Virtual CISO & AI Governance Advisor
25 years building and leading security programs for regulated institutions. Available on retainer, working remotely.
Start a conversationWhat I do
For organizations that need CISO-level judgment and oversight without a full-time hire. I work with your security team, report to your board, and take ownership of the security programme alongside you, on retainer.
Risk frameworks for autonomous and agentic AI systems. Board-level guidance on AI adoption decisions, regulatory gap analysis, and governance structures for organizations deploying AI at scale. Grounded in active PhD research in agentic AI governance.
Fraud risk advisory for banks and financial services organizations facing increasingly sophisticated threats in the age of digital banking and AI enabled fraud. Covering fraud risk frameworks, controls assessment, and governance for digital channels.
Security risk management, compliance programme design, and regulatory readiness across ISO 27001, NIST, PCI DSS, QCB Technology Risk, National Information Assurance, and other GCC and South Asian frameworks.
Selected work
Led cybersecurity advisory for a Qatari bank under the national critical infrastructure protection programme ahead of the FIFA World Cup. Achieved the highest compliance maturity rating across multiple cybersecurity domains under the Qatar 2022 framework. Zero security incidents through the tournament period.
Currently the dedicated security advisor to AlRayan Bank (formerly Masraf Al Rayan), leading governance across the bank's core banking migration, digital banking expansion, cloud adoption, and AI adoption programme. Working with the same security function I originally built and led from 2009 to 2018.
Built and run an independent advisory practice serving clients across banking, telecom, and government in the GCC and South Asia. Engagements include virtual CISO advisory, third-party risk assessments for e-government initiatives, and cloud security governance for digital transformation programmes.
About
I started as an engineer and ended up at the table where technology, risk, and regulation collide. I have built security programs from zero, run them as CISO, and directed advisory engagements at EY and as an independent practice.
My practice covers virtual CISO advisory for regulated institutions, digital fraud risk management for banks navigating the threat landscape that comes with digital banking and AI enabled fraud, GRC and regulatory compliance, and AI governance for boards adopting autonomous systems.
On AI governance specifically, I am a PhD researcher in agentic AI governance. I am not commenting on where this is going from the outside. I am in the literature, helping to shape it.
I work onsite, online, or hybrid depending on what the engagement needs. My primary markets are the GCC and South Asia, though I am open to engagements in other regions. My clients are typically regulated institutions that need senior security judgment without a full-time hire.
Get in touch
USD 2,500 / day
Advisory engagements start at USD 2,500 per day with a minimum commitment of 10 days. Retainer and long-term arrangements are structured differently. Let's talk.