Overview
Work History
Education
Skills
Websites
Achievements
Timeline
Generic
ENOCH OPPONG PEPRAH

ENOCH OPPONG PEPRAH

LONDON

Overview

11
11
years of professional experience

Work History

Cyber Security Manager

ST. GEORGE'S UNIVERSITY OF LONDON
11.2022 - Current


• Responsible for planning and development of an appropriate Information security operational plan.
Leading the development of information security architecture, services and systems within the university environment.
• Team Management of the cyber security analysts, planning and implementing effective training,
• Responsible for the selection, implementation and operation of cyber security services and solutions
• Stay abreast with information security issues and regulatory changes affecting higher education, participate in national policy and practice discussions, and
communicate to the university on a regular basis about those topics; engage in professional development to maintain continual growth in professional skills and
knowledge essential to the position.
• Utilizing analytical tools to determine emerging threats, vulnerabilities and implement measures, such as Intrusion detection and prevention and encryption
to find the best way (with support as necessary) to secure the IT infrastructure
• Ensure regular reviews of policy documents are conducted. Advising the relevant committees of proposed changes.
• Work with other ICT colleagues to ensure that systems are patched and adequately secured and protected, and that any changes are performed in a controlled and documented fashion
• Maintain a strategy and plan for information security work which addresses the evolving business risk and information control requirements.ISO27001,NIST & PCIDSS
• Carry out regular security audits both internal and with the assistance of external security specialists
• Regular inspections of systems and functions to ensure compliance with university policy and to ensure that any gaps are filled
• Engage directly with university projects to review new projects and initiatives, ensuring security requirements are captured and managed through to implementation
• Responsible for the process of gathering, analysing and assessing the current and future threat landscape, providing a realistic view of risks, threats and
priorities in the enterprise environment
• Lead investigations, analysis and review following breaches of security controls and manages security incidents
• Communicate well, both orally and in writing, and respond to wide-ranging and detailed questioning relating both to own areas of specialization and, at a more
general level, to the wider field of IT
• Promote the service within the University and create strong personal relationships with the full range of stakeholders.
• Liaise with HE sector, external organizations and key suppliers to share ideas, compare approaches and develop best practice.
• Co-ordinate cyber security awareness training for colleagues.

Cyber Security Consultant

AIDEC CONSULTANCIES INTERNATIONAL LTD
09.2020 - 10.2022
  • Design the most efficient way to protect system, networks, software, data and information systems against any potential attacks, using:ISO27001/5,NIST,PCIDSS etc.
  • Train client on technical and non-technical domains in cyber security.
  • Select and develop a range of effective resources, including appropriate use of new and emerging technologies ensuring they are inclusive, promote equality and engage with diversity.
  • Implement vulnerability testing, threat analyses, and security checks.
  • Perform research on cyber security criteria, security systems, and validation procedures.
  • Consult/build a SOC, and train SOC analyst.
  • Advise on accurate cost estimations and categorize integration issues for IT project teams.
  • Plan and design healthy security architectures for any IT project, using: TOGAF,SABSA etc.
  • Investigate and provide security solutions using business standard analysis criteria. Using: SOC2 etc.
  • Deliver technical reports and official papers relating to test findings.
  • Provide professional supervision and guidance to security teams.
  • Consult/advise on both technical and business as of cyber security and information technology in general.

Cyber Security Analyst

ECOBANK TRANSNATIONAL INC
03.2017 - 08.2020
  • Monitored the organization’s networks for security breaches and investigate violation across the 36 affiliates using tools like M365(Azure sentinel,cloud app,MS defender) and McAfee SIEM.
  • Collaborated with the digital forensics team to analyze malware samples, obtain from IOCs and implement necessary preventive measures.
  • Performed systems vulnerability/risk management using Qualys.
  • Conduct detailed comprehensive analysis and investigation on a wide variety of security events and implement containment and mitigation processes.
  • Perform threat analysis and hunting with IOC's.
  • Performed any other duties assigned by the SOC manager

Senior IT Service Delivery Analyst

ECOBANK TRANSNATIONAL INC.
08.2015 - 02.2017
  • Resolved incoming help requests from end users via both telephone and e-mail in a courteous manner.
  • Documented all pertinent end user identification information, including name, department, contact information, and nature of problem or issue across the 34 affiliates in the Ecobank group such as: Ghana, Nigeria, Uganda, Zambia, Senegal, Mali,Tanzania,Malawi among many others.
  • Built rapport and elicit problem solving skills aimed at resolving both internal and external customer request.

Applications Support Specialist/Engineer

ECOBANK TRANSNATIONAL INC
02.2013 - 01.2015
  • Worked as a core banking applications team lead to provide excellent 24/7 support.
  • Supported in Oracle Flex cube (Host a Branch) to all affiliates in the Ecobank group across 34 African countries such as Nigeria, Ghana, Burkina Faso, Senegal, Gabon, Tanzania, and Malawi amongst many others.
  • Actively participate in testing and implementation of new systems and ensure taking of daily accurate and complete backup of affiliates system (Oracle flex cube host database).
  • Provided operational database support, primarily in oracle flex cube database.

Education

CGEIT

ISACA
USA
12.2022

CISA

ISACA
USA
10.2022

CISM

ISACA
USA
08.2022

CRISC

ISACA
USA
03.2022

CEH

EC COUNCIL
USA
11.2018

Master of Science - Business Consulting And Enterprise Risk Management

Kwame Nkrumah University of Science And Technology
KUMASI, GHANA
11.2017

ITIL-Intermediate Level

Axelos
United Kingdom
11.2016

Bachelor of Science - BSc. Computing and Commerce

University of Ghana
ACCRA,GHANA
05.2012

Oracle Certified Professional (OCP)

Oracle University
United States Of America, Washington DC
06.2008

Associate of Applied Science - Six Sigma Yellow Belt

VMEdu Inc
India
02.2021

Associate of Science - Scrum Fundamentals Certified

VMEdu Inc
India
02.2021

Associate of Science - ISO/IEC 27001 Information Security Associate

SkillFront
Zurich Switzerland
11.2021

Associate of Science - API SECURITY

API SEC UNIVERSITY
UNITED STATES
06.2023

Skills

  • Darktrace Threat Visualizer
  • Cybersecurity Best Practice Implementation
  • Cyber Kill Chain/Diamond Models
  • Security event log reviews
  • Firewalls, SIEM, NIDS/NIPS/HIDS/HIPS, AVs, DLP, proxies, network behavioral analytics, endpoint, and cloud security
  • Oracle Database
  • SQL / PLSQL
  • M365, SIEM,Qualys
  • Core Banking Functional Support & Security
  • Business Consulting
  • IT Service Management
  • System Vulnerability Management
  • MS Office
  • IT Risk Management
  • DNS, LDAP, SMTP, FTP, IAM,SSH, SSL/TLS and HTTPS,Network security
  • AWS Cloud Knowledge

Achievements


  • Provided strategic advisory and leadership services to St.Georges University to attain cyber essential-this creates opportunity for grants and other strategic alliance for St.Georges.
  • My advise helped senior management to procure Darktrace, I led the implementation as well,this security tool gives us real time visibility of telemetry on our digital estate.
  • I use the NSCS cyber tool kit for board to train and help top decision makers understand the importance of cyber security for St.George, this also promotes 95% alliance of cyber security with business.
  • Strategically I negotiated in famous of St. Georges to save a substantial discount of more than 250K over the span of the 4 years contract for Darktrace procurement.
  • I developed, cyber security strategy, policy and cyber incidence response plan.
  • I developed a strategy called: Cyber Champions who were department cyber marshals, they train and report any cyber risk to my team
  • I developed a training module for departmental cyber champions,staff and student, this helps to reduce our attack surface by 90%.
  • I simulated phishing campaign to gauge the cyber security awareness level of St.Georges staff and student.
  • I led an external team to perform penetration test to asses the vulnerability level of St.Georges digital estate.
  • I set up the forthright cyber security vulnerability posture review/remediation forum, to reduce the high level of system vulnerability in our digital estate.
  • I developed a strategy to create cyber info graphic content which was shared on lock screen and digital screens on campus, to create cyber security awareness.
  • I developed cyber risk register, cyber security policy and cyber security strategy for St.Georges.
  • Voluntarily provide cyber security advisory services live on TV to businesses and individuals on how to maintain hygiene cyber posture.


Here are some of the youtube links to my works:


https://youtu.be/fU01LiMMJyc?t=226
https://youtu.be/C9X1kqELvN4


Thank you.

Timeline

Cyber Security Manager

ST. GEORGE'S UNIVERSITY OF LONDON
11.2022 - Current

Cyber Security Consultant

AIDEC CONSULTANCIES INTERNATIONAL LTD
09.2020 - 10.2022

Cyber Security Analyst

ECOBANK TRANSNATIONAL INC
03.2017 - 08.2020

Senior IT Service Delivery Analyst

ECOBANK TRANSNATIONAL INC.
08.2015 - 02.2017

Applications Support Specialist/Engineer

ECOBANK TRANSNATIONAL INC
02.2013 - 01.2015

CGEIT

ISACA

CISA

ISACA

CISM

ISACA

CRISC

ISACA

CEH

EC COUNCIL

Master of Science - Business Consulting And Enterprise Risk Management

Kwame Nkrumah University of Science And Technology

ITIL-Intermediate Level

Axelos

Bachelor of Science - BSc. Computing and Commerce

University of Ghana

Oracle Certified Professional (OCP)

Oracle University

Associate of Applied Science - Six Sigma Yellow Belt

VMEdu Inc

Associate of Science - Scrum Fundamentals Certified

VMEdu Inc

Associate of Science - ISO/IEC 27001 Information Security Associate

SkillFront

Associate of Science - API SECURITY

API SEC UNIVERSITY
ENOCH OPPONG PEPRAH