20+ years of experience spanning networking, security architecture, and cloud, now focused on building private and sovereign AI cloud infrastructure for enterprises. I advise on security architecture, controls review, and hardening — helping enterprises become audit-ready and compliant (ISO, SOC, RBI).
AI Sovereign Cloud — a sovereign, multi-tenant cloud + governed AI platform, architected and largely built through agentic engineering.
Startups and SMBs on AI-driven security architecture, cloud automation, and SOC/compliance readiness — most recently led a FinTech and Property Tech company's ISO 27001 & SOC 2 programme from zero.
A sovereign, multi-tenant cloud deployed on-premises, extended into a governed on-prem AI platform. Owned end-to-end: architecture, implementation across six services, and security.
Led the company's first ISO/IEC 27001:2022 and SOC 2 Type 2 certification programme end-to-end — from zero formal ISMS to a governance-ready documentation set, ahead of the external consultancy kickoff.
| ISMS core | Scope Statement, Information Security Policy, Roles & Responsibilities, Risk Management Policy & Methodology, Risk Treatment Plan, Objectives, Control of Documented Information, Internal Audit Programme, Management Review, Nonconformity & Corrective Action — clauses 4–10 in full. |
| Registers | Risk Register (30 scored risks), Statement of Applicability (all 93 Annex A:2022 controls), ISO 27001↔SOC 2 Control Matrix, Policy Register, Legal & Regulatory Register, Findings Remediation Tracker (25 findings). |
| Governance | Steering Committee Terms of Reference, Agenda & Minutes with a batch-approval Annex satisfying clause 7.5.2. |
| SOC 2 | Trust Services Categories Selection Memo, System Description (Section III). |
| Control policies (17) | Access Control, Cryptography & Key Management, Information Classification, Data Retention & Deletion, Data Protection & Privacy, Incident Management, Supplier & Third-Party Security, Secure SDLC, Change Management, Logging & Monitoring, Vulnerability & Patch Management, Backup & Recovery, Malware Protection, Endpoint Security, Network Security, BC/DR, Physical & Environmental Security. |
| People | HR Security, Acceptable Use, Remote Working, Security Awareness & Training. |
Full-stack product security across DigiBanking, Wallet, Payments, and Subscriptions — application & API security, distributed systems, security orchestration, and joint-venture security integrations across regional Fin-Tech partners.
20 years in network & IoT security, threat defense, software-defined access, and enterprise blockchain — architecting security into the network layer itself.