Rufai Ahmad
Information Security and Governance Manager(Security Consultancy) @NHS National Services Scotland
Signup · Get unlimited contacts
WORK HISTORY
Information Security and Governance Manager(Security Consultancy) @NHS National Services Scotland
As part of my role, I contribute to strengthening the organisation’s information security and governance framework by:1. Conducting comprehensive risk assessments, including Data Protection Impact Assessments (DPIAs) and System Security Policy (SSPs), for new or evolving data processing activities.2. Identifying and assessing potential threats and vulnerabilities to information assets, ensuring proactive mitigation measures are in place.3. Reviewing and supporting the development of information security policies, procedures, and guidance to align with industry best practices and regulatory requirements.4. Evaluating the effectiveness of existing controls to ensure systems are adequately protected against cyber threats and security incidents.5. Promoting awareness and training across the organisation to embed a strong culture of information security and governance.6. Monitoring and verifying regulatory compliance to ensure adherence to applicable data protection, privacy, and information security laws and standards.7. Participating in Third-party risk management (TPRM) activities
EDUCATION
University of Sussex
Msc Information Technology with Business and Management, Information Technology
Brunel University of London
Bachelor of Science, Computer Science
University of Strathclyde
Doctor of Philosophy, Computer and Information Systems Security/Information Assurance
SKILLS
ABOUT RUFAI AHMAD
Information Security professional with a strong foundation in Security Operations and advanced expertise in risk management, governance, and security consulting. Leveraging hands-on SOC experience, I bring a deep understanding of threats, incident response, and operational security, now expanded into leading risk assessments, DPIAs, policy development, and security control design. Adept at translating complex technical risks into clear business insights, influencing stakeholders, and guiding the implementation of organisational security strategies. Recognised for driving security awareness, aligning programmes with regulatory standards, and leading cross-functional initiatives that elevate security maturity and resilience across the organisation.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.