GRC Consultant β’ Security Researcher
Exploring the intersection of security, governance, and technology β designing safe systems and advancing cybersecurity through research and practice.
I'm a cybersecurity professional currently pursuing an Erasmus Mundus Joint Master's in Applied Cybersecurity (CyberMACS), studying across prestigious universities in Istanbul, Berlin, and Skopje. This unique program combines technical depth with international perspectives on cybersecurity challenges.
My journey began with a Bachelor's in Electrical Engineering (Telecommunications) from NUCES Pakistan, where I graduated as Batch Gold Medalist with a 3.70 GPA. My thesis on "Secure VPN Gateway with Pi-Router" sparked my transition into cybersecurity.
I bring practical experience from roles at KPMG (auditing segregation of duties), Programmers Force (GRC analysis across ISO 27001, SOC 2, PCI-DSS), and as a freelance GRC consultant helping SMEs achieve ISO 27001 and ISO 27701 certification.
Beyond technical work, I'm active in the community through IEEE leadership roles, serving on technical program committees for international conferences, and representing students in the CyberMACS Quality Assurance Committee.
"Usman has consistently distinguished himself as an academically mature and intellectually curious professional. He possesses a solid, well-balanced foundation in cybersecurity, with particular strengths in information security governance, risk management, data privacy, and the application of artificial intelligence to security contexts."
"I have worked closely with Usman since 2020 as his academic mentor, when he joined me on my work on AI-based Detection Systems (IDS). While many students limit to completing assigned tasks, Usman went further, seeking a thorough understanding of methods for critically evaluating and improving their effectiveness in detecting security threats."
"Usman has strong grip on information security frameworks. His natural capabilities combined with his hardworking attitude make him a valuable team member. His collaborative approach and innovative thinking make him an asset to any cybersecurity team."
Kadir Has University (KHAS), Istanbul
SRH University of Applied Sciences Heidelberg, Campus Berlin
Ss. Cyril and Methodius University (UKIM), Skopje
Major: Telecommunication
Thesis: Secure VPN Gateway with Pi-Router
15+ peer-reviewed publications in cybersecurity, IoT security, and machine learning
Developed a Python-based pipeline to parse and normalize NVD CVE feeds, linking them to NIST CSF 2.0, CPE, and CWE standards. Engineered a unified, LLM-ready dataset with normalized CVSS scores and validated cross-references to support actionable security intelligence.
Conducted detailed research analysis on North Korea's RGB Group, its organizational structure and cyber operations, focusing on hybrid warfare, financial crime for sanctions evasion, and tactical analysis using the MITRE ATT&CK framework.
Bachelor's thesis project developing a cost-effective VPN gateway solution using Raspberry Pi. Implemented secure routing protocols and network segmentation for enhanced privacy and security.
Sharing knowledge and insights with the cybersecurity community
Interactive workshop on cybersecurity governance and data privacy compliance. Covering the implementation of ISO 27001, NIST, and GDPRthrough real-world risk management scenarios and hands-on incident response tabletop exercises.
Informative session providing a clear understanding of Erasmus Mundus opportunities, practical strategies for building a competitive application, and first-hand insights from my personal journey as a scholarship awardee.
Guest session highlighting the benefits of joining IEEE as a student, including access to global networks, technical resources, leadership opportunities, and career development pathways in engineering and technology.
Delivered an invited talk on IEEE OU Analytics, IEEE CLE, and the VoLT Program, focusing on data-driven leadership and organizational excellence. The session highlighted strategic tools for volunteer leadership development and member engagement within the IEEE Islamabad Section.
Comprehensive technical and professional capabilities developed through academic research, industry experience, and continuous professional development
Information security management systems and regulatory compliance frameworks
Hands-on security assessment and defensive operations
Academic research and machine learning applications in cybersecurity
Software development and automation capabilities
Leadership and communication capabilities
System administration and platform expertise
Multilingual communication skills for international professional collaboration










Supporting the evaluation, development, and continuous improvement of academic and quality standards within the CyberMACS program.
Reviewing research papers in cybersecurity and network technologies.
Technical review and program organization for international conference.
ExCom Member directing strategic plan execution for Peshawar Sub-Section. Facilitated inter-university coordination and represented IEEE at sectional events.
Reactivated IEEE student branch from dormant to active status. Directed campus execution of IEEE SAC Leadership Summit 2022 and designed policies to optimize volunteer engagement.
Highlights from conferences, events, and professional engagements
Interviews, talks, and media features
Event Highlights and comments on key takeaways from ORSHIN Summer School 2025
One Semester in CyberMACS! -- Discussing career journey and research opportunities
First Month in CyberMACS! -- Sharing student experience the programme
FAST-NUCES Inter-University Debate Competition 2022
British High Commission Intra-University Debate Competition 2020
Available for GRC consulting, security research collaboration, and speaking engagements
Whether you need comprehensive risk assessments, ISO 27001 implementation, or want to discuss cutting-edge cybersecurity researchβI'm here to collaborate.