From HR & Recruitment to Cybersecurity & GRC
I bring 10+ years of HR & recruitment experience (process, compliance, stakeholder management) into Cybersecurity, GRC, and AI Governance—with a portfolio built on hands-on execution, not just theory.
My Foundation: Governance Before I Called It “GRC”
My career started in HR and technical recruitment, where I spent over a decade building teams, running structured processes, and operating in compliance-driven environments across India, Canada and US. That background trained me to work with documentation, audits, controls, and leadership expectations—skills that translate directly into security governance.
The Pivot: May 2025 — I Started Cybersecurity From Zero
On May 24, 2025, I began my cybersecurity journey on TryHackMe with one goal: build real capability through consistent practice. Within months, I completed the Jr. Penetration Tester path, finished SOC Level 1, and rose into the Top 1% globally (4M+ users), earning Diamond League Champion status.
My mindset: learn fast, document cleanly, and prove it with evidence.
My Lab: Practice That Mirrors Real Environments
I didn’t rely on rented labs or “follow-along” simulations. I built my own home lab to practice both offense and defense—because strong GRC needs real-world context.
- Kali Linux for recon and testing
- Metasploit for controlled exploitation
- Custom scripts and repeatable workflows
- Wazuh SIEM for telemetry and alerts
- Log analysis and incident investigations
- Network segmentation and lab hardening
- Active Directory scenarios
- Privilege escalation and access testing
- Policy and control validation mindset
Discovering GRC: Where Everything Connected
As my security understanding grew, I realized the real value happens when security becomes governance—measurable, auditable, and aligned to business decisions. That’s when I moved fully into GRC and AI Governance and validated my learning through certifications:
Today I focus on practical delivery: risk assessments, control mapping, evidence-ready documentation, and governance programs that work in the real world.
GRC Made Simple: Turning Complexity Into Clarity
I run GRC Made Simple—a YouTube channel where I publish practical, no-fluff content on GRC and cybersecurity. My goal is simple: help professionals execute, not just study.
The GRC Practice Lab: Portfolio-Grade, Not Costly
A common problem in GRC is that practice is either expensive, locked behind enterprise tools, or too theoretical. So I built a GRC Practice Lab to simulate real workflows:
- Assets → Risks → Controls → Treatments
- ISO SoA completion and reporting
- Inherent vs Residual risk analytics
- Resume-ready bullet points
- PDF export for interview evidence
- Project-based learning path
My focus: prove capability with evidence—clean, structured, audit-ready work.
What I’m Looking For (GCC / UAE)
I’m actively exploring roles across the GCC / UAE (and open to remote globally), including: GRC Analyst, Cybersecurity Analyst (Governance), Risk & Compliance, ISO Program, and AI Governance roles.
If your organization is building a secure, compliant, and future-ready program—and you value execution, clarity, and evidence—let’s connect.