Adedeji Michael Cybersecurity, GRC & AI Governance Leader
12+ years building and running enterprise security programmes — security strategy and board reporting, ISO 27001 / SOC 2 / PCI DSS audit delivery, SOC operations and major incident response, cloud security across AWS and Microsoft 365, and ISO 42001-aligned AI governance. I turn technical risk into commercial decisions, and compliance obligations into controls that actually hold up at audit.
The Numbers Behind The Work
Every figure below comes directly from delivered enterprise engagements and defensible audit outcomes.
Six Areas I Deliver In
One career, six angles. Whichever problem you have, the underlying work is the same: make the risk visible, design controls that survive scrutiny, and get them running.
vCISO & Security Leadership
Acting as the most senior security voice — strategy and roadmap, policy stack, steering committee, vendor and MSSP oversight, monthly executive and board reporting.
IT & Cyber Audit
CISA-certified end-to-end audit delivery — risk-based planning, fieldwork, workpapers, findings, and tracking remediation through to closure.
Security Operations
SOC leadership and operations oversight, 24/7 coverage through managed MSSP partners, P1/P2 major incident command, Defender XDR integration, and KPI-driven operational improvement.
GRC & Compliance
Reading dense regulation and turning it into controls and plain-English guidance teams can act on — ISO 27001/27701, SOC 2, PCI DSS, UK GDPR, and Cyber Essentials Plus.
Cloud & Microsoft Security
Purview DLP and sensitivity labels, Entra ID Conditional Access, PIM and RBAC, AWS Zero Trust re-architecture, and backup/DR resilience design with Vault Lock.
AI Governance
ISO 42001-aligned frameworks mapped to ISO 27001/27701, EU AI Act readiness, AI risk classification and DPIA for AI systems — plus AI-driven compliance automation I hold IP on.
Case Studies & Delivery Stories
Client names withheld. Real engineering, architectural and audit transformations.
Zero Trust Cloud Security Re-Architecture
An AWS estate had grown organically across accounts. Misconfigurations kept recurring, cloud spend was escalating without governance, and the estate could not evidence the control posture needed for ISO 27001 or enterprise customer due diligence — putting live deals at risk.
Designed and led a Zero Trust re-architecture against CIS Benchmarks: hardened IAM and network configuration, implemented guardrails and continuous posture monitoring, embedded the controls into the ISO 27001 framework, and aligned identity strategy across cloud and Microsoft 365.
- 50% fewer cloud misconfigurations (Zero Trust + CIS Benchmarks)
- 35% reduction in redundant cloud infrastructure costs
- 92% control compliance achieved during ISO 27001 certification
- Customer due diligence cleared without findings, unblocking live enterprise deals
AI-Driven Continuous GRC Automation
Evidence collection, control testing, and exception tracking were manual and repetitive — consuming analyst capacity and producing inconsistent audit evidence that slowed every certification cycle.
Architected AI-powered GRC automation that converted point-in-time evidence gathering into continuous monitoring with executive dashboards, and filed intellectual property covering the approach.
- 65% reduction in compliance & audit workload via AI-driven GRC automation
- Materially better evidence quality for internal and external audit
- Granted UK Registered Design No. 6498103 (granted Jan 2026)
- Pending UK Patent Application (GB2607921)
Major Incident Leadership & Crisis Response
P1/P2 security events demanding coordinated technical containment at the same time as customer, executive and board communication — under time pressure and incomplete information.
Acted as Lead Incident Manager: owned containment strategy, coordinated cross-functional teams, controlled internal and external communications, and ran post-incident reviews that converted attacker TTP findings into concrete control changes.
- Structured containment and executive/customer reporting
- 40% reduction in client MTTR after tabletop IR simulations
- Recurring findings fed straight into the audit and risk plan
Frameworks & Technical Toolset
What I work with day to day — and what I have working knowledge of rather than delivery experience.
All 93 Annex A controls: ISMS scoping, risk assessment, Statement of Applicability (SoA), and audit defence.
ISO 42001-aligned frameworks mapped to ISO 27001/27701, AI risk classification, and AI system lifecycle assurance.
Trust Services Criteria scoping, evidence gathering, management assertions, and external CPA audit defence.
DPIA methodology, records of processing activities (RoPA), data transfer assessments, and 72-hour breach response.
AI risk classification, high-risk conformity assessments, transparency requirements, and DPIA for AI systems.
Cardholder data environment (CDE) scoping, network segmentation, and Cyber Essentials Plus certification.
Privacy Information Management Systems (PIMS) extension to ISO 27001 for controller and processor obligations.
Data Loss Prevention (DLP), sensitivity labels, retention policies, eDiscovery, and Insider Risk management.
Conditional Access policies, Privileged Identity Management (PIM), RBAC access governance, and MFA enforcement.
AWS IAM least-privilege, GuardDuty, Security Hub, KMS encryption, and AWS Backup Vault Lock immutability.
Defender XDR and Sentinel integration, managed MSSP oversight, SLAs, and P1/P2 major incident command.
Authoring responses for SIG, CAIQ, and custom enterprise RFP security questionnaires; third-party risk management.
Experience
From hands-on infrastructure support to owning enterprise security programmes end to end.
• Strategy & governance: Multi-year security strategy aligning ISO 27001, SOC 2, NIST CSF, Cyber Essentials Plus, PCI DSS and ISO 42001; authored the full policy stack and chaired the Information Security Steering Committee.
• Audit leadership: SOC 2 readiness, ISO 27001 certification and surveillance audits, Cyber Essentials Plus — 92% control compliance and a 70% drop in findings; built a gap methodology covering all 93 ISO 27001:2022 Annex A controls.
• Security operations: Managed MSSP partners for 24/7/365 coverage with defined SLAs and shift handovers; tuned Sentinel detections, deployed UEBA and integrated Defender XDR to cut false positives and dwell time.
• Major incident management: Lead Incident Manager for P1/P2 events — containment, executive and customer communications, and post-incident reviews converting attacker TTPs into control improvements.
• Cloud & data protection: AWS Zero Trust re-architecture (50% fewer misconfigurations, 35% lower spend); Microsoft Purview DLP, sensitivity labels, retention and Insider Risk; Entra ID Conditional Access, PIM and RBAC.
• Resilience engineering: AWS Backup estate design — organisation-wide plans, cross-account and cross-region copy, Vault Lock immutability, KMS-encrypted vaults.
• AI governance: ISO 42001-aligned framework mapped to ISO 27001/27701; EU AI Act readiness advisory; AI-powered GRC automation cutting compliance workload 65%.
• Commercial: Contributed to 18% client revenue growth, expanded the client base 50% in a year, and built partnerships with insurers and regulators; owned security questionnaires (SIG, CAIQ) and RFP responses that unblocked enterprise deals.
• Delivered governance and compliance uplift in high-assurance environments, implementing security control frameworks and CIA risk evaluations across critical platforms.
• Directed SOC operations, ran gap assessments against ISO standards, and led external cybersecurity audits.
• Conducted advanced vulnerability assessments, threat modelling, and impact analysis for senior security leadership.
• Led real-time incident response across cloud and on-premise environments, coordinating cross-functional containment and remediation of complex threats.
• Designed and deployed a cloud security framework aligned to CIS Benchmarks and Zero Trust — 50% reduction in misconfigurations.
• Architected third-party risk management programmes under ISO 27001/GDPR; evaluated ITGC, access governance and cloud security architecture.
• Built the enterprise SOC operations playbook and mentored junior analysts into repeatable incident-handling practice.
• Reduced system vulnerabilities 25% through patch and update management; maintained firewall, encryption and data-protection controls.
• Produced security metrics and breach reporting that drove a 20% uplift in security investment.
• Designed SOC documentation, processes and procedures, helping establish a structured security operations function.
• Applied IP networking expertise to streamline configurations, monitor performance and enforce security policy.
• Resolved customer IT issues through root-cause analysis — 25% fewer recurring problems.
• Hands-on desktop rollout, imaging, hardware installation and end-user support across VDI and workstation estates.
Patents & Innovation
Demonstrated track record of technical invention in automated compliance and privacy-preserving computing architectures.
No. 6498103
“Computer Device for Continuous Patient Monitoring Using Differential Data Protection Techniques” — Granted January 2026 by the UK Intellectual Property Office.
GB2607921
“AI-Driven Compliance and Continuous GRC Automation System” — Novel continuous telemetry synthesis for automated audit evidence and real-time control verification.
Certifications & Education
Get In Touch
Currently taking on interim security leadership, audit and compliance delivery, cloud security and AI governance engagements — contract, fractional or advisory.