MUHAMMAD ANWAR
Cyber · GRC · AI Assurance
ISMPSPFNIST SP 800-53ISO 42001
Click to skip
About your advisor
I'm a Cybersecurity & Compliance Assurance Leader and Assessor supporting mission-critical environments across the Federal Government, Defence and the private sector.
My work spans the Information Security Manual (ISM), the Protective Security Policy Framework (PSPF), NIST SP 800-53, SOCI Act obligations, AESCSF, PCI DSS, NIST CSF 2.0, ISO 27001 and AI governance under ISO/IEC 42001. I help organisations rapidly understand complex risk landscapes, strengthen their security posture and drive organisation-wide uplift in compliance, assurance and cyber resilience.
As an emerging-technology practitioner, I bring AI-driven methods into governance and risk programs — automating compliance workflows, sharpening decision-making and, increasingly, assessing the risks inside the AI products that organisations are rushing to adopt.
My style is outcomes-focused and built on strong stakeholder engagement: I've led multidisciplinary teams, briefed senior executives and Boards, run executive workshops, and secured more than $10M in tender wins through bid leadership.
Experience
Client and employer names are withheld to respect confidentiality.
Critical infrastructure · Line 2 security assurance
Independent Line 2 technical assurance over the design, implementation and effectiveness of security controls, primarily against NIST SP 800-53 Revision 5, alongside the PSPF and the Essential Eight. The focus is verifying how controls are actually configured, not just that they are documented.
Australian Federal Government · Defence industry security
Led a team of seven conducting cybersecurity assessments of organisations seeking entry to a national Defence-industry security program.
Big Four professional services firm
SOCI Act, AESCSF, PCI DSS and IT risk engagements for national telecommunications, energy and digital-services clients.
Federal government consultancy
Cyber uplift project management in Defence, plus SSP/SRMP/SoA authoring and ISO 27001 provider assessments for federal departments.
Big Four professional services firm
Third-party risk, Business Impact Level assessments and risk management for telecommunications and Defence.
Technology consultancy
IRAP certification readiness and ISMS/SSP analysis for a major national infrastructure project.
Financial services
Process re-engineering and core-banking audit — a zero-defect go-live and 100% on-time project completion.
Credentials
SZABIST
Harvard Business School Online
MIT xPRO
University of Canberra