Duncan O.
vCISO | Cybersecurity Consultant | ISO 27001 | Security Operations
I am a cybersecurity leader and consultant with 12+ years of experience helping organizations strengthen their security posture, reduce cyber risk, achieve compliance, and build resilient security programs across banking, telecommunications, managed security services, and enterprise environments. As a virtual Chief Information Security Officer (vCISO), I support organizations that need executive-level cybersecurity leadership without the cost of a full-time CISO. I help businesses define security strategies, establish governance frameworks, manage cyber risks, improve compliance readiness, and align security investments with business objectives. My experience includes leading enterprise cybersecurity programs, managing Security Operations Centers (SOC), overseeing incident response, conducting vulnerability management, coordinating penetration testing activities, implementing security controls, and advising senior leadership and boards on cyber risk. Services I Offer: Virtual CISO (vCISO) Services * Cybersecurity strategy development and execution * Security roadmap creation and maturity assessments * Cyber risk management and executive reporting * Security governance, policies, standards, and procedures * Board and leadership cybersecurity advisory * Third-party risk management Security Assessment & Compliance * Cybersecurity gap assessments * ISO 27001 readiness and implementation support * PCI DSS implementation * SWIFT CSP security advisory * Regulatory compliance alignment * Security policy development Security Engineering & Operations * Security architecture reviews * Vulnerability assessments and remediation programs * Penetration testing coordination and remediation tracking * SIEM monitoring and SOC improvement * Incident response planning and execution * Endpoint, network, email, and cloud security deployments Cloud & Infrastructure Security * AWS and Azure security reviews * Secure cloud configuration assessments * Identity and access management (IAM) * Network security architecture * Secure infrastructure design Why Clients Work With Me I combine hands-on technical expertise with executive-level cybersecurity leadership. I have worked with complex environments where security, compliance, operational resilience, and business objectives must work together. My background includes: * Chief Information Security Officer experience within financial services * Leading enterprise information security programs * Managing security operations and incident response teams * Designing and deploying security solutions across network, endpoint, email, and cloud environments * Working with auditors, regulators, technology partners, and executive stakeholders I hold industry-recognized certifications including CISM, EC-Council Certified CISO, ISO 27001 Lead Auditor, GIAC Certified Incident Handler (GCIH), AWS Security Specialty, AWS Solutions Architect, and other security certifications. Whether you are a startup needing your first security program, a growing company preparing for compliance, or an enterprise looking to mature your cybersecurity capabilities, I can help you build practical, effective, and business-aligned security solutions.