Strengthening Security. Reducing Risk. Enabling Compliance.
I help organizations build stronger cybersecurity programs, manage information security risk, and navigate complex compliance requirements through practical, business-aligned solutions.
Lead the cybersecurity function of OGIS Philippines, driving cybersecurity governance, compliance, consulting, and client delivery while serving as the organization's primary technical authority.
My work sits at the intersection of business, risk, security, compliance and technology. I help organizations take cybersecurity and compliance requirements — ISO/IEC 27001, ISO/IEC 42001, ISO/IEC 27701, SOC 2 — and turn them into security programs, controls, assessments, documentation and remediation activities that actually get implemented, not just written down.
Day to day, that means leading cybersecurity delivery at OGIS Philippines: running security assessments, building out ISMS and governance structures, and helping teams get audit-ready. It also means working across adjacent areas as they intersect with security — AI governance, privacy, cloud security, and third-party risk. Earlier in my career, that same focus took shape at Accenture, leading global security assessments across hosting sites and cloud services, and at N-able, running third-party and vendor security assessments.
Alongside my current role, I take on independent consulting engagements — through Upwork and direct client relationships — supporting organizations on ISO 27001 implementation, GRC-as-a-Service, privacy compliance, and security assessments.
I start by understanding the organization's environment, objectives and actual risks before recommending controls or frameworks.
Compliance should improve security rather than simply check boxes for certification.
I work across governance, frameworks, risk management, cloud security, and hands-on implementation.
Clients are anonymized. Expand any card for the full case study.
Mapping Essential Eight controls into ISO/IEC 27001:2022 with practical implementation guidance for Microsoft environments.
The client received a practical playbook to implement Essential Eight controls while aligning the implementation with ISO/IEC 27001 requirements.
Establishing and strengthening a GDPR compliance program, including review of existing privacy and data protection practices.
Improved GDPR compliance readiness and privacy governance, supported by a structured roadmap for addressing identified gaps.
A structured delivery approach was needed ahead of formal ISO/IEC 27001 implementation — scope, activities, responsibilities, deliverables and sequencing.
Established a structured roadmap that provided the foundation for transitioning from pre-implementation planning into formal ISMS implementation.
Ongoing leadership and hands-on support to establish, operate and maintain the client's ISO/IEC 27001 compliance program.
Strengthened the client's ISMS and ISO/IEC 27001 readiness while establishing a more structured approach to managing information security compliance.
Dedicated support for implementing and managing ISO/IEC 27001 requirements — evidence collection, gap remediation and certification readiness.
Improved ISO/IEC 27001 compliance maturity and audit readiness while establishing consistent processes for managing controls, evidence, risks and remediation.
Guiding a healthcare AI startup through a practical, lightweight HIPAA compliance implementation — building strong security foundations and audit-ready evidence from day one.
Delivered a scalable, right-sized HIPAA compliance foundation — reducing breach and regulatory risk while establishing a program the client can grow into as the business scales.
OAuth abuse · Microsoft 365 · Phishing Investigation · Identity Security · Incident Triage
A phishing campaign attempted to abuse OAuth application consent within a Microsoft 365 environment to gain unauthorized access to user accounts and data.
Triaged the incident, analyzed OAuth application activity and sign-in logs within Microsoft 365, and traced the scope of the attempted abuse to assess exposure.
Listed as tools used in the course of assessments and delivery — not implied partnerships or vendor certifications.
Distinct from personal certifications — see Credentials below for what I'm certified in.
Credential and membership ID numbers are kept private.
Lead Auditor certification covering ISO/IEC 27001:2022 Information Security Management Systems, audit planning, execution, reporting and conformity assessment.
Lead Implementer certification focused on establishing, implementing, maintaining and continually improving an AI Management System, including AI governance and responsible AI practices.
Lead Auditor certification covering Privacy Information Management Systems, privacy governance, data protection requirements and privacy risk assessment.
IRCA-registered qualification covering auditing principles and practices for ISO/IEC 27001:2022 Information Security Management Systems.
Professional practitioner credential demonstrating competence in quality management principles, continual improvement and management system practices.
Government-recognized cybersecurity professional credential demonstrating competency in cybersecurity and information security.
Information systems audit, cybersecurity, governance, risk and compliance.
Cybersecurity leadership, information security governance and CISO community.
Cybersecurity collaboration, professional development and security community engagement in the Philippines.
Department of Information and Communications Technology's Registry of Certified Cybersecurity Professionals in the Philippines.
Security controls should work in the real world.
Security investment should be aligned with actual risk.
Security decisions should be supported by evidence and measurable outcomes.
Security should protect what matters most to the organization.
I translate complex security, risk and compliance requirements into clear, actionable solutions that organizations can actually implement.
I understand both the governance side of cybersecurity and the technical realities behind the controls — connecting business requirements with practical security implementation.
My focus goes beyond assessments and reports. I work with teams to turn findings into remediation plans, implement controls, and build sustainable security programs.
Independent cybersecurity, information security, GRC and compliance consulting — active since October 2025, via Upwork, direct client engagements, and my professional network.
I help startups, SaaS companies, healthcare organizations, and enterprises build audit-ready cybersecurity, GRC, privacy, and AI governance programs — from gap assessment and implementation to audit and certification readiness.
Practical perspectives from my work across cybersecurity, GRC, cloud security, privacy, and AI governance.
"Security isn't just about controls. It's about understanding risk, making informed decisions, and building programs that organizations can actually operate."
Cybersecurity, compliance, risk, or security assessment — let's talk it through.