Ibrahim Kehinde Alli

Associate Consultant

Federal Capital Territory, Nigeria2 yrs 5 mos experience
Highly Stable

Key Highlights

  • Expert in Governance, Risk & Compliance frameworks.
  • Proven track record in cloud security implementations.
  • Skilled in translating complex risk into actionable insights.
Stackforce AI infers this person is a Governance, Risk & Compliance expert in the Fintech industry.

Contact

Skills

Core Skills

Governance, Risk & Compliance (grc)Cloud SecurityRisk ManagementSecurity Operations

Other Skills

GovernanceComplianceNIST 800-53ISO 27001Audit ReadinessRisk RegisterExecutive ReportingThird-Party Risk GovernanceRisk ArtifactsExecutive CommunicationGovernance StructureRisk Mitigation PlansPowerShellActive DirectorySecurity Assessments

About

ABOUT IBRAHIM KEHINDE ALLI I’m a Governance, Risk & Compliance (GRC) professional with a strong IT Support/Helpdesk foundation, bridging day-to-day IT operations with security governance so controls work in the real world (not just on paper). I help organizations reduce cyber risk by translating frameworks into practical, auditable processes aligned to NIST CSF and ISO/IEC 27001. Alongside my IT Support work (Windows/macOS, networking, endpoint reliability, user access issues, troubleshooting), I’ve built a GRC portfolio program that mirrors how security teams operate in companies: policies, risk registers, control mapping, evidence plans, and third-party risk workflows. What I Deliver: • Risk assessments & risk register management (likelihood/impact scoring, treatment plans, owners, due dates, residual risk) • Control design & control testing support (what the control is, how it’s performed, how it’s measured, what evidence proves it) • Policy & procedure writing (Access Control, Incident Response, Asset Management, Change Management, Vendor) • Audit readiness (evidence collection plan, documentation structure, control-to-evidence traceability) • Third-party/vendor risk (questionnaires, access review requirements, onboarding/off-boarding, evidence requests) • Vulnerability & exposure awareness (Qualys VM concepts + security basics that connect technical findings to risk decisions) Certifications: Google Cybersecurity Professional, ISC2 CC, ISO 27001, NIST CSF, Qualys Vulnerability Management (plus additional security training). I’m currently targeting GRC Analyst / Risk & Compliance / Security Compliance / Third-Party Risk roles where I can support audits, strengthen control maturity, improve documentation, and help teams make defensible risk decisions. Keywords: GRC, cybersecurity risk, compliance, ISO 27001, NIST CSF, controls, audit readiness, evidence collection, risk assessment, risk register, policies, third-party risk, vendor risk, incident response, vulnerability management. Skills: Governance, Risk & Compliance (GRC) • Cybersecurity Risk Management • Security Compliance • ISO/IEC 27001 • NIST Cybersecurity Framework (NIST CSF) • Security Controls • Control Mapping • Controls Testing • Audit Readiness • Evidence Collection • Policy & Procedure Writing • Risk Assessments • Risk Register • Risk Treatment Plans • Third-Party Risk Management (TPRM) • Vendor Risk Management • Security Governance • Incident Response • Access Reviews • IAM • Asset Management • Change Management • Vulnerability Management • Qualys • Security Awareness

Experience

2 yrs 5 mos
Total Experience
2 yrs 5 mos
Average Tenure
2 yrs 5 mos
Current Experience

Aws cloud lab/project

GRC Analyst | Cloud Risk & Identity Governance

Jan 2026Present · 3 mos · Africa · On-site

  • Built and operated hands-on governance, risk, and compliance programs combining security frameworks with real-world cloud implementations. My work focuses on translating standards like NIST 800-53, NIST CSF, and ISO 27001 into practical, auditable controls.
  • Key highlights:
  • Designed a full-stack fintech GRC program including risk register development, executive reporting, and third-party risk governance.
  • Authored core security policies and control documentation mapped to audit evidence requirements.
  • Implemented cloud identity governance in AWS aligned to NIST 800-53 AC-2, enforcing least-privilege IAM architecture and MFA for privileged users.
  • Produced audit-ready artifacts including SSP control narratives, risk documentation, and control-to-evidence mappings.
  • Focused on bridging technical cloud security with governance and audit readiness.
GovernanceRisk ManagementComplianceNIST 800-53ISO 27001Cloud Security+2

Paynest (independent project)

GRC Analyst — PayNest FinTech Risk & Governance Program

May 2025Present · 11 mos · Africa · On-site

  • Designed and implemented an end-to-end Governance, Risk, and Compliance (GRC) program for a cloud-based fintech environment handling regulated customer data.
  • This structured case study was built to demonstrate real-world GRC decision-making, governance design, and executive risk communication.
  • Key contributions:
  • Built enterprise risk register and mitigation frameworks aligned with ISO 27001 and NIST 800-53 principles
  • Developed governance structure, policies, and third-party risk management processes
  • Created executive-ready risk artifacts including heat maps, dashboards, and board reporting templates
  • Designed risk mitigation plans and lifecycle remediation tracking
  • Delivered full GRC lifecycle from risk identification through executive communication
  • Focused on translating complex risk into clear, decision-ready insights for leadership.
GovernanceRisk ManagementComplianceISO 27001NIST 800-53Risk Artifacts+2

Pwc

Security Analyst Intern

May 2024Present · 1 yr 11 mos

Self-employed

3 roles

Active Directory using PowerShell Lab

Feb 2024Present · 2 yrs 2 mos

  • Implemented robust PowerShell scripts for automating Active Directory tasks, enhancing efficiency and reducing manual errors in user provisioning, de-provisioning, and group management.
  • Conducted comprehensive security assessments on the Active Directory environment, identifying and mitigating vulnerabilities, ensuring a resilient defense against potential cyber threats.
  • Developed and maintained a robust monitoring system using PowerShell to detect and respond to suspicious activities within the Active Directory, enhancing the overall cybersecurity posture.
PowerShellActive DirectorySecurity AssessmentsSecurity Operations

Security Specialist

Dec 2023Present · 2 yrs 4 mos

LinuxSecurity OperationsPython

Malware Removal and SIEM Using Microsoft Sysmon with PowerShell

Nov 2023Present · 2 yrs 5 mos

  • Implemented Sysmon, PowerShell scripts, and PStools to enhance malware detection and removal capabilities within the project lab environment.
  • Leveraged the combined power if Sysmon, PowerShell scripts, and PStools to enhance visibility into system activities, enabling proactive threat detection and incident response.
  • Developed custom PowerShell scripts to automate response actions to security events detected by Sysmon, streamlining incident response procedures and reducing manual intervention.
  • Conducted in-depth event log analysis using Sysmon and PowerShell, providing valuable insights into system behaviour and identifying potential security threats.
PowerShellSysmonMalware DetectionSecurity Operations

Cloud engineer

Graduate

Dec 2023Present · 2 yrs 4 mos

Education

Federal University of Technology Minna

Bachelor of Technology - BTech — Industrial Chemistry

Sep 2016Apr 2023

Stackforce found 100+ more professionals with Governance, Risk & Compliance (grc) & Cloud Security

Explore similar profiles based on matching skills and experience