You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Sabby R.SR

Sabby R.

Senior Security Consultant

€810/day
Birmingham, GB
8-15 years

Average response time: 1 hour

About Sabby

I help businesses strengthen their cybersecurity posture, reduce risk, and meet compliance requirements without unnecessary complexity.

I specialise in practical, business-focused security consulting rather than technical pentesting or coding. My work focuses on helping organisations understand where their security gaps are, what risks matter most, and how to address them in a structured and achievable way.

I typically support SMEs, startups, and growing organisations with:

Security risk assessments and gap analysis
GDPR-aligned security reviews
ISO 27001 readiness and advisory support
Security policy development and improvement
Supplier / third-party risk assessments
General cybersecurity advisory for leadership and IT teams

What sets me apart is my focus on clear, actionable guidance that non-technical stakeholders can understand and implement. I translate security requirements into practical steps that align with business priorities, budget, and operational reality.

My goal is to help organisations improve security maturity in a way that is measurable, compliant, and sustainable, without overwhelming teams with unnecessary technical detail.
  • English

    Native or bilingual

Remote only
Primarily works remotely

Experience

  • Deliveroo/DoorDash/Wolt
    Security Consultant
    RETAIL (LARGE RETAILERS)
    March 2026 - Today (3 months)
    Leading the group-wide redesign of the GRC and Security strategy across Deliveroo, DoorDash, and Wolt across global regions.
    •Building a scalable enterprise GRC operating model across international business units
    •Standardising policies, control frameworks, risk taxonomy, and assurance processes group wide
    •Aligning controls to ISO 27001, NIST CSF, SOC 2, and AI governance requirements
    •Partnering with legal, privacy, security, and engineering leaders on strategic risk initiatives
    •Designing board-level risk reporting, governance metrics, and control assurance dashboards
    •Reviewing and assessing new GRC tooling capabilities to address AI and emerging technology risks
    •Supporting the development of AI governance controls aligned to ISO 42001 and EU AI Act principles
    •Leading global workshops to align risk ownership, accountability, and remediation priorities
    •Facilitating executive tabletop exercises for cyber and operational resilience scenarios
    Governance, Risk & Compliance (GRC) NIST Cybersecurity Security Architecture
  • National Grid
    Security Consultant
    ENERGY AND UTILITIES
    April 2025 - December 2025 (8 months)
    Led end-to-end GRC engagements and risk management supporting Critical National Infrastructure and AI initiatives, ensuring compliance with Ofgem, NIS2, HMG standards, ISO 27001, NIST CSF, NCSC CAF, ISO 42001, and SOC 2, with full ownership of scope, delivery, and outcomes.
    •Managed client relationships with strong professionalism, responsiveness, and trust-based engagement
    •Translated complex regulatory requirements into clear, actionable advice for stakeholders
    •Produced and quality-assured client-facing governance deliverables, including policies, risk assessments, reports, and audit documentation
    •Managed delivery risks and escalations, ensuring timely resolution and sustained client satisfaction
    •Supported presales activities including scoping, proposals, and client presentations
    •Contributed to internal methodologies, templates, and knowledge sharing to improve delivery consistency
    •Delivered ISO 27001, audit readiness, gap analysis, risk treatment, and statement of applicability
    •Supported SOC 2 engagements including control mapping, evidence collection, and readiness assessments
    •Applied NIST CSF to assess security maturity and develop actionable improvement roadmaps
    •Facilitated workshops and tabletop exercises to strengthen incident response and organisational resilience
    •Engaged in AI governance including ISO 42001 and awareness of the EU AI Act
    •Led implementation of GRC tooling to streamline and automate governance, risk, and compliance workflows
  • Inertiasoft
    Security Consultant
    DEFENSE AND MILITARY
    September 2024 - December 2024 (3 months)
    Delivered strategic cybersecurity and GRC assessments for clients across the EMEA region during large scale digital transformation programs, enhancing operational resilience and ensuring compliance with ISO 27001 , NIST, SOC 2, GDPR, and DORA across hybrid cloud and on-premises environments.
    • Led Secure by Design, Privacy by Design, and Zero Trust initiatives, enforcing Windows Server
    hardening, endpoint compliance via Intune, and establishing DLP, firewall, and encryption baselines to
    protect critical infrastructure
    • Implemented SIEM (Splunk, Microsoft Sentinel), IDS/IPS, and SOAR integrations to detect, investigate, and escalate threats in alignment with incident response, business continuity, and DR procedures.
    • Partnered with regional IT and business units to identify risks, perform vendor and third-party assessments, and deploy mitigations including IAM strategies and network segmentation
    • Integrated endpoint management and secure remote access policies via Intune to maintain device compliance across multi-country staff
    • Conducted proactive threat intelligence analysis, threat modelling, vulnerability assessments, and
    penetration tests, integrating findings into risk mitigation strategies and prioritizing remediation of critical issues
    • Supported SecOps and DevOps teams to embed security controls into CI/CD pipelines and produced incident response, DR documentation, and executive security briefings
    NIST Cybersecurity

Recommendations

Be the first to recommend Sabby

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Re-Certification in Cyber Security Practitioner - Level 3
    Re-Certification in Cyber Security Practitioner - Level 3
  • Certification in Penetration Testing – Level 4
    Certification in Penetration Testing – Level 4

Skill set

Categories