AVAILABILITY: IMMEDIATE UK-Wide, Remote or Hybrid · Inside or Outside IR35 · Rate Negotiable Initiate Contact →
Founder & Principal Consultant · Pyralink Innovation Ltd

Adedeji Michael Cyber Security & GRC Consultant

12+ years across security operations, audit and assurance, cloud security and AI governance. I take work end-to-end — assessing technology and third-party solutions against policy and standards, running ISO 27001 and SOC 2 audit programmes, hardening AWS and Microsoft 365 estates, leading SOC and incident response activity, and reporting it all in language executives and auditors can act on. Currently operating as an independent consultant, comfortable dropping into an existing team or owning a workstream outright.

Target Roles & Engagement Terms
Inside or Outside IR35 Immediate Availability UK-Wide / Remote / Hybrid Day Rate Negotiable
Security Analyst Cyber Security Consultant IT / Cyber Auditor GRC & Compliance Consultant Cloud Security Security Assurance AI Governance Interim Security Lead / vCISO
CISM CISA CEH CC (ISC²) CompTIA A+ MSc Data Science CISSP (in progress)
Executive Snapshot
Track Record: 12+ Years Enterprise
Audit Compliance: 92% Sustained Pass
Audit Findings Drop: 70% Cycle-on-Cycle
AI GRC Automation: 65% Workload Saved
SIEM Cost Reduction: 42% Ingestion Savings
Incident Command: Lead Manager P1/P2
Intellectual Property: Granted Design + Patent
Proprietary Technology & IP

Products Built at Pyralink

Security, compliance and privacy products designed, built and architected to solve core enterprise bottlenecks.

CloudAuditX™ Compliance Platform
Automated Multi-Cloud Evidence Harvesting Engine

Plugs into AWS, Azure, GCP and Microsoft 365 via read-only APIs to continuously map infrastructure against ISO 27001, SOC 2 and Cyber Essentials. Covered by a granted UK Registered Design (No. 6498103) and a pending UK patent application (GB2607921).

Cuts enterprise compliance effort by 65% via continuous control monitoring
TelemetrySentinel™ Sensor Bridge
High-Throughput Log Pipeline & OCSF Normalisation

Filters routine noise and normalises multi-cloud telemetry to the Open Cybersecurity Schema Framework (OCSF) schema before piping into Microsoft Sentinel or external SIEMs — preventing alert fatigue and data bloating.

Reduces SIEM data ingestion and retention cost by 42%
ReputationShield™ Brand Defence
External Digital Risk Surveillance & Takedowns

Continuous threat monitoring service inspecting underground stealer log dumps, dark web channels, Telegram leaks, and domain registrars for lookalike phishing domains, brand spoofing, and employee credential exposures.

Automated reconnaissance & takedown workflows for active phishing threats
DataPrivacyVault™ Tokenisation Enclave
Sovereign Cryptographic Tokenisation & LLM Redaction

Hardware-enclave tokenisation engine providing real-time PII prompt redaction for Generative AI / LLM workflows — de-risking enterprise databases and AI pipelines from data breach liability under UK GDPR Article 32.

Compliant with GDPR Art. 32 with hardware enclave cryptographic protection
Core Capabilities

What I Deliver

End-to-end security delivery across operations, audit, cloud architecture and emerging AI assurance.

Security Assessment & Assurance

Assessing technology projects, SaaS platforms, and third-party solutions against NIST CSF, ISO 27001, and internal security policies. Running vendor and supply-chain risk assessments.

NIST CSF SaaS Assessment Supply Chain Risk Policy Evaluation

IT & Cyber Audit

CISA-certified end-to-end audit delivery — risk-based planning, fieldwork, workpapers, findings, and tracking remediation through to closure.

Risk-Based Planning CISA Fieldwork Audit Workpapers Remediation Tracking

ISO 27001 / 27701 & SOC 2

Full lifecycle delivery: readiness assessments, certification and surveillance audits, evidence management, and Statement of Applicability (SoA) across all 93 controls.

ISO 27001 (93 Controls) ISO 27701 PIMS SOC 2 Type I/II Cyber Essentials+

Security Operations & SIEM

SIEM alert monitoring, triage and investigation across Rapid7, Microsoft Sentinel, CrowdStrike, and Defender XDR; vulnerability management and MSSP partner oversight for 24/7 coverage.

Rapid7 & Sentinel CrowdStrike Defender XDR Vulnerability Mgmt

Cloud & Microsoft Security

AWS and Microsoft 365 architecture review, CIS hardening, Zero Trust, backup & DR; Microsoft Purview (DLP, eDiscovery, DSAR, labels), and Entra ID (Conditional Access, PIM, RBAC).

AWS Zero Trust Purview DLP / DSAR Entra ID & PIM Backup Vault Lock

AI Governance & Privacy

ISO 42001-aligned AI management, EU AI Act readiness, AI risk assessments, UK GDPR data protection operations, and automated compliance pipelines.

ISO 42001 EU AI Act UK GDPR & DPIA AI Compliance IP
Measured Impact

Selected Achievements

Every figure below comes directly from delivered enterprise programmes and defensible audit outcomes.

92%
Audit Compliance
Control compliance sustained across ISO 27001 / SOC 2 / Cyber Essentials Plus
70%
Finding Reduction
Drop in audit findings cycle-on-cycle via structured remediation
65%
Workload Removed
Compliance hours saved by building AI-driven GRC automation
50%
Fewer Misconfigs
Achieved by re-architecting AWS estates around Zero Trust & CIS
40%
MTTR Reduction
Response time improvement post tabletop IR simulations
42%
SIEM Cost Savings
Log pipeline normalisation to OCSF via TelemetrySentinel™
35%
Cloud Spend Cut
Infrastructure cost reduction during security re-architecture
18%
Revenue Lift
Client revenue unblocked by clearing vendor questionnaires (SIG, CAIQ)
Selected Engagements

Case Studies & Delivery Stories

Client names withheld. Real engineering, architectural and audit transformations.

Cloud Security & Architecture AWS & M365

Zero Trust Cloud Security Re-Architecture

Problem

An AWS estate had grown organically across accounts. Misconfigurations kept recurring, cloud spend was escalating without governance, and the estate could not evidence the control posture needed for ISO 27001 or enterprise customer due diligence — putting live deals at risk.

Action

Designed and led a Zero Trust re-architecture against CIS Benchmarks: hardened IAM and network configuration, implemented guardrails and continuous posture monitoring, embedded the controls into the ISO 27001 framework, and aligned identity strategy across cloud and Microsoft 365.

Measured Outcomes
  • 50% fewer cloud misconfigurations (Zero Trust + CIS Benchmarks)
  • 35% reduction in redundant cloud infrastructure costs
  • 92% control compliance achieved during ISO 27001 certification
  • Customer due diligence cleared without findings, unblocking key revenue
AI Governance & Innovation Patent & Design IP

AI-Driven Continuous GRC Automation

Problem

Evidence collection, control testing, and exception tracking were manual and repetitive — consuming analyst capacity and producing inconsistent audit evidence that slowed every certification cycle.

Action

Architected AI-powered GRC automation (CloudAuditX™) that converted point-in-time evidence gathering into continuous monitoring with executive dashboards, and filed intellectual property covering the approach.

Measured Outcomes
  • 65% reduction in compliance & audit workload via AI-driven GRC
  • Materially better evidence quality for internal and external audit
  • Granted UK Registered Design No. 6498103 (granted Jan 2026)
  • Pending UK Patent Application (GB2607921)
Incident Leadership & Operations P1/P2 Major Incident

Major Incident Leadership & Crisis Response

Problem

P1/P2 security events demanding coordinated technical containment at the same time as customer, executive and board communication — under time pressure and incomplete information.

Action

Acted as Lead Incident Manager: owned containment strategy, coordinated cross-functional teams, controlled internal and external communications, and ran post-incident reviews that converted attacker TTP findings into concrete control changes.

Measured Outcomes
  • Structured containment and executive/customer reporting
  • 40% reduction in client MTTR after tabletop IR simulations
  • Recurring findings fed straight into the audit and risk plan
Technical & Governance Scope

Frameworks & Toolset Matrix

What I work with day to day across audit standards, cloud platforms, security operations and privacy.

ISO/IEC 27001:2022 & 27002 Delivery Lead

All 93 Annex A controls: ISMS scoping, risk assessment, Statement of Applicability (SoA), and audit defence.

ISO/IEC 42001 (AI Management) Delivery Lead

ISO 42001-aligned frameworks mapped to ISO 27001/27701, AI risk classification, and AI system lifecycle assurance.

SOC 2 (Type I & Type II) Delivery Lead

Trust Services Criteria scoping, evidence gathering, management assertions, and external CPA audit defence.

UK GDPR & Data Protection Act 2018 Delivery Lead

DPIA methodology, records of processing activities (RoPA), data transfer assessments, and 72-hour breach response.

EU AI Act Readiness Delivery Lead

AI risk classification, conformity assessments, transparency requirements, and DPIA for AI systems.

PCI DSS v4.0 & Cyber Essentials+ Delivery Lead

Cardholder data environment (CDE) scoping, network segmentation, and Cyber Essentials Plus technical verification.

ISO/IEC 27701 (Privacy Information) Delivery Lead

Privacy Information Management Systems (PIMS) extension to ISO 27001 for controller and processor obligations.

Microsoft Purview Delivery Lead

Data Loss Prevention (DLP), sensitivity labels, retention policies, eDiscovery, and DSAR management.

Microsoft Entra ID Delivery Lead

Conditional Access policies, Privileged Identity Management (PIM), RBAC access governance, and MFA enforcement.

AWS Security & Backup Vault Lock Delivery Lead

AWS IAM least-privilege, GuardDuty, Security Hub, KMS encryption, and AWS Backup Vault Lock immutability.

SIEM & EDR Operations Delivery Lead

Alert triage and investigation across Rapid7, Microsoft Sentinel, CrowdStrike, and Defender XDR; MSSP SLA oversight.

Customer Due Diligence (SIG / CAIQ / DDQ) Delivery Lead

Owning security questionnaires (SIG, CAIQ, DDQ) and RFP security responses that unblock sales cycles.

Career History

Professional Experience

12+ years progression across security operations, audit and assurance, cloud security and AI governance.

Nov 2022 – Present

Founder & Principal Consultant — Cyber Security, GRC & AI Governance

Pyralink Innovation Ltd, United Kingdom

• Own client security programmes end-to-end: strategy and roadmap, full policy stack, ISO 27001 certification and surveillance audits, SOC 2 readiness and Cyber Essentials Plus assessments.

• Assess technology projects, SaaS platforms and third-party solutions against security policy and standards; run vendor and supply-chain risk assessments and track findings to closure.

• Secure and assess cloud estates — AWS IAM, network, storage, logging and posture; Microsoft 365 with Purview DLP and labels, Entra ID Conditional Access, PIM and RBAC.

• Run security operations — SIEM alert monitoring, triage and investigation across Rapid7, Microsoft Sentinel, CrowdStrike and Defender XDR; vulnerability management and MSSP oversight for 24/7 coverage.

• Act as Lead Incident Manager for P1/P2 events; own customer security questionnaires (SIG, CAIQ, DDQ) and RFP security responses.

• Implement ISO 42001-aligned AI governance, advise on EU AI Act readiness, and assess AI and AI-enabled systems.

• Report monthly to executives and boards; primary contact for auditors, certification bodies, insurers and regulators.

Jan 2022 – Dec 2022

Information Security & Compliance Consultant (Contract)

Crystal Lagun Ltd, United Kingdom

• Assessed government-grade environments against NIST 800-53 / 800-60, supporting Authority to Operate decisions; produced SSP, SAR and POA&M documentation.

• Directed SOC operations, ran gap assessments against ISO and NIST standards, and led external cybersecurity audits.

• Delivered vulnerability assessments, threat modelling and impact analysis with prioritised remediation for senior leadership.

Dec 2019 – Dec 2021

Mid-Senior Cybersecurity Analyst

Technobeacon Consulting Ltd

• Led real-time incident response across cloud and on-premise environments; built the enterprise SOC operations playbook and mentored junior analysts.

• Designed and deployed a CIS/Zero Trust cloud security framework — 50% reduction in misconfigurations.

• Performed third-party and vendor risk assessments; evaluated ITGC, access governance and cloud security architecture.

Feb 2017 – Dec 2019

Information Security & Risk Analyst

TighTech Consulting

• Ran vulnerability and patch management across the estate — 25% reduction in vulnerabilities; maintained firewall, encryption and data-protection controls.

• Produced security metrics and breach reporting that drove a 20% uplift in security investment; designed SOC processes and documentation.

May 2013 – Jan 2017

System Support Analyst

Mikevicone Innovation

• Infrastructure, networking and end-user support with security policy enforcement — 25% reduction in recurring issues through root-cause analysis.

Intellectual Property

Patents & Innovation

Demonstrated track record of technical invention in automated compliance and privacy-preserving computing architectures.

Granted UK Registered Design

No. 6498103

“Computer Device for Continuous Patient Monitoring Using Differential Data Protection Techniques” — Granted January 2026 by the UK Intellectual Property Office.

Pending UK Patent Application

GB2607921

“AI-Driven Compliance and Continuous GRC Automation System” — Continuous control telemetry synthesis for automated audit evidence and real-time verification.

Published Author

Author of practical enterprise Security Awareness Training literature.

Credentials

Certifications & Education

CISM
Certified Information Security Manager · ISACA
Active
CISA
Certified Information Systems Auditor · ISACA
Active
CEH
Certified Ethical Hacker · EC-Council
Active
CC (ISC²)
Certified in Cybersecurity · ISC²
Active
CompTIA A+
CompTIA Certified
Active
MSc, Data Science
University of Sunderland, UK
Degree
BSc, Computer Science
Bachelor of Science Degree
Degree
AVAILABLE NOW

Get In Touch

Available immediately for contract, fractional or advisory engagements UK-wide, remote or hybrid. Inside or outside IR35 · Rate negotiable.