I will conduct an iso 27001 or pci dss gap analysis
Information Systems Auditor
About this Gig
Welcome to my IT Governance & Compliance Consulting Gig!
Are you a startup or enterprise facing pressure to prove your IT security and achieve compliance?
I am Stephen, a CISA-certified IT Audit Leader and the 2026 IIA Global Young Professional of the Year. With 8+ years of experience in Big Four consulting and regional banking, I transform complex regulatory requirements into actionable, business-friendly IT strategies.
What I Offer:
- Gap Assessments: Evaluating your IT environment against ISO 27001, ISO 22301, and PCI DSS.
- Risk Reporting: Highlighting vulnerabilities in your network, access, and ITGCs.
- Strategic Roadmaps: Step-by-step plans to remediate gaps and achieve audit readiness.
- Policy Drafting: Custom information security policies tailored to your operations.
- Executive Decks: High-level presentations for your Board or C-suite.
Why Choose Me? I don't just check compliance boxes; I architect digital trust. My approach bridges the gap between technical IT controls and C-suite strategy. I bring proven executive-level experience to your business, ensuring your IT governance acts as a secure springboard for growth.
Message me before ordering to align on scope!
FAQ
What information or access do you need to get started?
To begin, I will need an overview of your current tech stack, existing IT policies, and your primary compliance objective (e.g., upcoming external audit, enterprise customer request, or certification roadmap). If you have prior audit findings or an asset inventory, that helps accelerate the initial
Does this gig include certification issuance?
No. Accredited third-party certifying bodies or Qualified Security Assessors (QSAs) issue formal certifications. This service provides readiness reviews, gap assessments, policy frameworks, and remediation roadmaps to prepare your systems and team for a successful certification or regulatory audit.
Which frameworks and standards do you cover?
My core expertise covers ISO/IEC 27001 (Information Security Management), ISO 22301 (Business Continuity), PCI DSS, IT General Controls (ITGC), and local/regional banking and data protection guidelines.
Can you help draft custom policies, or do you only use templates?
I tailor all documentation directly to your operational workflows, company size, and infrastructure. Generic templates often create operational overhead; the goal is practical governance that your team can actually maintain.
