Enter your keyword

Bola Mabawonku
Bola Mabawonku
Edmonton, AB · Canada
• Open to work
// Senior Cybersecurity Leader · CISM · CRISC · CISSP · CCSP

Senior GRC Manager
& Cloud Security Architect

Five-plus years · Financial Services · Healthcare · Technology

I build security programs that protect organizations, govern cloud environments at scale, and give boards the visibility they need to make risk decisions.

CISM CRISC CISSP CCSP MBA
// Program outcomes
Years experience5+
Documented projects9
Active certifications4
Cloud platforms3
OCC examinationZero findings
// Flagship project — Project 00
Greenfield Cybersecurity Program Build — Community Financial Institution
Built the institution’s first cybersecurity program from zero as the sole security leader, covering strategy, 30+ policies, NIST CSF implementation, an ISO 27001-aligned ISMS, board governance, vulnerability management, and security awareness. The CBN examination cleared with four low-risk findings.
4
Low-risk findings
30+
Policies authored
18mo
Zero to board-ready
78%
Misconfiguration reduction — multi-cloud CSPM
340+
IAM users eliminated → federated SSO
65%
MTTD reduction — Sentinel + 18 KQL rules
9 days
SOC 2 + ISO 27001 evidence cycle
Selected Projects
View all 9 projects →
Cloud Security · CSPM
Enterprise Cloud Security Posture Management
Multi-cloud CSPM across AWS, Azure, and GCP covering 2,400+ assets — 78% critical misconfiguration reduction in 90 days, first clean internal audit in three years.
78% reduction2,400+ assetsClean audit
IAM · Least Privilege
Cloud IAM Governance & Least-Privilege Program
Eliminated 340+ individual IAM users across 18 AWS accounts — federated SSO, CyberArk JIT, zero standing privileged accounts for 12 consecutive months. ITGC finding closed.
340+ consolidated0 standing privilegesITGC closed
AI Governance · Risk Management
AI Risk Governance Framework
Built an enterprise AI risk governance framework for a managed services provider — 15 AI use cases classified, 100% endpoint coverage, questionnaire turnaround cut to same-day.
15 AI use cases100% endpoint coverageNIST AI RMF 1.0
Security Awareness · Human Risk
Next-Generation Security Awareness & Human Risk Management Programme
Built a next-generation security awareness program addressing AI-era threats — phishing click rate cut from 34% to under 6%, with 97% completion across two simulation cycles.
34% → 6% click rate97% completion100% board completion
Core Specialisms
🔲
Governance, Risk & Compliance
Enterprise GRC program design, risk appetite frameworks, Board Risk Committee reporting, OCC and FFIEC regulatory examination management.
☁
Cloud Security Architecture
Multi-cloud CSPM, IAM governance at scale, policy-as-code via SCPs, continuous security posture management across AWS, Azure, and GCP.
🔍
Detection & Incident Response
Microsoft Sentinel, custom KQL detection rules, MITRE ATT&CK for Cloud mapping, SOAR automation, cloud IR playbooks aligned to NIST SP 800-61 Rev 3.
📋
Regulatory Compliance
NIST CSF 2.0 (all 6 functions including Govern), ISO 27001:2022, SOC 2 Type II, HIPAA, PCI DSS v4.0, FFIEC CAT, CBN Framework, NDPA 2023, PIPEDA.
🤝
Third-Party Risk Management
120+ vendor assessments, risk-tiered TPRM frameworks, SOC 2 attestation requirements, DORA Article 30 supply chain compliance, vendor offboarding.
🧠
AI Governance & Human Risk
AI risk management under NIST AI RMF and EU AI Act, deepfake-aware security awareness, phishing simulation — click rate reduced from 34% to 6%.
Frameworks & Standards
NIST CSF 2.0 ISO 27001:2022 SOC 2 Type II HIPAA PCI DSS v4.0 FFIEC CAT MITRE ATT&CK CIS Benchmarks NIST AI RMF DORA NDPA 2023 PIPEDA CBN Framework NIST SP 800-61 Rev 3
Thought Leadership
View all articles →
🤖
AI Governance
AI Risk Governance: The Framework Security Leaders Need Now
NIST AI RMF, EU AI Act risk tiers, shadow AI inventory, and practical implementation steps for security leaders governing AI adoption in regulated environments.
⚡
Regulatory · DORA
DORA is Live — and Most Financial Institutions Are Underprepared
The four most common DORA compliance gaps: ICT vendor registers, missing contract clauses, no tested exit strategy, and misunderstanding the TLPT scope requirement.
// Open to new opportunities
Let’s work together.

Senior GRC Manager, Cloud Security Architect, and CISO roles across Alberta and Canada — available from September 2026.

bmabawonku@bolamabawonku.com
Connect on LinkedIn → View Evidence Vault