Information Security Officer · CISSP · GRC & Security Programme Leadership

I build and lead security programmes organisations can actually rely on.

8+ years across security operations, GRC, ISO 27001 audits, and incident response, from averting live ransomware to designing certifications trusted by 7M+ users. CISSP-certified. M.Sc., Carnegie Mellon. Open to senior security-leadership roles, remote-first or EMEA.

Open to senior security roles · Remote / EMEA

  • CISSP
  • ISO 27001
  • NIST 800-53
  • M.Sc. Carnegie Mellon
Raha Mawazo, Information Security Officer
8+Years in information security
7M+Users on certifications I helped build
10Enterprise ISO 27001 audit clients
20+Systems recovered from a live ransomware attack

Portfolio

Work that proves it.

All projects
Flagship
Governance & GRC

Lighthouse — GRC Platform

In progress · MVP, Phase 1 · target Aug 2026

A minimalist, opinionated GRC platform for small-to-mid SaaS companies — risk register, control-framework mapping (ISO 27001 / NIST CSF / SOC 2), third-party risk, evidence collection, and audit management in one place, with plugins for AWS Security Hub, MISP, and Slack.

Proves: ISO 27001 / SOC 2 programme design · control-framework mapping · TPRM · threat-informed risk (MISP) · evidence automation · executive dashboards.

  • Python
  • FastAPI
  • PostgreSQL
  • React
  • TypeScript
  • Docker
Read the case study →
Incident Response

IR Tabletop & Playbook Library

Published · public on GitHub

A public tabletop-exercise pack and IR playbook library — 10 scenarios across 5 industries and 5 jurisdictions, built on 5 threat-based playbooks (ransomware, data exfiltration, BEC / payment fraud, OT / cyber-physical, payment-card / POS), each with jurisdiction-specific regulatory annexes. Designed so a small security team can run any scenario unmodified.

Proves: IR programme leadership & facilitation · crisis communication · multi-jurisdiction regulatory breadth (POPIA, UK FCA/ICO, GDPR, Australia NDB, PCI-DSS) · operational documentation.

  • Incident Response
  • Playbooks
  • Tabletop
  • Multi-jurisdiction
View on GitHub →

Writing

Notes from the programme.

All writing

Credentials

Certified, and still shipping.

CISSP, an M.Sc. from Carnegie Mellon, and a working command of the frameworks that carry an audit. The full record — certifications, skills, and experience — lives on the about page.

See full background
  • CISSPISC2
  • M.Sc. CybersecurityCarnegie Mellon
  • ISO 27001Lead auditor experience
  • Certified Incident ResponderINE

Get in touch

Hiring for a senior security seat?

I review every inbound personally and respond within one business day.