About your advisor

Muhammad Anwar.
Assurance leader. AI security innovator.

  • Australian Government security cleared
  • MBA · AAICD
  • Melbourne, AU
$10M+ in tender wins through bid leadership
6 sectors, from Defence to energy and finance
30+ cyber, risk and AI certifications
15+ frameworks assessed and audited
Muhammad Anwar

I'm a Cybersecurity & Compliance Assurance Leader and Assessor supporting mission-critical environments across the Federal Government, Defence and the private sector.

My work spans the Information Security Manual (ISM), the Protective Security Policy Framework (PSPF), NIST SP 800-53, SOCI Act obligations, AESCSF, PCI DSS, NIST CSF 2.0, ISO 27001 and AI governance under ISO/IEC 42001. I help organisations rapidly understand complex risk landscapes, strengthen their security posture and drive organisation-wide uplift in compliance, assurance and cyber resilience.

As an emerging-technology practitioner, I bring AI-driven methods into governance and risk programs — automating compliance workflows, sharpening decision-making and, increasingly, assessing the risks inside the AI products that organisations are rushing to adopt.

My style is outcomes-focused and built on strong stakeholder engagement: I've led multidisciplinary teams, briefed senior executives and Boards, run executive workshops, and secured more than $10M in tender wins through bid leadership.

  • Based inMelbourne, Australia
  • ClearanceAustralian Government security cleared
  • MemberAAICD

Curriculum vitae · PDF

Download Muhammad’s CV

Tell me who you are and the 2-page CV downloads straight away.

Spam protection active

Connect on LinkedIn Talk to my AI agent

Experience

A career in high-stakes assurance.

Client and employer names are withheld to respect confidentiality.

  1. 2026 – Present

    Senior Security Technical Assurance Specialist

    Critical infrastructure · Line 2 security assurance

    Independent Line 2 technical assurance over the design, implementation and effectiveness of security controls, primarily against NIST SP 800-53 Revision 5, alongside the PSPF and the Essential Eight. The focus is verifying how controls are actually configured, not just that they are documented.

    • Configuration-level testing of NIST SP 800-53 Rev 5 controls
    • Validating board cyber metrics against the underlying data sets
    • Challenging control owners and reporting control effectiveness to leadership
  2. 2026

    Team Leader & Cybersecurity Assessor

    Australian Federal Government · Defence industry security

    Led a team of seven conducting cybersecurity assessments of organisations seeking entry to a national Defence-industry security program.

    • Regular cadence and senior management reporting
    • Cybersecurity assessments of applicant organisations
    • Quality assurance and mentoring across the assessor team
  3. 2023 – 2025

    Manager, Cybersecurity

    Big Four professional services firm

    SOCI Act, AESCSF, PCI DSS and IT risk engagements for national telecommunications, energy and digital-services clients.

    • AESCSF V2 assessment: 100+ artefacts, 30+ stakeholders, board-ready reporting
    • Built KRIs/KCIs in ServiceNow IRM aligned to ISO 42001 & NIST 800-53
    • Multi-framework all-hazards assessment presented to a CEO
  4. 2022 – 2023

    Manager, Cybersecurity

    Federal government consultancy

    Cyber uplift project management in Defence, plus SSP/SRMP/SoA authoring and ISO 27001 provider assessments for federal departments.

    • PMO leadership for Defence cyber hub capability
    • Security documentation across multiple system classifications
    • ISO 27001 assessments for departmental service providers
  5. 2021 – 2022

    Manager, Cybersecurity

    Big Four professional services firm

    Third-party risk, Business Impact Level assessments and risk management for telecommunications and Defence.

    • Supplier tabletop exercises with global hyperscalers
    • Helped build a CTI platform to power supplier risk
    • BIL assessments and DSPF-aligned audits
  6. 2021

    Cybersecurity Consultant

    Technology consultancy

    IRAP certification readiness and ISMS/SSP analysis for a major national infrastructure project.

    • Gap assessment of existing security controls
    • Proposal and bid writing
  7. Earlier

    Business Analyst / Core Banking Auditor

    Financial services

    Process re-engineering and core-banking audit — a zero-defect go-live and 100% on-time project completion.

Credentials

Always learning.

Master of Business Administration (MBA)

SZABIST

Organisational Leadership

Harvard Business School Online

Designing & Developing AI Products and Services

MIT xPRO

Diploma in Business Informatics

University of Canberra

AI & Data

  • ISO/IEC 42001:2023 AI Management System (ANU)
  • AI Security & Governance (Securiti)
  • Trusted AI
  • Responsible AI (TAFE NSW)
  • AWS GenAI Developer Kit — Bedrock, Amazon Q, Prompt Engineering
  • Microsoft Purview for DLP
  • GenAI for Project Managers (PMI)

Cyber & Risk

  • ISO 27001 Lead Auditor
  • IRAP Assessor / Readiness Training
  • Zero Trust Certified Architect (ZTCA)
  • Certified GRC Professional (GRCP)
  • Certified GRC Auditor (GRCA)
  • Certified Identity & Access Manager (CIAM)
  • FAIR Cyber Risk Management
  • Cybersecurity Risk & Strategies (RMIT)

Resilience & OT

  • ISO 22301 Risk Manager
  • ISO 31000 Risk Manager
  • ICS Cybersecurity Risk (CISA)
  • Cybersecurity Practices for ICS
  • Data Protection Officer (DPO)