Skip to content
View Nouman-J-Nizami's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report Nouman-J-Nizami

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Nouman-J-Nizami/README.md

Hi, I'm Nouman Nizami 👋

Cybersecurity Analyst | GRC & Compliance | ISO/IEC 27001 | NIS2 | Risk Management

I combine an industrial engineering background with hands-on cybersecurity training and practical security projects, with a focus on Governance, Risk & Compliance (GRC), information security, security operations, risk management, and regulatory frameworks.

My portfolio focuses on applying security and compliance principles to realistic enterprise scenarios, with particular interest in European cybersecurity and regulatory requirements.


🎓 Certifications & Training

  • CompTIA Security+ (SY0-701)
  • ISO/IEC 27001 Lead Implementer (Provisional) — PECB
  • Master in Cybersecurity & Ethical Hacking (Professional Program) — EPICODE Institute of Technology
  • ⁠Diploma in Mechanical Engineering

🔎 Focus Areas

  • Governance, Risk & Compliance (GRC)
  • ISO/IEC 27001 & Information Security Management Systems (ISMS)
  • NIS2 & Cybersecurity Regulatory Compliance
  • DORA & ICT Operational Resilience
  • GDPR & Privacy Risk Management
  • ISO/IEC 42001 & AI Governance
  • Enterprise Risk Assessment
  • Security Controls & Control Mapping
  • Identity & Access Management (IAM)
  • Third-Party & ICT Risk
  • Security Operations & Incident Response
  • Industrial & OT Cybersecurity

🛡️ Enterprise GRC Portfolio

A structured portfolio of synthetic enterprise case studies demonstrating practical application of Governance, Risk & Compliance principles across information security, privacy, operational resilience, identity governance, AI governance, and European regulatory frameworks.

Featured Assessments


🧩 Cybersecurity Projects

Selected practical cybersecurity projects covering security monitoring, vulnerability assessment, network security, threat intelligence, and security operations.

Areas include:

  • SIEM & security monitoring
  • Wazuh
  • Splunk
  • Nmap
  • Nessus
  • Wireshark
  • Burp Suite
  • Metasploit
  • Vulnerability assessment
  • Network security
  • Threat intelligence
  • MITRE ATT&CK
  • Incident response
  • Security testing

🛠️ Tools & Technologies

Security & Monitoring

Splunk Wazuh Nmap Nessus Wireshark

Security Testing

Burp Suite Metasploit Kali Linux DVWA OWASP

Security & Risk

SIEM EDR NDR Threat Intelligence Vulnerability Management

Governance & Compliance

ISO/IEC 27001 NIS2 DORA GDPR ISO/IEC 42001 GRC Risk Assessment Control Mapping ISMS IAM


📊 Professional Interests

I am particularly interested in roles involving:

  • Cybersecurity Governance
  • GRC & Compliance
  • Information Security
  • Risk Management
  • Security Operations
  • ISMS
  • Regulatory Compliance
  • ICT Risk & Operational Resilience
  • IAM & Access Governance
  • AI Governance
  • Industrial & OT Cybersecurity

📌 Portfolio Approach

The projects in this portfolio are designed as structured professional case studies rather than claims of client engagements.

They demonstrate how security and compliance requirements can be translated into:

Requirements → Risks → Controls → Evidence → Testing → Findings → Remediation → Management Reporting

The objective is to demonstrate practical analytical thinking, risk-based decision making, control governance, and the ability to connect multiple regulatory and security requirements within an enterprise operating model.


⚠️ Disclaimer

The portfolio assessments are synthetic case studies created for professional demonstration and learning purposes.

They do not represent real client engagements, confidential information, audit opinions, legal or regulatory advice, certification evidence, or production implementations.


📫 Let's Connect

LinkedIn

📍 Based in Upper Austria, Austria

Pinned Loading

  1. ISO27001_Cloud_Migration_Risk_Assessment ISO27001_Cloud_Migration_Risk_Assessment Public

    Governance, Risk and Compliance case study covering risk assessment, treatment planning, control mapping and cloud security governance. compliance, cloud security and risk management.

  2. ISO27031-Business-Continuity-and-Disaster-Recovery ISO27031-Business-Continuity-and-Disaster-Recovery Public

    Business Continuity, Disaster Recovery and ICT Readiness analysis based on ISO/IEC 27031.

  3. Cyber-Risk-Threat-Assessment-Report-Aligned-with-ThreatConnect-OWASP-Top-10-and-MITRE-ATT-CK Cyber-Risk-Threat-Assessment-Report-Aligned-with-ThreatConnect-OWASP-Top-10-and-MITRE-ATT-CK Public

    Cyber risk and threat assessment project aligned with MITRE ATT&CK, OWASP Top 10, ISO 27001, NIST, and Threat Intelligence methodologies.

    1

  4. Vulnerability-Assessment-and-Security-Analysis-Report Vulnerability-Assessment-and-Security-Analysis-Report Public

    Security assessment project focused on vulnerability identification, risk analysis, remediation planning, and security posture improvement.

  5. Cybersecurity_Incident_Response_SOC_CSIRT_Wazuh_SIEM_Lab_Report Cybersecurity_Incident_Response_SOC_CSIRT_Wazuh_SIEM_Lab_Report Public

    Incident response and SOC operations project using Wazuh SIEM/XDR for threat detection, investigation, alert analysis, and security monitoring.

    1

  6. Social-Engineering-Laboratory-Report-Phishing-Simulation-and-Credential-Harvesting Social-Engineering-Laboratory-Report-Phishing-Simulation-and-Credential-Harvesting Public

    Social Engineering awareness and phishing simulation project using SET (Social Engineering Toolkit) to analyze credential harvesting techniques and improve security awareness.

    1