I make sure technology work is defensible, worth the money, and actually gets built.
Nineteen years across telecom operations, digital consulting, and portfolio, product and project control. Audit, certification and security on one side, the business case and the market on the other, and I build the systems myself.
Most failures in a technology portfolio are not purely technical or purely managerial. They sit in the seam between the two — a risk assessed but never designed against, a control agreed but never evidenced, a delivery plan that ignores what compliance will cost. I work that seam.
Two master's degrees frame how I approach it: one in cybersecurity, one in project management. Managing a portfolio taught me the other half — that a control which cannot be paid for is not a control, so the business case, the financials and the route to market belong in the same conversation as the risk.
I lead the certification and audit programmes that put evidence behind the claim, and I govern products across their whole life — idea, business case, security requirements, launch, and eventually retirement. And I do not stop at the recommendation: I build the dashboards, the automation and the AI platforms that carry it out.
What I do
six families of work
They overlap by design. One governance decision usually becomes a business case, a process change, a security requirement and a dashboard at the same time.
01
governance & assurance
Making sure what gets built can be defended — to an auditor, a regulator, or a customer’s security team.
Control frameworks & policy
Governance of the product lifecycle
Risk & compliance programmes
Business continuity & recovery
Regulatory requirements
02
audit & certification
Leading the programmes that put evidence behind the claim, and answering the findings when they come.
Internal & external audit
Project & product management audit
ISO 27001 certification programmes
PCI DSS · CMMI · business continuity
Finding response & closure
03
portfolio & commercial
Deciding what deserves the capital, taking it to market, then holding what is funded to scope and budget.
Portfolio management
Business case assessment
Financial analysis, ROI & margin
Market & go-to-market
Acquisition & vendor due diligence
04
security assurance
Security designed into a product before launch, and proved after it — not reviewed once and filed.
Cybersecurity requirements
Security assessment & review
VA & PT remediation
Secure environment design
Access & identity governance
05
engineering & automation
Building the systems rather than specifying them and waiting — infrastructure through to interface.
AI platform engineering
Workflow automation
Approval & evaluation engines
Linux & server administration
Process design
06
data & decision support
Turning scattered operational data into something an executive can act on, with the right people seeing the right rows.
Dashboards & business intelligence
Role-based & row-level access
Advanced & predictive analytics
Large-scale pipelines
Customer experience analytics
Product lifecycle
idea to retirement
A product is a governed object for its whole life, not just at launch. Each gate below has an owner, an evidence requirement and a decision.
01
idea
Problem, market and fit. Screened before anyone spends on it.
02
business case
Revenue model, cost to serve, ROI and the number it will be judged on.
03
design
Architecture, cybersecurity requirements and the compliance obligations it inherits.
04
onboard
Risk assessment, security testing, VA and PT remediation, and approval to launch.
05
operate
Change control, audit evidence, performance against the business case.
06
retire
Migration, data disposal, contract exit — closed properly rather than left running.
How I work
six stages, every time
The same sequence whether it is a compliance programme, an investment assessment or an AI platform. Most things fail at stage one or stage five.
01
frame
The problem, the users, the data it touches, and what "done" has to look like.
02
brief
A specification precise enough to hold under pressure, with phased delivery and acceptance criteria.
03
build
Infrastructure, data model and interface — iterated against the brief, not against impressions.
04
govern
Security review, data-protection position and a defined approval path before it touches real work.
05
operate
Monitoring, access control, uptime and cost. An unmonitored system is an unowned one.
06
improve
Measure where it saves time and where it fails, then fold the change back into the documented process.
What changes
before and after
Governance is easy to describe and hard to evidence. These are the shifts the work is meant to produce.
BeforeAudit findings absorbed to keep the peace, accountability landing wherever it fell.
then
AfterEvery finding answered on the evidence — agreed where it holds, disputed with business justification where responsibility sits elsewhere, closed with a package rather than a promise.
BeforeEach reporting cycle rebuilt by hand from scattered exports, late and slightly different every time.
then
AfterA pipeline that runs the same way every period — reconciled, formatted, reproducible, identical whoever presses the button.
BeforeAI stuck in permanent pilot, because nobody could answer the security and data-protection questions.
then
AfterA documented position on posture, data handling and approval, taken through stakeholders — so the capability reaches real work instead of expiring in evaluation.
BeforeApprovals living in email threads, reconstructed after the fact when someone asked who signed off.
then
AfterApproval designed as software — staged routing, explicit responsibility boundaries, and a trail that answers "who approved this, and when" as a query.
BeforeProducts funded on enthusiasm, with no shared view of what each one returns or costs to serve.
then
AfterEvery candidate scored the same way — business case, margin, cost to serve, market fit and risk — so the ranking survives the meeting where someone's favourite comes out low.
BeforeA good product launched into no particular market, positioned by whoever wrote the deck.
then
AfterA go-to-market position tied to the business case — who it is for, what it displaces, what it costs to serve them, and the number it will be judged on.
Scale, timelines and figures belong in a conversation rather than on a public page. Happy to go into detail.
Portfolio management alongside governance, risk and compliance — business cases and financial assessment, go-to-market and product positioning, internal and external audit, executive reporting, and the AI and automation that carries it.
2018 — 2019Riyadh
senior consultant — digital business
Consulting practice
Digital transformation for clients: business cases, commercial modelling and revenue models, delivery and project management, with governance system implementation running alongside.
2007 — 2018Kingdom-wide
specialist — systems analyst
National telecom operator
Eleven years in operations and technical support at national scale — broadband, fibre, IP and IPTV — plus budgets, training and the first monitoring dashboards. The network fluency everything since rests on.
Education
Master's — CybersecurityMidocean University
Master's — Project Management
BSc — Information TechnologyArab Open University, Riyadh
Certifications
PMP — Project Management Professional
CISM — Certified Information Security Manager
CEH — Certified Ethical Hacker
PMO-CP · CompTIA Security+ · ITIL · Six Sigma
Standards led
ISO 27001Information security management
PCI DSSPayment card data security
CMMICapability maturity
Business continuityPlans developed and exercised
Internal & external auditProgramme leadership and finding closure
Also building
3limak.com Arabic learning marketplace — courses, digital files and printed titles
maziktkSecond platform, in development
Get in touch
say hello
If something here is relevant to a problem you are working on, I am happy to talk it through. Questions and second opinions are welcome.