Wais A
Senior Information Security Consultant @Independent Consultant
Signup · Get unlimited contacts
WORK HISTORY
Senior Information Security Consultant @Independent Consultant
Toronto, ON, CA
4 years |~10 client engagements | Public & Private SectorImpact Summary:Supported 10+ enterprise engagements, including SOC 2, ITGC, and PCI DSS audits, 200+ third-party vendor assessments,150+ project security assessments, and hundreds of systems and cloud workloads across regulated environments.Key Responsibilities & Expertise:• Led AI Governance initiatives, including risk assessments, policy development, and responsible-AI control frameworks• Designed and reviewed security architecture for cloud, hybrid, and on-prem environments• Delivered cloud security assessments and control alignment across Azure, Microsoft 365, and GCP• Conducted IT security audits, control testing, and audit-readiness activities (SOC 2, ISO-aligned, PCI DSS)• Performed project, operational, and enterprise security risk assessments• Executed third-party security risk assessments, vendor due diligence, and ongoing risk tracking• Led vulnerability management programs, including risk-based prioritization, remediation tracking, and executive reporting• Developed data analytics and visualization (Power BI dashboards, KPIs, KRIs) to support security governance and decision-making• Led SOC 2 Type I & Type II audit readiness, evidence coordination, and gap remediation• Led PCI DSS v4.0 audit and readiness engagements, including scope definition, gap assessments, and remediation roadmaps
EDUCATION
American University of Afghanistan (AUAF)
Bachelor of Science (BSc), Computer Science & IT
Rochester Institute of Technology
Master of Business Administration (MBA), Management Information Systems, General
Portland State University
Intensive English Language Program, English Language and Literature, General
SKILLS
ABOUT WAIS A
Senior Security Consultant | Cybersecurity & GRC Leader15+ years advising public sector, private sector, and Fortune 500 organizations on cybersecurity strategy, governance, risk, and compliance, translating technical risk into business-aligned decisions. Expertise across GRC, security architecture, cloud security, PCI DSS, SOC 2, third-party risk, and audit readiness, with a growing focus on AI governance and AI risk management. CISM, CISA, CRISC certified.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.