f
f_mncwango

Fortunate M

@f_mncwango

Cybersecurity, IT Risk and Compliance Consultant

South Africa
English
About me
Hi, I’m Fortunate, a detail-oriented Cybersecurity, IT Risk & Compliance professional who also provides reliable administrative support. I specialize in information security, risk assessments, policy reviews, GRC, NIST CSF, ISO 27001, and POPIA. I also offer data entry, document formatting, PDF conversion, internet research, Microsoft Office support, report writing, proofreading, and virtual assistance. I’m committed to delivering accurate, high-quality work on time and exceeding client expectations.... Read more

Skills

f
f_mncwango
Fortunate M
Offline • 
Average response time: 1 hour

See my services

Programming & Tech
I will review your information security policies and procedures

Work experience

EY

Cybersecurity Associate

EY • Full-time

Jan 2023 - Jun 20263 yrs 5 mos

Key Capabilities • IT General Controls (ITGCs) and Test of Controls (TOC) execution • Cybersecurity Programme Assessments (25+ domains across IAM, Privacy, BCM, DR, etc.) • Data Privacy and Protection • Identity and Access Governance (Joiners, Movers, Leavers testing) • Operating System & Database Security Reviews (Windows, Linux, SQL, Oracle, Active Directory) • Process Documentation & Walkthrough Development • Business Continuity Management (aligned with ISO 22301, ISO 27031, and internal continuity standards) • IoT/OT Security – Secure by Design Framework (AMI Security) • Policy and standards review for cybersecurity alignment • Control framework mapping and risk evaluation • Web development experience (HTML, CSS, JavaScript, C#, SQL Professional Experience Cybersecurity Associate | Ernst & Young (EY) | Cape Town, South Africa • Conducted reviews on databases and operating systems focusing on access controls, password policies, privilege management, and event logging across Windows, Linux, SQL, Oracle, and Active Directory. • Evaluated data centre controls including access management, environmental systems, and backup infrastructure. • Developed process descriptions and walkthroughs to assess IT General Controls. • Executed Joiners, Movers, Leavers (JML) testing for identity and access governance. • Reviewed Business Continuity and Disaster Recovery frameworks aligned with ISO 22301, ISO 27031, and internal business continuity standards. • Supported cybersecurity programme maturity reviews and evidence collection across multiple industries. • Contributed to the creation of an AMI Secure by Design Framework focusing on IoT and OT Security. • Collaborated with cross-functional teams to assess risk and implement security improvement recommendations.