Muhammad Najam Iftikhar
• *** Colville Pl • Milton, ON, L9E 1H4 • 416-***-**** • ********@***.***
Professional Summary:
Senior Information Security Specialist with over a decade of experience driving security excellence and regulatory compliance for the Canadian Federal Government (PSPC, ESDC) and Fortune 500 enterprises (BMO, Shaw Communications). Proven track record of leading complex Security Assessment & Authorization (SA&A) initiatives to secure critical digital infrastructure and achieve Authority to Operate (ATO) ahead of schedule. Expert in aligning enterprise security posture with complex frameworks like GC ITSG-33, NIST, and PCI-DSS, while enabling secure cloud adoption and building robust Business Continuity Programs. Recognized for delivering practical, risk-based security solutions that strengthen enterprise resilience, support secure digital transformation, and enable regulatory compliance across complex environments.
Summary of Skills
·Security Risk & Compliance (PCI-DSS, ISO 27001, NIST RMF, COBIT, SOX)
·Governance, Risk & Control (GRC), ITGC Testing, Audit & Assurance
·Vulnerability Management, Threat & Risk Assessments, Incident Response
·Cloud Security (Azure AD, AWS IAM, GC Secure Cloud, DevSecOps, Zero Trust)
·Identity & Access Management (IAM, PIM/PAM, RBAC, MFA, SSO)
·SIEM & Monitoring (Azure Sentinel, Splunk, QRadar, McAfee ePO, CrowdStrike)
·Security Documentation (ConOps, SAP, MAP, TRA, ATO, RACI Matrices)
·Vendor/Third-Party Risk Assessments, Contract Reviews, Due Diligence
Technical Tools
SIEM: Azure Sentinel, Splunk, QRadar
Network Security: Cisco FirePower, Palo Alto Traps, Fortinet VPN
Cloud: Azure, AWS, Government of Canada Secure Cloud
Endpoint & Security Management: McAfee ePO, CrowdStrike
Vulnerability: QualysGuard, Rapid7, Trustwave
Certifications & Training
·CISSP – Certified Information Systems Security Professional
·Microsoft Certified Professional
·Completed Fortinet FortiGate I & FortiGate II Training
·Completed AlienVault Sourced Computer Security Training
Security Clearance
·Secret Level II Security Clearance
Professional Experience
Information Security Consultant (Remote)
Public Services and Procurement Canada (PSPC). Gatineau, Quebec. (November 2025 – Present)
Create and maintain ServicePSPC platform security standards, ensuring compliance with federal, provincial, and territorial IT security frameworks.
Implement Cloud Guardrails for ServicePSPC, delivering evidence and documentation across multiple project phases.
Lead ongoing Security Assessment and Authorization (SA&A) for the ServicePSPC platform, enabling phased Authority to Operate (ATO) approval in alignment with GC ITSG-33 and TBS guidelines.
Led cross-functional collaboration among security architects, platform owners, and technical advisors to achieve phased ATO milestones while aligning security controls with Government of Canada standards.
Develop and implement Cyber Incident Handling procedures for the ServicePSPC platform, enhancing response readiness and reducing incident closure time.
Perform Vulnerability Assessments and deliver detailed findings and recommendations to strengthen security posture.
Establish a Business Continuity Program (BCP) to support service resilience and operational recovery objectives.
Conduct Security Certification & Accreditation (C&A) activities, including Security Certification Plans, Management Action Plans (MAPs), and validation of implemented safeguards.
Produce continuous deliverables, including ATO Self-Assessment Workbook updates, vulnerability reports, and weekly executive status summaries for senior management.
Information Security Consultant (Remote)
Public Services and Procurement Canada (PSPC). Ottawa, Ontario. (December 2024 – November 2025)
·Architected and led the Security Assessment & Authorization (SA&A) for the Central Index application, securing an Authority to Operate (ATO) two months ahead of schedule by streamlining the evidence collection process across 5+ stakeholder groups and proactively remediating identified control gaps.
·Authored and delivered security documentation (ConOps, SAP, MAP), streamlining evidence collection across 5+ stakeholder groups and reducing audit cycle time by 20%.
·Conducted architecture reviews, analyzed the Target State and Disaster Recovery architecture diagrams, and aligned security controls to the Government of Canada (GC) cloud standards.
·Verified TLS 1.3, data masking, and GC Pass integration, ensuring compliance for 100% of Protected B data.
·Ensured compliance for Protected B data, including PRI, IAN, and PII, by verifying encryption at rest and in transit and validating database-level protections.
·Partnered with technical advisors to validate vulnerability scanning and Azure Sentinel monitoring, enhancing real-time SOC coverage and reducing incident response times.
·Integrated DevSecOps principles with continuous integration/deployment (CI/CD), automated testing, and stakeholder involvement in security testing.
IT Security Practitioner & Security Assessment Specialist (Remote)
Employment and Social Development Canada (ESDC). Gatineau, Quebec. (May 2023 – December 2024)
·Collaborated with solution teams to implement security controls per ITGC-33 security profiles, ensuring compliance with Government of Canada policies.
·Provided strategic guidance on security mechanisms for cloud-based projects, analyzing and selecting appropriate controls.
·Conducted comprehensive risk assessments for enterprise technologies and cloud services, identifying vulnerabilities and recommending remediation measures.
·Facilitated third-party risk assessments by analyzing external vendor risks and delivering detailed reports to mitigate security threats.
·Reviewed SOC 2, ISO 27001, PCI-DSS, and pen test reports, confirming vendor controls and reducing third-party security gaps.
·Developed and delivered Threat and Risk Assessments (TRA) for cloud and IT projects, aligning security protocols with internal policies and industry best practices.
·Worked closely with project managers, security architects, and cloud operations teams to assess, test, and improve security measures while maintaining compliance with regulatory standards.
·Presented security assessment results and provided detailed recommendations to senior management and stakeholders, ensuring alignment with organizational objectives and government compliance standards.
Senior Cybersecurity Risk Analyst (Remote)
Shaw Communications. Calgary, Alberta. (June 2022 – May 2023)
·Spearheaded 25+ complex enterprise risk assessments for mission-critical telecom systems, identifying and mitigating 150+ vulnerabilities to achieve and maintain compliance with ISO 27001, COBIT, NIST, and PCI-DSS mandates.
·Reviewed security documentation, including SSAE 18 Type 2 reports, vulnerability scan reports, and ISO 27001 certifications.
·Conducted in-depth risk-based security assessments of housed, cloud, vendor, and third-party hosted environments. The assessment focus included Risk Management, Physical Security, Identity & Access Management, Encryption, Data Loss Prevention, Secure Development, Incident Management, Security Infrastructure, and Information Security Policy.
·Led security risk assessments for various projects, delivering TRVA reports and providing recommendations to senior management.
·Partnered with architects and SecDevOps teams to implement risk mitigation strategies, reducing enterprise vulnerabilities.
·Reported risk assessment results, including metrics, to internal senior management and the service provider, and recommended remediation actions.
Third-Party Risk Analyst (Remote)
Bank Of Montreal. Chicago, Illinois. (August 2021 – August 2022)
·Engaged with service providers to obtain due diligence reports and performed end-to-end risk assessments for third-party vendors.
·Performed end-to-end risk assessments for all assigned third-party vendors.
·Reviewed SOC1, SOC2, ISO, PCI DSS, and Pentest reports to validate control accuracy and identified gaps.
·Collaborated with the Quality Assurance team to coordinate and complete third-party assessment questionnaires (TPAQ).
·Reported risk assessment results, including vendor risk assessment (VRM) metrics, to internal senior management and the service provider, and recommended remediation actions.
·Reviewed existing and new contracts with third parties to ensure Early Warning’s security, compliance or governance-related requirements are being met.
·Ensured third-party adherence to contractual/regulatory compliance to minimize the risk of fines and reputational harm.
·Efficiently identified control gaps/deficiencies and assisted business areas with documentation and resolution.
·Monitored vendor risk management policies and procedures and maintained the vendor risk management system.
IT Security Analyst
Sobeys Inc., Mississauga, Ontario. (February 2018 – August 2021)
·Performed end-to-end risk assessments of new or existing services, applications, technologies, and vendors. Documented and effectively communicated findings to key stakeholders and notified them of the risk.
·Performed third-party risk assessments to identify issues and/or control gaps, and recommended remediation initiatives.
·Performed risk and control assessments for all high-risk third-party service providers to evaluate the effectiveness of controls.
·Worked with Internal Audit, Legal, Privacy, and other key stakeholders to ensure Information Security policies, procedures, and controls align with all associated requirements.
·Worked closely with Managed Security Services through all integration, project, and ongoing Cyber Security operational activities.
·Owned all aspects of cloud security project definition, including vendor integration, platform integration and monitoring for cloud platforms, including Azure.
·Assisted the Managed Security Services Provider in building escalation procedures for various system-related events such as IPS, OS, Network switches, routers, and firewalls.
·Provided input into reviews of all security-related systems and applications, such as Anti-Malware, SPAM and IPS (McAfee Web Gateway, Qradar, Cisco FirePower).
·Assisted the Security Administration team with Access control reviews of all critical applications and systems.
·Conducted Vulnerability Assessments of existing and new systems and development of remediation plans.
Senior Cybersecurity Analyst
Compass Group Canada. Mississauga, Ontario. (February 2016 – January 2018)
·Completed internal PCI Self-Assessment Questionnaires (SAQs) and the requirements to comply with PCI DSS Reports on Compliance (ROC), Approved Scanning Vendor (ASV) Reports, and PCI AOC (Attestation of Compliance).
·Delivered key PCI Program components such as scope determination, gap assessments and remediation strategy.
·Developed security configuration standards for infrastructure technology assets.
·Planned, tested, and implemented the technology required for PCI DSS compliance, such as Symantec DLP, event logging/alerting, a firewall rule compliance toolset, vulnerability assessments, etc.
·Worked with Legal and Development teams to guide the management of risk with third-party service providers.
·Led incident response activities during technology security incidents.
·Managed vulnerability scanning of all relevant Canadian assets in Qualys and created a remediation plan.
·Identified vulnerabilities in Qualys and ensured remediation efforts were taken.
·Made recommendations to senior management on the results of the analysis and worked closely with other Information Technology groups to refine and enhance security controls.
Security Analyst, IT Security & Risk Management
Moneris Solutions. Etobicoke, Ontario. (February 2015 – February 2016)
·Assisted in the design, implementation and maintenance of security monitoring, intrusion detection/prevention and escalation within Moneris’ security architecture for minimizing risks against internal and external threats. This includes performing vulnerability assessments, reviewing firewall change requests and investigating and handling security incidents.
·Conducted vulnerability assessments with Rapid7 for all types of Critical Infrastructure systems and networks.
·Assisted in running monthly scans, along with keeping the appropriate lines of business informed about the patches.
·Designed and established rules for the Dragon Network Intrusion Prevention System (Dragon 7.1), McAfee ePolicy Orchestrator, FireFlow, AlgoSec, Arbour Pravail APS DDoS and McAfee DLP. These capabilities included the ability to generate session-busting traffic and instantiate firewall-blocking rules in response to an attack.
·Provided business and application owners with clear information about the current situation regarding detected vulnerabilities.
·Coordinated between vendors, the project team, and the network team to implement vulnerability patches to meet PCI Audit requirements.
·Conducted Risk assessments of various technological changes in cloud-based applications, Firewall, web controls and Secure file management methodologies.
Information Security Specialist (Technology Governance Risk & Control (Consultant)
CIBC Bank. Toronto, Ontario. (April 2014 – January 2015)
·Documented in-scope SOX processes such as risk overlays, procedure narratives, process risk assessments, handoffs and test plans.
·Responsibilities included assessment of information technology internal controls based upon the CoBIT framework, ICR, KCar, IT general and application controls, information security, systems development, change management, business continuity, disaster recovery, computer operations, risk management and regulatory compliance.
·Oversaw the governance of 80+ IT General Controls (ITGC) for a Sarbanes-Oxley (SOX) audit, achieving a 100% pass rate on internal and external audits through rigorous review of evidence and proactive remediation of control deficiencies.
·Developed and improved processes in IT Security, like User Access Management and Program Change Management.
·Managed and monitored day-to-day IT Logical and Physical Security operations, including user provisioning, password configuration, logical access, logging, New Hire, Termination and Transfer processes.
·Provided oversight of CIBC & FCIB security and compliance policies, processes, procedures, and standards.
·Engaged with IT Security, IT Infrastructure, IT Operations, and IT Architecture to ensure ITGCC compliance.
·Performed consulting for businesses in establishing IT compliance solutions based on company policies and standards, industry best practices, industry standards, and regulatory requirements.
Education
·Ryerson University – Toronto, Ontario.
BACHELOR OF INFORMATION TECHNOLOGY MANAGEMENT (ITM)
·Seneca College – Toronto, Ontario.
Computer System Technology