Brian Haman, PhD

Associate Consultant

Austria5 yrs 6 mos experience

Key Highlights

  • PhD holder with 15 years in academia and communications.
  • Expert in ISO 27001 gap assessments and risk frameworks.
  • Published author on cybersecurity governance and AI risk.
Stackforce AI infers this person is a Cybersecurity and GRC expert with a focus on regulatory compliance in fintech and EU institutions.

Contact

Skills

Other Skills

Information SystemsCybersecurity Frameworks (NIST, ISO, CIS Controls)Network SecuritySecurity OperationsSecurity PrinciplesAccess Controls ConceptsBusiness Continuity (BC) ConceptsDisaster Recovery (DR) ConceptsSecurity Policy & DocumentationData Privacy & GDPRPolicy & Procedure DevelopmentRisk Assessment & MitigationSecurity Awareness & TrainingNIST Cybersecurity FrameworkResearch & Analysis

About

GRC professional with deep expertise in information security governance, risk management, and regulatory compliance across EU institutions, fintech, and consulting environments. Currently delivering ISO 27001 gap assessments, ISMS documentation, and risk frameworks for clients through Arden Content; previously supporting regulatory governance and risk communications at the European Investment Fund across 27 member states. My path to GRC is unconventional. I have a PhD, and 15 years in academia, criticism, and regulated communications sharpened precisely the skills enterprise GRC demands most: the ability to interrogate complex systems, communicate risk to non-technical stakeholders, and think critically about governance assumptions that practitioners often take for granted. CRISC candidate (Q2 2026). Hands-on technical experience includes Python automation for GRC workflows, zero-trust architecture validation (Cloudflare Tunnel, VLANs, Tailscale), and vulnerability assessment using Nmap, OpenVAS, and Wireshark. Published weekly on cybersecurity governance, AI risk, and ISO/NIST frameworks. Contributor to Corporate Compliance Insights; bylines in the New York Times and The Guardian. Open to mid-senior GRC, information security risk, and compliance roles in Vienna, remotely across the EU, or within EU institutional environments. Particularly interested in regulated sectors where governance depth and analytical rigour matter.

Experience

5 yrs 6 mos
Total Experience
1 yr 7 mos
Average Tenure
1 yr 4 mos
Current Experience

Arden content

Cybersecurity GRC Consultant

Jan 2025Present · 1 yr 4 mos · Vienna, Austria & Bucharest, Romania

The shanghai literary review

Information Security Governance Lead

Jun 2024Oct 2025 · 1 yr 4 mos · Remote

European investment fund (eif)

Senior Regulatory & Risk Communications Specialist

Jun 2023May 2024 · 11 mos · Luxembourg

University of vienna

Lecturer

Oct 2021Feb 2025 · 3 yrs 4 mos · Vienna, Austria

Trality

Senior Compliance & Security Communications Strategist

Sep 2020May 2023 · 2 yrs 8 mos · Vienna, Austria

Education

University of Warwick

Doctor of Philosophy - PhD — German Studies

University of Warwick

Master's Degree — English Literature (British and Commonwealth)

Oct 2007Sep 2008

Manhattan University

Bachelor's Degree — English Literature (British and Commonwealth)

Jan 1999Mar 2003

Stackforce found 100+ more professionals with Information Systems & Cybersecurity Frameworks (NIST, ISO, CIS Controls)

Explore similar profiles based on matching skills and experience