Summary
Overview
Work history
Skills
References
Timeline
Generic

Maria Zaine

Summary

A Senior Security Architect and Consultant with over 6 years of experience in enterprise security architecture and governance, specialising in IAM, Zero Trust, network security, data protection and third-party risk.

Demonstrated ability to engage senior stakeholders, clearly articulate complex security concepts, and produce high-quality architectural diagrams and HLDs that ensure compliance with data protection (GDPR) and security standards (NIST 2.0 and ISO 27001). Led the design of a 6-year Zero Trust and IAM capability roadmap using TOGAF, with developing knowledge of SABSA through ongoing professional learning.

Bilingual in English and Arabic. Holds CCZT and is currently pursuing CCSK and CISSP. Leveraging Gartner Peer Insights to track market trends and assess tool maturity.

Overview

7
7
years of professional experience

Work history

Senior Cybersecurity Architect & Consultant

Cyberfort Ltd
2024.11 - Current

Full-time consultancy role with managerial responsibilities. Client engagements listed below:

Senior Security Architect | Consultant

Quickline Communication | Nov 2025 - Present

  • Conducted ISO 27001 and TSA gap analysis, providing remediation plans for client compliance.
  • Facilitated stakeholder sessions to evaluate business context and existing security controls.
  • Delivered detailed reports outlining security mechanisms tailored to client environments.

Senior Security Architect | Consultant

Which ltd | Dec 2024 - Oct 2025

  • Authored comprehensive security policies by evaluating risks and ensuring compliance with PCI DSS, NIST 2, and ISO 27001.
  • Defined security standards, functional requirements, and control specifications aligned with organisational policies.
  • Authored an enterprise-wide Incident Management procedure to streamline response operations, reduce response times, define clear roles and responsibilities (RASCI), define SLAs, and ensure the organisation can demonstrate compliance with NIST 2.0 and ISO 27001.
  • Developed an enterprise-wide Incident Management procedure to optimise response operations, incorporating RASCI, SLAs, BIAs and ensuring compliance with NIST 2.0 and ISO 27001.
  • Served as a trusted security advisor during audits, managing scope (ToR), evidence collection, and engagement with auditors.
  • Served as technical authority, explaining complex architectural designs to auditors and stakeholders.

Additional responsibility: Information Security Manager (client engagement):

  • Served as the security advisor for a 40-person team of developers and data analysts, embedding secure-by-design practices and reviewing PoC security prior to production release.

Cybersecurity Consultant

MThree
2022.05 - 2024.11

Served as an on-site consultant at a global financial asset management company. Client engagement responsibilities included:

Security Architect | Consultant

Nomura International | Feb 2024 - Nov 2024

  • Defined Zero Trust (ZT) principles and IAM capabilities for a 6-year implementation plan.
  • Designed high- and low-level security architectures (HLDs and LLDs) to facilitate enterprise transformation, utilising tools like Lucidchart, Microsoft Visio and draw.io.
  • Developed attack trees aligned with MITRE framework to guide architectural decisions.
  • Conducted STRIDE threat modelling for integrating a global transaction tool API, enhancing fraud detection and data security capabilities.
  • Participated in PANDA meetings addressing New Technology Initiatives and Products (NTIs and NTPs).
  • Managed data storage practices to ensure compliance and security. utilising NCSC and NIST guidelines.

Security Analyst & Incident Responder | Consultant

Nomura International | May 2022 - Jan 2024

  • Drove security automation by developing custom playbooks to enhance operational efficiency.
  • Managed identity and access control requests, ensuring compliance with organisational policies.
  • Identified and resolved process and control gaps in collaboration with senior management.
  • Served as the primary advisory and approval authority for proxy-related operations.

Cyber Security Analyst

The Ardonagh Group
2020.09 - 2021.09
  • Led privacy and third-party risk assessments (PIAs and KYS reviews) or onboarding vendors.
  • Developed and managed a security risk register for audit and remediation purposes.
  • Defined pentesting scope and testing strategies, identifying weaknesses and inform risk treatment decisions.
  • Implemented risk-driven security controls, including the rollout of MFA for 200+ users, utilising Azure AD.

Cyber Security Academic Mentor, Part-Time

Kingston University
2019.01 - 2020.09

Skills

    Education

  • BSc Cyber Security & Computer Forensics (Honours) Kingston University 2:1
  • Achievements

  • 2025 Roehampton Guest Speaker Introduction to GRC & Why It Matters
  • 2023 CSA UK Panel Member Starting Your Career in Cyber
  • Certifications

  • 2026: Certificate of Cloud Security Knowledge (CCSK) CSA In Progress
  • 2026: Certified Information Systems Security Professional (CISSP) ISC2 In Progress
  • 2025: Competence in Zero Trust (CCZT) CSA Complete
  • 2024: Zero Trust Security Model; Best Practices Framework Microsoft Complete
  • Skillsets:

  • Secure by design architecture
  • Defence-in-depth
  • Enterprise Architectural methodologies
  • Governance and risk framework
  • Threat Modelling
  • Interpersonal communication
  • Team-oriented collaboration
  • Technical and non-technical writing
  • Knowledge & Experience with:

  • NIST CSF 1 & 2
  • NIST Publications ( NIST 800-207, NIST 800-53)
  • ISO 27001/2 and other ISO publications like ISO 42001
  • MITRE ATT&CK
  • CSA Cloud Control Matrix (CMM)
  • CIS 18 controls
  • CISA ZTMM
  • TOGAF and SABSA
  • NCSC CAF
  • Personal Projects:

  • QRL Jacking Exercise
  • Network Discovery and Security Auditing
  • Securing Inboxes: The Intersection of Email Security and NIST Framework Final Year Project
  • Tools:

  • Eramba
  • Risk Ledger
  • One Trust
  • Microsoft Visio
  • Lucidchart
  • Confluence
  • ServiceNow
  • Zscaler ZIA
  • Palo Alto Networks
  • Packet Tracer
  • Wireshark
  • Nessus
  • Nmap
  • Azure Active Directory
  • AD Manager
  • AD Audit Plus
  • ManageEngine
  • Memberships

  • Cybrary
  • CIISEC
  • CSA
  • Gartner
  • Community Involvement

  • Black Hat Europe 2025
  • WiCyS Meetup 2024
  • The Security Event 2024
  • Volunteering

  • SEO London and SEO France
  • Coaching and Mentoring
  • Education & Career Development Speaker
  • Languages

  • English Native
  • Arabic Native
  • Hobbies

  • Nature walking
  • Blogging

References

References available upon request.

Timeline

Senior Cybersecurity Architect & Consultant

Cyberfort Ltd
2024.11 - Current

Cybersecurity Consultant

MThree
2022.05 - 2024.11

Cyber Security Analyst

The Ardonagh Group
2020.09 - 2021.09

Cyber Security Academic Mentor, Part-Time

Kingston University
2019.01 - 2020.09
Maria Zaine