🏆 TryHackMe Top 1% Worldwide • Diamond League Champion

From HR & Recruitment to Cybersecurity & GRC

I bring 10+ years of HR & recruitment experience (process, compliance, stakeholder management) into Cybersecurity, GRC, and AI Governance—with a portfolio built on hands-on execution, not just theory.

My Foundation: Governance Before I Called It “GRC”

My career started in HR and technical recruitment, where I spent over a decade building teams, running structured processes, and operating in compliance-driven environments across India, Canada and US. That background trained me to work with documentation, audits, controls, and leadership expectations—skills that translate directly into security governance.

The Pivot: May 2025 — I Started Cybersecurity From Zero

On May 24, 2025, I began my cybersecurity journey on TryHackMe with one goal: build real capability through consistent practice. Within months, I completed the Jr. Penetration Tester path, finished SOC Level 1, and rose into the Top 1% globally (4M+ users), earning Diamond League Champion status.

My mindset: learn fast, document cleanly, and prove it with evidence.

My Lab: Practice That Mirrors Real Environments

I didn’t rely on rented labs or “follow-along” simulations. I built my own home lab to practice both offense and defense—because strong GRC needs real-world context.

Attack & Validation
  • Kali Linux for recon and testing
  • Metasploit for controlled exploitation
  • Custom scripts and repeatable workflows
Detection & Monitoring
  • Wazuh SIEM for telemetry and alerts
  • Log analysis and incident investigations
  • Network segmentation and lab hardening
Enterprise Simulation
  • Active Directory scenarios
  • Privilege escalation and access testing
  • Policy and control validation mindset

Discovering GRC: Where Everything Connected

As my security understanding grew, I realized the real value happens when security becomes governance—measurable, auditable, and aligned to business decisions. That’s when I moved fully into GRC and AI Governance and validated my learning through certifications:

ISO/IEC 27001:2022 Lead Auditor (Mastermind)
ISO/IEC 42001:2023 Lead Auditor (AI Governance) (Mastermind)
Governance, Risk, Compliance, and Data Privacy (IBM)
Vulnerability Management (IBM)
PrivacyOps (Securiti)
AI Security & Governance (Securiti)
Certified Cybersecurity Educator Professional (CCEP) (Red Team Leaders)
Qualys Certified Specialist – VMDR (Vulnerability Management, Detection, and Response)
AWS Certified Solutions Architect – Associate
AWS Certified Cloud Practitioner
TryHackMe: SOC Level 1
TryHackMe: Jr Penetration Tester
Cisco: Introduction to Cybersecurity
Cybersecurity Job Simulations (Forage): AIG • PwC • Mastercard • Datacom • Tata (Issued Oct 2025)

Today I focus on practical delivery: risk assessments, control mapping, evidence-ready documentation, and governance programs that work in the real world.

GRC Made Simple: Turning Complexity Into Clarity

I run GRC Made Simple—a YouTube channel where I publish practical, no-fluff content on GRC and cybersecurity. My goal is simple: help professionals execute, not just study.

Watch on YouTube → Open GRC Practice Lab →

The GRC Practice Lab: Portfolio-Grade, Not Costly

A common problem in GRC is that practice is either expensive, locked behind enterprise tools, or too theoretical. So I built a GRC Practice Lab to simulate real workflows:

Real Workflows
  • Assets → Risks → Controls → Treatments
  • ISO SoA completion and reporting
  • Inherent vs Residual risk analytics
Portfolio Output
  • Resume-ready bullet points
  • PDF export for interview evidence
  • Project-based learning path

My focus: prove capability with evidence—clean, structured, audit-ready work.

What I’m Looking For (GCC / UAE)

I’m actively exploring roles across the GCC / UAE (and open to remote globally), including: GRC Analyst, Cybersecurity Analyst (Governance), Risk & Compliance, ISO Program, and AI Governance roles.

If your organization is building a secure, compliant, and future-ready program—and you value execution, clarity, and evidence—let’s connect.