home services experience skills contact
azharuddin@cyberaon: ~/profile — zsh — 132×48
 █████╗ ███████╗██╗  ██╗ █████╗ ██████╗ ██╗   ██╗██████╗ ██████╗ ██╗███╗   ██╗
██╔══██╗╚══███╔╝██║  ██║██╔══██╗██╔══██╗██║   ██║██╔══██╗██╔══██╗██║████╗  ██║
███████║  ███╔╝ ███████║███████║██████╔╝██║   ██║██║  ██║██║  ██║██║██╔██╗ ██║
██╔══██║ ███╔╝  ██╔══██║██╔══██║██╔══██╗██║   ██║██║  ██║██║  ██║██║██║╚██╗██║
██║  ██║███████╗██║  ██║██║  ██║██║  ██║╚██████╔╝██████╔╝██████╔╝██║██║ ╚████║
╚═╝  ╚═╝╚══════╝╚═╝  ╚═╝╚═╝  ╚═╝╚═╝  ╚═╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚═╝╚═╝  ╚═══╝
$ Sr. SecOps Engineer & GRC @ Credgenics · India, Remote
$ Founder & vCISO · Cyberaon Technologies — vCISOaaS Platform
FULL_NAME
Azharuddin Mohammed
CURRENT_ROLE
Sr. SecOps Engineer & GRC
EMPLOYER
Credgenics (Fintech · Debt Resolution)
STARTUP
Cyberaon Technologies — vCISOaaS
LINKEDIN
LOCATION
India · Remote
EXPERIENCE
15+ Years · Security & GRC
15+
years_exp
6+
certs
12+
frameworks
30+
clients
certifications
ISO 27001 LA CISA CISM CIPP/EU AWS Security CISSP
compliance_expertise
ISO 27001 ISO 42001 ISO 22301 ISO 27701 ISO 9001 SOC 2 T2 PCI DSS HIPAA GDPR CCPA ADHICS DPDP Act RBI SAR
active_services
vCISOaaS — Cyberaon Technologies
Sr. SecOps @ Credgenics
ISO 27001 Internal Audits
VAPT Coordination (CERT-In)
TPRM Vendor Audits
AWS Cloud Security Reviews
azharuddin@ cyberaon:~/services$ systemctl list-units --type=service --state=active
service_registry.d
12 active units loaded · End-to-end security & compliance delivery across all major frameworks
I provide comprehensive, end-to-end security and compliance services — from initial gap assessment through certification, continuous monitoring, and ongoing advisory. Every engagement is structured around your regulatory landscape, risk appetite, and business context. Services are delivered individually or as a bundled vCISOaaS retainer through Cyberaon Technologies.
SVC-001 · CORE ● ACTIVE
🛡️
vCISOaaS

Fractional Chief Information Security Officer delivered as a service via Cyberaon Technologies. Ideal for SaaS, fintech, and health-tech startups that need senior security leadership without the full-time cost. I own your ISMS, security roadmap, and board reporting end-to-end.

Security strategy & annual roadmap
ISMS setup, ownership & maintenance
Board & executive security reporting
Incident response planning & tabletop
Security awareness programme design
vCISOISMSGovernanceCyberaon
SVC-002 · COMPLIANCE ● ACTIVE
📋
ISO Standards Suite

Full end-to-end compliance lifecycle for all major ISO standards — from scoping and gap assessment through implementation, internal audit, and certification support. I manage the entire journey so you can focus on building your product.

ISO 27001:2022 — Information Security ISMS
ISO/IEC 42001 — AI Management System (AIMS)
ISO 22301 — Business Continuity Management
ISO 27701 — Privacy Information Management
ISO 9001 — Quality Management System
ISO 27001ISO 42001ISO 22301ISO 27701
SVC-003 · COMPLIANCE ● ACTIVE
⚙️
SOC 2 Type 2

Complete SOC 2 Type 2 readiness and audit support covering all five Trust Service Criteria. From pre-audit gap analysis and evidence collection to audit management, remediation tracking, and post-report advisory.

TSC scoping: Security, Availability, Confidentiality, PI, Privacy
Control mapping, SoA & evidence library
Continuous control monitoring setup
Auditor liaison & inquiry management
Remediation roadmap & closure tracking
SOC 2 T2TSCEvidenceControls
SVC-004 · COMPLIANCE ● ACTIVE
💳
PCI DSS Compliance

End-to-end PCI DSS compliance programme for organisations processing, storing, or transmitting cardholder data. Covers scoping, gap analysis, SAQ preparation, QSA coordination, and all 12 requirements of PCI DSS v4.0.

CDE scoping & network segmentation review
SAQ / ROC preparation and QSA coordination
Firewall rules, encryption & key management review
Vulnerability scanning & penetration test coordination
Remediation tracking across all 12 requirements
PCI DSS v4SAQCDEQSA
SVC-005 · PRIVACY ● ACTIVE
🔏
GDPR & CCPA

Full privacy compliance programmes for organisations operating under GDPR (EU) and CCPA (California). Includes data mapping, lawful basis analysis, consent architecture, DSR workflows, and privacy-by-design integration into your SDLC.

Data flow mapping & RoPA (Records of Processing)
DPIA / Transfer Impact Assessments (TIA)
Consent management & opt-out mechanisms (CCPA)
Privacy notices, policies & DPA templates
Data subject request (DSR) process design
GDPRCCPADPIAPrivacy
SVC-006 · HEALTHCARE ● ACTIVE
🏥
HIPAA & ADHICS

Healthcare-specific compliance covering HIPAA (US) and ADHICS (Abu Dhabi Healthcare Information and Cyber Security standard). Designed for health-tech platforms, digital health startups, and healthcare providers operating across multiple jurisdictions.

HIPAA Security Rule gap assessment & risk analysis
PHI data flow mapping & access controls review
ADHICS framework mapping & implementation
BAA review, vendor assessment & TPRM
Breach notification policies & incident response
HIPAAADHICSPHIHealth-tech
SVC-007 · AUDIT ● ACTIVE
🔍
Internal & External Audits

Structured internal and external audit services across all major frameworks. I serve as both auditor and advisor — conducting audits on behalf of clients, preparing organisations for external certification audits, and acting as a liaison with accreditation bodies.

ISO 27001 internal audit programme management
Evidence collection, review & gap closure
Non-conformity tracking & CAR/PAR management
External audit readiness & pre-audit dry runs
Audit report authoring & certification liaison
Internal AuditExternal AuditNCRCertification
SVC-008 · RISK ● ACTIVE
🏢
Vendor TPRM Audits

Third-Party Risk Management (TPRM) audits conducted on behalf of clients — evaluating vendors, suppliers, and partners against security, privacy, and regulatory requirements. I manage the full vendor lifecycle from onboarding questionnaires through annual reassessment.

Vendor security questionnaire design & review
Risk-tiering framework and scoring model
On-site / remote vendor security assessments
Contractual control requirements & DPA review
Annual vendor reassessment programme management
TPRMVendor RiskSupply ChainDPA
SVC-009 · DUE DILIGENCE ● ACTIVE
📑
Onboarding & Due Diligence

Security due diligence audits for company onboarding, M&A, investor readiness, and partnership assessments. I evaluate target organisations' security posture, compliance status, and risk exposure — producing structured reports for decision-makers.

Security posture assessment & maturity scoring
Compliance status mapping across applicable frameworks
Data protection & privacy risk review
Identified gaps, risk rating & remediation timeline
Executive due diligence report for stakeholders
Due DiligenceM&ARisk ScoringInvestor
SVC-010 · CLOUD ● ACTIVE
☁️
AWS Cloud Security

Deep-dive AWS cloud security assessments using ScoutSuite, AWS Security Hub, and native tooling. Covers IAM privilege analysis, network exposure, encryption posture, logging & monitoring, and RBI SAR Data Localisation requirements.

ScoutSuite-based multi-account hardening assessment
IAM privilege analysis & least-privilege remediation
GuardDuty / Security Hub configuration review
CloudTrail forensics & logging completeness audit
RBI SAR data localisation & cross-border data flow review
AWSIAMScoutSuiteGuardDuty
SVC-011 · OFFENSIVE ● ACTIVE
🎯
VAPT & PenTesting

Vulnerability assessment and penetration testing across web, mobile, API, and cloud surfaces. I coordinate CERT-In empanelled vendors, manage the full engagement lifecycle, and deliver structured reports with risk-rated findings and remediation roadmaps.

Black-box, grey-box & white-box web application VAPT
Mobile security assessment (iOS & Android, MobSF)
API security testing & authentication review
Source code review & SCA (software composition analysis)
CERT-In empanelled vendor coordination & report review
VAPTPenTestCERT-InMobSF
SVC-012 · AI/ML ● ACTIVE
🤖
AI Governance (ISO 42001)

End-to-end AI Management System (AIMS) implementation aligned to ISO/IEC 42001. Covers AI risk assessment, model lifecycle governance, LLM security (OWASP Top 10 for LLMs), algorithmic impact analysis, and responsible AI policy design for AI-first companies.

ISO 42001 gap assessment & AIMS implementation
AI risk register & algorithmic impact assessment
LLM security testing (OWASP LLM Top 10 payload library)
AI policy suite: acceptable use, model governance, data quality
Responsible AI framework & ethics board advisory
ISO 42001LLM SecurityAIMSResponsible AI
azharuddin@ cyberaon:~$ journalctl -u career.service --no-pager --output=verbose
career.journal
4 entries · sorted: newest first · filter: all priorities
Feb 2026 → Present credgenics.local career[secops]: Sr. SecOps Engineer & GRC · Full-time · India, Remote ● CURRENT
Credgenics — Fintech · Debt Resolution Platform
1SCOPE: Drive comprehensive security audits — establishing ISMS policies, security controls & procedures aligned to ISO 27001, ISO 27701, PCI DSS, RBI SAR Data Localisation.
2TPRM: Conduct Third-Party Risk Management audits during vendor onboarding and on an annual basis; engage fintech clients' InfoSec teams for artefact sharing and control validation.
3VAPT: Oversee & coordinate security assessments by CERT-In empanelled auditors — server hardening, config reviews, firewall rule audits, AWS cloud security testing.
4COMPLIANCE: Managing ISO 27001, ISO 27701, PCI DSS, and RBI SAR compliance programmes end-to-end for production AWS environments (ap-south-1 / ap-south-2).
5SKILLS: Compliance_Management · Internal_Audits · AWS_Security · ISMS · TPRM · PCI_DSS · RBI_SAR · +14
Oct 2022 → Feb 2026 · 3 yrs 5 mos hackrew.local career[grc]: Senior Manager GRC · Full-time · Hyderabad, Telangana · Remote ✓ COMPLETED
Hackrew — Security & GRC Services
1GRC: Led ISMS auditing, log reviews, and ISMS policy documentation for multiple clients under ISO 27001:2013/2022, PCI DSS, SOC 2 and other compliance frameworks.
2vCISO: Acted as virtual CISO for SaaS & fintech clients — owned risk registers, SoA, vendor risk assessments, and security roadmaps aligned to board-level reporting.
3AUDITS: Internal and external audit coordination across ISO 27001, SOC 2, and PCI DSS; managed remediation tracking and certification evidence closure.
4SKILLS: Compliance_Management · AWS_Security · ISO_27001 · vCISO · SoA · SOC_2 · Vendor_Risk · +12
Oct 2019 → Oct 2022 · 3 yrs 1 mo defmax.local career[analyst]: Senior Security Analyst · Full-time · India, Remote ✓ COMPLETED
Defmax Technologies Pvt. Ltd.
1AUDITS: Security audits, GRC assessments & ISMS implementation covering ISO 27001, PCI DSS, NIST-aligned controls for technology clients.
2VAPT: Web & mobile penetration testing (Burp Suite, MobSF); structured findings reports with risk-rated remediation roadmaps delivered to client security teams.
3POLICY: Built secure SDLC policies, access control frameworks, and incident response playbooks adopted as baseline governance artefacts across client portfolios.
4SKILLS: Security_Audits · GRC · VAPT · ISMS · Source_Code_Review · Mobile_Security · +11
Jan 2011 → Apr 2019 · 8 yrs 4 mos patra.local career[ops]: Senior Team Lead · Full-time · Visakhapatnam, Andhra Pradesh ✓ COMPLETED
Patra Corporation — Insurance Technology
1ROLE: Led cross-functional operations team delivering management operations support for an international insurance technology firm.
2OPS: Managed quality assurance processes, SLA adherence, and operational risk controls; structured process documentation that built the foundation for later GRC work.
3SKILLS: Management_Operations · Team_Leadership · Process_Governance · Quality_Assurance · SLA_Management
azharuddin@ cyberaon:~$ htop --sort-key=EXPERTISE --tree
skills.monitor
Live skill utilisation · Updated: continuously · 6 categories loaded
SKILL MONITOR v4.2 Uptime: 15+ yrs Tasks: 58 skills running Load avg: HIGH
Compliance Frameworks
ISO 27001:2022
98%
SOC 2 Type 2
95%
PCI DSS v4
92%
ISO/IEC 42001
90%
ISO 22301 / BCP
88%
HIPAA / ADHICS
85%
GDPR / CCPA
93%
RBI SAR Data Loc.
90%
Cloud & Infrastructure
AWS Security
94%
ScoutSuite / Hub
90%
IAM Analysis
92%
Wazuh SIEM
85%
Azure NSG / AKS
80%
Server Hardening
88%
Security Testing
VAPT / PenTest
90%
Burp Suite Pro
88%
MobSF (Mobile)
85%
Source Code Review
82%
Nmap / Nuclei
86%
LLM Security (OWASP)
80%
GRC & Advisory
Risk Register / SoA
97%
Vendor TPRM
93%
Due Diligence Audits
90%
vCISO Advisory
95%
ISMS Documentation
98%
Policy Authoring
96%
azharuddin@ cyberaon:~$ ssh -v -p 443 azharuddin@cyberaon.com
open_channel.sh
Secure connection established · Protocol SSH-2.0 · Cipher aes256-ctr
SSH — azharuddin@cyberaon.com — bash — 132×40
debug1: Connecting to cyberaon.com debug1: Connection established. debug1: Authentications that can continue: publickey debug1: Authenticated to azharuddin@cyberaon.com
Last login: --:--:--
Initiating connection to discuss a security engagement, compliance programme, vCISOaaS retainer, or audit? Drop me an email — I aim to respond within one business day.
engagement_types
I work with SaaS companies, fintech platforms, health-tech startups, and enterprise organisations across India, the Middle East, and globally. Engagements range from focused one-time audits to long-term vCISOaaS retainers.
what i can help you with
End-to-end ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR certification
ADHICS & CCPA compliance for regional and global expansion
Internal & external audit management for any framework
Vendor TPRM programmes & due diligence audits on your behalf
Company onboarding & M&A security due diligence
vCISOaaS retainer — full security leadership via Cyberaon
AWS cloud security review & VAPT coordination
AI governance (ISO 42001) for AI-first products
$ echo "Response time: < 24h business days"
$ echo "Availability: Global (Remote) + India (On-site)"
$ echo "Languages: English · Hindi · Telugu · Urdu"