Adedeji Michael Cybersecurity, GRC & AI Governance Leader
12+ years building and running enterprise security programmes — board risk strategy, ISO 27001 / SOC 2 / PCI DSS audit delivery, SOC operations and P1/P2 major incident command, cloud security across AWS & Microsoft 365, and ISO 42001-aligned AI governance. I turn technical risk into commercial decisions, and compliance obligations into controls that actually hold up at audit.
The Numbers Behind The Work
Every figure below comes directly from delivered enterprise engagements and defensible audit outcomes.
Six Core Delivery Areas
One career, six angles. Whichever problem you have, the underlying work is the same: make the risk visible, design controls that survive scrutiny, and get them running.
vCISO & Security Leadership
Acting as the most senior security voice — strategy and roadmap, policy stack, steering committee, vendor and MSSP oversight, monthly executive and board reporting.
IT & Cyber Audit Defence
CISA-certified end-to-end audit delivery — risk-based planning, fieldwork, workpapers, findings, and tracking remediation through to closure. Government-grade NIST 800-53 assessments supporting ATO decisions.
Security Operations (SecOps)
SOC leadership and detection engineering in Microsoft Sentinel and Defender XDR, 24/7 coverage through managed partners, P1/P2 major incident command, and KPI-driven operational improvement.
GRC & Regulatory Compliance
Reading dense regulation and turning it into controls and plain-English guidance teams can act on — ISO 27001/27701, SOC 2, PCI DSS v4.0, UK GDPR, and Cyber Essentials Plus.
Cloud & Microsoft Security
Purview DLP and sensitivity labels, Entra ID Conditional Access, PIM and RBAC, AWS Zero Trust re-architecture, and backup/DR resilience design with Vault Lock and infrastructure as code.
AI Governance & Continuous GRC
ISO 42001-aligned frameworks mapped to ISO 27001/27701, EU AI Act readiness, AI risk classification and DPIA for AI systems — plus AI-driven compliance automation with proprietary IP.
Case Studies & Delivery Stories
Client names withheld. Real engineering, architectural and audit transformations.
Zero Trust Cloud Security Re-Architecture
An AWS estate had grown organically across accounts. Misconfigurations kept recurring, cloud spend was escalating without governance, and the estate could not evidence the control posture needed for ISO 27001 or enterprise customer due diligence — putting live deals at risk.
Designed and led a Zero Trust re-architecture against CIS Benchmarks: hardened IAM and network configuration, implemented guardrails and continuous posture monitoring, embedded the controls into the ISO 27001 framework, and aligned identity strategy across cloud and Microsoft 365.
- 50% fewer cloud misconfigurations (Zero Trust + CIS Benchmarks)
- 35% reduction in redundant cloud infrastructure costs
- 92% control compliance achieved during ISO 27001 certification
- Customer due diligence cleared without findings, unblocking key revenue
AI-Driven Continuous GRC Automation
Evidence collection, control testing, and exception tracking were manual and repetitive — consuming analyst capacity and producing inconsistent audit evidence that slowed every certification cycle.
Architected AI-powered GRC automation that converted point-in-time evidence gathering into continuous monitoring with executive dashboards, and filed intellectual property covering the approach.
- 65% reduction in compliance & audit workload via AI-driven GRC
- Materially higher evidence quality with continuous validation
- Granted UK Registered Design No. 6498103 (granted Jan 2026)
- Pending UK Patent Application (GB2607921)
Enterprise Incident Command & Tabletop Drills
P1/P2 security events demanding coordinated technical containment at the same time as customer, executive and board communication — under extreme time pressure and incomplete information.
Acted as Lead Incident Manager: owned containment strategy, coordinated cross-functional teams, controlled internal and external communications, and ran post-incident reviews that converted attacker TTP findings into concrete control changes.
- Structured containment, zero data loss, zero regulatory penalties
- 40% reduction in client MTTR after tabletop IR simulations
- Recurring findings fed straight into the audit and risk plan
Government-Grade Compliance & ATO Delivery
A federal-grade environment required formal authorisation with defensible control evidence against NIST 800-53, on a fixed, non-negotiable assessment timetable.
Ran the control assessments, performed system categorisation and CIA risk evaluation, produced the SSP, SAR and POA&M documentation, and prioritised remediation with senior security leadership.
- Documentation pack fully supported Authority to Operate (ATO)
- Complete SSP, SAR, and POA&M delivered on schedule
- Incident response readiness measurably strengthened
Standards, Frameworks & Toolset
What I work with day to day — with delivery-grade execution and working knowledge.
Full lifecycle: Scope, SoA, Risk Assessment, and audit defence across all 93 Annex A controls.
AI governance frameworks mapped to ISO 27001/27701, AI system risk classification & lifecycle assurance.
Trust Services Criteria scoping, automated evidence pipelines, management assertions and CPA audit defence.
Government-grade assessments, system categorization, SSP, SAR, POA&M documentation, supporting ATO decisions.
DPIA methodology, Records of Processing (RoPA), cross-border data transfers, and 72h breach response.
AI risk classification (High-Risk vs Limited/Minimal), conformity documentation, and DPIA for AI systems.
Detection engineering, KQL queries, custom workbooks, UEBA tuning, and automated Logic App playbooks.
Endpoint EDR, Office 365 protection, Purview DLP, sensitivity labeling, retention, and Insider Risk management.
IAM least privilege, Organizations SCPs, KMS encryption, GuardDuty, Security Hub, and Vault Lock immutability.
Conditional Access policies, Privileged Identity Management (PIM), RBAC architecture, and passwordless MFA.
CDE network scoping, key management, Cyber Essentials Plus hands-on technical verification.
Infrastructure as Code security baselines, tfsec/checkov, Lambda automated restore and validation testing.
Professional Experience
From hands-on network and infrastructure support to owning enterprise security programmes end to end.
• Authored multi-year security strategy across ISO 27001, SOC 2, NIST CSF, PCI DSS and ISO 42001; chaired Information Security Steering Committees.
• Maintained 92% control compliance and a 70% drop in audit findings; built gap methodology covering all 93 ISO 27001:2022 controls.
• Lead Incident Manager for P1/P2 crises; tuned Sentinel UEBA and Defender XDR.
• Engineered AWS Zero Trust (50% fewer misconfigurations, 35% lower spend) and patented AI-driven GRC automation (65% workload cut).
• Contributed to 18% client revenue growth by clearing complex SIG/CAIQ questionnaires.
• Delivered governance and compliance uplift in government-grade environments under NIST SP 800-53 and 800-60.
• Authored SSP, SAR, and POA&M packs supporting formal Authority to Operate (ATO) decisions.
• Directed SOC operations, led external audits, and ran advanced threat modeling / vulnerability assessments.
• Coordinated cross-functional real-time incident response across hybrid cloud and on-premises environments.
• Built cloud security baseline aligned to CIS Benchmarks (50% reduction in misconfigurations).
• Architected Third-Party Risk Management (TPRM) programmes and authored SOC operations playbooks.
• Reduced system vulnerabilities 25% through rigorous patch and vulnerability management.
• Delivered executive breach and risk metrics driving a 20% uplift in enterprise cybersecurity investment.
• Authored initial SOC documentation, procedures, and triage workflows.
• Configured IP networking, switching, routing, and enforced enterprise endpoint security policy.
• Executed root-cause problem remediation resulting in 25% fewer recurring issues.
• Managed physical hardware rollouts, imaging, and workstation migrations across estates.
Intellectual Property & Patents
Demonstrated track record of technical invention in automated compliance and privacy-preserving computing architectures.
No. 6498103
“Computer Device for Continuous Patient Monitoring Using Differential Data Protection Techniques” — Granted January 2026 by the UK Intellectual Property Office.
GB2607921
“AI-Driven Compliance and Continuous GRC Automation System” — Novel continuous telemetry synthesis for automated audit evidence and real-time control verification.
Verified Certifications
Initiate an Engagement
Currently accepting interim security leadership (vCISO), audit and compliance delivery, cloud security, and AI governance mandates — contract, fractional or advisory.