A detail-oriented GRC professional bringing 7 years of banking and insurance experience — applying a risk mindset to assessments, control mapping and practical recommendations across ISO 27001, NIST CSF 2.0 and Essential Eight.
Background
I am building a career in cybersecurity Governance, Risk and Compliance, bringing 7 years of banking and insurance experience — and a detail-oriented risk mindset — into the field.
Through hands-on projects I have worked across ISO 27001, NIST CSF 2.0 and Essential Eight — assessing risks, mapping controls and developing practical recommendations. This portfolio showcases my GRC project work as I grow in this space.
Work
A full cybersecurity GRC assessment of Oscorp evaluating their security posture against ISO 27001 and NIST CSF 2.0, with a gap analysis, risk register and prioritised remediation roadmap.
Oscorp is a technology and research organization with an established IT function but limited cybersecurity maturity. While the organization has invested in foundational IT controls such as business continuity, network security and physical security, significant gaps exist across critical cybersecurity domains including identity and access management, detection and response, vulnerability management and third party risk.
Reviewed Oscorp's existing security controls across all key domains — documenting what is in place, what is working well and areas of concern. This formed the foundation for all subsequent analysis.
Compared Oscorp's controls against ISO 27001 and NIST CSF 2.0 requirements, rating each gap as Critical, High, Medium or Low. Key findings included the absence of MFA, no SIEM capability, shared admin passwords and no formal vulnerability management program.
Identified the top 13 cybersecurity risks facing Oscorp, scored by likelihood and impact (1-5). Each risk includes the threat, current control and recommended control. Critical and High risks require immediate leadership attention.
A prioritised roadmap organised into immediate, short-term and medium-term timeframes, mapped to NIST CSF 2.0 and ISO 27001. Recommended for board-level presentation given the number of critical gaps identified.
A full Essential Eight assessment of the National Benefits Delivery Agency (NBDA), a fictional Australian Government organisation with 1,500 staff. I played the role of GRC Analyst — conducting a structured interview with the IT Manager across all 8 strategies, collecting and reviewing evidence documents, identifying red flags, rating each strategy against the ASD Essential Eight Maturity Model, and producing a findings report with practical recommendations.
NBDA is a fictional Australian Government agency that delivers welfare payments and support services to 1,500 staff across 4 states. Their IT environment is hybrid — on-premise servers plus Microsoft 365 cloud. The assessment used the ASD Essential Eight Maturity Model as the framework, rating each strategy from ML0 to ML3. The overall result was ML1 — below the ML2 requirement expected of Australian Government agencies.
Full assessment report covering all 8 strategies — interview questions, evidence reviewed, red flags identified, maturity ratings, gaps, and recommendations for the National Benefits Delivery Agency.
A formal Third Party Risk Assessment conducted in the role of GRC Analyst at Meridian Health Group (MHG), a fictional Australian healthcare organisation. With the contract for telehealth vendor CareConnect Telehealth Pty Ltd due for renewal in 60 days, I assessed whether CareConnect was a safe and compliant custodian of MHG patient data — sending a vendor security questionnaire, reviewing responses and supporting evidence, identifying red flags, producing a risk rating, and delivering recommendations to the CISO. The assessment was framed under the Privacy Act and the Notifiable Data Breaches scheme.
CareConnect Telehealth Pty Ltd is a cloud-based telehealth platform (80 staff, Sydney-based, hosted on AWS Sydney) providing GP video consultations, specialist referrals, and patient messaging to MHG. The vendor holds highly sensitive patient data including names, Medicare numbers, health conditions, consultation recordings, and referral letters — classified as Critical risk. Annual SaaS contract renewal was due in 60 days.
Full assessment report including vendor profile, security questionnaire responses, red flags identified, risk rating, and recommendations for the CISO on whether to renew the CareConnect contract.
Expertise
GRC Frameworks
GRC Capabilities
Domain Knowledge
Certifications
Get In Touch
Interested in collaborating or have a GRC opportunity? I would love to connect.