Architecture: Conducted end-to-end security architecture and control assessments for a large insurance firm's migration to Microsoft Azure (2,500+ VMs), identifying and remediating compliance gaps.
- Challenger Bank Resilience: Defined data management strategies and cyber resilience scenario testing for a challenger bank, ensuring protection against insider threats and compliance with GDPR.
- Algorithmic Trading Audit: Performed a comprehensive cybersecurity review of a Fintech trading firm to ensure IP protection and MIFID II compliance.
Technology Risk & Security Architecture SME
Greater London, UK / Zurich, Switzerland ยท Hybrid
- Cost Reduction: Coordinated external audit efforts throughout Group Technology, implementing a standardized audit response framework that reduced overall audit costs to UBS by ~40%. ~40% cost reduction
- Cloud Migration Risk: Performed risk assessments for file transfer technologies migrating to cloud (Azure, AWS), identifying 23 compliance gaps and defining remediation roadmaps.
- Regulatory Change Management: Managed requirements for MAS TRM and HKMA TPRM, defining remediation roadmaps for non-production environments and insider threat monitoring.
- Control Implementation: Validated the sustainability of data protection controls for internal auditors and closed critical risk issues related to data corruption detection.
Interim Head of IT Audit โ CIO Global
Greater London, UK ยท Hybrid
- Led the global audit function for the CIO domain, covering infrastructure, architecture, strategy, and resilience across all business units.
- Defined the IT Audit universe and developed a risk-based multi-year audit plan, ensuring comprehensive coverage of critical technology risks.
- Coached and developed the audit team to improve delivery quality and strengthen stakeholder relationships across the organization.
Infrastructure & Security Architect
Greater London, UK ยท Hybrid
- Designed and implemented a technology infrastructure compliance framework integrated into the SDLC, ensuring security controls were embedded from design through deployment.
- Enforced compliance across ~800 on-premise and MS Azure assets across US, UK, Switzerland, and Singapore, covering Access Control, Cryptography, and Vulnerability Management.
Core IT Audit Director โ Technology Risk SME
Greater London, UK ยท On-site
- Executed high-profile audits within Cyber Security Governance, Data Governance (BCBS 239), and Middleware, delivering actionable findings to senior management.
- Assessed the "Cyber Security by Design" framework, reviewing secure development controls for infrastructure and applications to ensure alignment with regulatory expectations.
Infrastructure Security Architecture & Audit SME (via ENFTC)
Greater London, UK ยท On-site
- Delivered end-to-end audits of security architecture design across the Group's infrastructure, including Linux, Windows, IBM Mainframe, and HPE Non-Stop platforms.
- Identified critical gaps in privileged access, event logging, and patch management, driving significant improvements in the Group's overall security posture.
Technology Risk Advisory
London, UK
- Delivered technology risk advisory services to financial services clients, focusing on IT controls assessment and regulatory compliance.
Senior IT Audit Manager
Belgium ยท On-site
- Managed complex IT audit engagements across the Euroclear Group, covering critical financial market infrastructure and settlement systems.
- Developed audit methodologies and mentored junior team members, building a high-performing audit function.
Head of IT Risk & Controls
Brussels Region, Belgium
- Established and led the IT risk and controls function, designing control frameworks aligned with regulatory requirements for banking operations.
IT Controls Director
Istanbul, Turkey
- Directed IT controls operations, ensuring compliance with banking regulations and internal control standards.
Senior IT Auditor
Istanbul, Turkey
- Conducted IT audits across banking systems and infrastructure, identifying control weaknesses and providing practical remediation recommendations.