Mustafa Alobaidy - Senior GRC Professional

Mustafa Alobaidy

Senior GRC Professional · ISO 27001 Lead Implementer · Governance & Compliance Specialist

7 Years Securing Enterprise Governance Across Amazon, Ten Group & Beyond

Download CV

About Me

Professional Profile

Mustafa Alobaidy
Arabic (Native) · English (Fluent)

Senior Governance, Risk & Compliance (GRC) professional with 7 years of experience designing and implementing regulatory compliance programmes, governance frameworks, enterprise risk management practices, and policy frameworks across multinational organisations.

Experienced partnering with Legal, Operations, Risk, and executive leadership to develop compliance controls, conduct regulatory gap analyses, implement monitoring programmes, and strengthen organisational governance. Strong background in policy development, compliance monitoring, stakeholder engagement, and executive reporting across Amazon, Ten Group, Meltwater, and consulting engagements.

0+

Years Experience

0

Major Employers

0+

Certifications

0

Portfolio Engagements

Career Journey

Professional Experience

2020 – Present

Babylon Corporation

Founder | ISO 27001 Consultant | Principal GRC Consultant

Cape Town
  • Founded an independent GRC and cybersecurity consulting practice supporting SMEs with governance, compliance readiness, and risk management.
  • Led ISO 27001 implementation, ISMS design, gap assessments, and policy development for multiple clients.
  • Advised executive leadership on regulatory compliance risks and governance improvements.
  • Delivered cybersecurity awareness programmes, executive security briefings, and governance training.
2021 – 2025

Ten Group

Information Security Governance & ISO 27001 Lead

Cape Town
  • Led cybersecurity governance for a global organisation serving royal families, HSBC, Visa, SAB, and embassies across the Middle East and Europe.
  • Maintained and continuously improved the ISMS, coordinating ISO 27001 audits and certification readiness.
  • Conducted third-party security assessments, vendor due diligence, and supplier security reviews.
  • Reported governance and compliance status to executive leadership through dashboards and executive reporting.
2019 – 2022

Meltwater

Compliance Reporting & Governance Analyst

Cape Town
  • Delivered governance, risk, and compliance reporting for government and financial sector stakeholders.
  • Produced executive governance reports, cyber risk briefings, and compliance dashboards.
  • Monitored governance controls and operational risks, identifying control gaps and recommending corrective actions.
  • Led governance and cybersecurity awareness training, strengthening policy adherence and security culture.
2017 – 2019

Amazon

Regional Governance & Risk Analyst (EMEA)

Cape Town
  • Managed enterprise governance, compliance, and risk management across EMEA operations.
  • Conducted enterprise and operational risk assessments, developing SOPs and governance procedures.
  • Maintained enterprise risk registers, Key Risk Indicators (KRIs), and executive reporting.
  • Delivered governance training and security awareness to multilingual teams across EMEA.

Credentials

Certifications & Education

CompTIA Security+

Achieved

ISO 27001 Lead Implementer

Achieved

Google Cybersecurity Professional Certificate

Achieved

ISACA Certifications

All Exams Passed

CDPSE

Certified Data Privacy Solutions Engineer

CGEIT

Certified in Governance of Enterprise IT

CISA

Certified Information Systems Auditor

CISM

Certified Information Security Manager

CRISC

Certified in Risk and Information Systems Control

BA Honours

University of the Western Cape

In Progress

Expertise

Skills & Competencies

Frameworks & Standards

ISO 27001:2022SOC 2 Type IINIST CSFCIS ControlsCyber Resilience ActNIS2EU AI ActISO 42001

Tools & Platforms

ExcelPower BIJiraConfluenceServiceNow GRCVantaDrataMicrosoft Purview

Regulatory Compliance

Compliance Programme ManagementRegulatory Gap AnalysisCompliance MonitoringConsumer ProtectionPolicy GovernanceRegulatory Reporting

Enterprise Risk Management

Risk Identification & AssessmentRisk RegistersRisk Treatment PlansKey Risk IndicatorsOperational ResilienceRisk Governance

Governance & Business Analysis

Governance Framework DesignPolicy DevelopmentExecutive ReportingRequirements GatheringProcess MappingStakeholder Workshops

Agile & Delivery

ScrumSprint PlanningBacklog RefinementUser Acceptance TestingJiraConfluence

Portfolio

Consulting Engagements

Selected projects demonstrating governance, risk management, and compliance expertise across diverse industries.

FinTech

vCISO Cybersecurity Governance Strategy

PaySecure Financial

Served as Virtual CISO for a UAE fintech processing AED 2.5B in annual transactions.

  • NIST CSF & ISO 27001 maturity assessment
  • Enterprise risk register & risk dashboard
  • Data governance & privacy roadmap
  • AI governance recommendations
Cloud Technology

GRC Advisory & Compliance Readiness

CloudVault Technologies

Dual ISO 27001 & SOC 2 readiness assessment for a growing cloud technology provider.

  • Security maturity assessment
  • Control mapping & gap analysis
  • 12-month compliance roadmap
  • AI regulatory readiness guidance
SaaS

ISO 27001:2022 Gap Assessment

CloudSync Technologies

Readiness assessment for a $35M SaaS provider supporting 500+ B2B clients on AWS.

  • Evaluation of all 93 Annex A controls
  • Risk register & treatment plan
  • Audit-ready compliance documentation
  • 9–12 month certification roadmap
E-commerce

Cybersecurity Awareness Transformation

ShopNow Digital

Security awareness programme for a 220-employee Azure-based e-commerce organisation.

  • Human risk assessment
  • Role-based security awareness training
  • Phishing simulation programme
  • Phishing susceptibility target: below 5%
ISO 27001

ISO 27001 Audit Readiness Lab

Independent Portfolio Project

Comprehensive ISO 27001 implementation simulation demonstrating end-to-end governance.

  • ISMS & gap assessment
  • Statement of Applicability (SoA)
  • Security policies and procedures
  • Executive implementation roadmap
Privacy

GDPR Privacy Governance Framework

PlayOrbit Group

Comprehensive GDPR and privacy governance framework with full compliance documentation.

  • Risk register & SoA
  • Compliance calendar
  • Central evidence library
  • Internal audit & NC tracker

Get in Touch

Contact

Interested in discussing governance, compliance, or risk management opportunities? Reach out below.

Your information is stored securely and will only be used to respond to your inquiry.