Summary
Overview
Work History
Education
Skills
Timeline
References
Volunteering
Generic

Maria Zaine

Summary

A Senior Security Architect and Consultant with over 6 years of experience in enterprise security architecture and governance, specialising in IAM, Zero Trust, network security, data protection and third-party risk.

Demonstrated ability to engage senior stakeholders, clearly articulate complex security concepts, and produce high-quality architectural diagrams and HLDs that ensure compliance with data protection (GDPR) and security standards (NIST 2.0 and ISO 27001). Led the design of a 6-year Zero Trust and IAM capability roadmap using TOGAF, with developing knowledge of SABSA through ongoing professional learning.

Bilingual in English and Arabic. Holds CCZT and is currently pursuing CCSK and CISSP. Leveraging Gartner Peer Insights to track market trends and assess tool maturity.

Overview

7
7
years of professional experience

Work History

Senior Cybersecurity Architect & Consultant

Cyberfort Ltd
11.2024 - Current

Full-time consultancy role with managerial responsibilities. Client engagements listed below:

Senior Security Architect | Consultant

Cyberfort Ltd | Jan 2026 - Present

  • Performing ISO 27001 internal audits covering incident management, cloud service security, and data protection and privacy, identifying gaps and preparing for external audit compliance.

Senior Security Architect | Consultant

Quickline Communication | Nov 2025 - Jan 2026

  • Conducted ISO 27001 and TSA gap analysis, providing remediation plans for client compliance.
  • Facilitated stakeholder sessions to evaluate business context and existing security controls.
  • Delivered detailed reports outlining security mechanisms tailored to client environments.

Senior Security Architect | Consultant

Which ltd | Dec 2024 - Oct 2025

  • Authored comprehensive security policies by evaluating risks and ensuring compliance with PCI DSS, NIST 2, and ISO 27001.
  • Defined security standards, functional requirements, and control specifications aligned with organisational policies.
  • Developed an enterprise-wide Incident Management procedure to optimise response operations, incorporating RASCI, SLAs, BIAs and ensuring compliance with NIST 2.0 and ISO 27001.
  • Served as a trusted security advisor during audits, managing scope (ToR), evidence collection, and engagement with auditors.
  • Served as technical authority, explaining complex architectural designs to auditors and stakeholders.

Additional responsibility: Information Security Manager (client engagement):

  • Served as the security advisor for a 40-person team of developers and data analysts, embedding secure-by-design practices and reviewing PoC security prior to production release.

Cybersecurity Consultant

MThree
05.2022 - 11.2024

Served as an on-site consultant. Client engagement responsibilities included:

Security Architect | Consultant

Nomura International | Feb 2024 - Nov 2024

  • Defined Zero Trust (ZT) principles and IAM capabilities for a 6-year implementation plan.
  • Designed HLDs and LLDs to facilitate enterprise transformation, utilising tools like Lucidchart and Microsoft Visio.
  • Developed attack trees aligned with MITRE framework to guide architectural decisions.
  • Conducted STRIDE threat modelling, supporting integration of a global transaction tool API.
  • Managed data storage practices to ensure compliance and security. utilising NCSC and NIST guidelines.

Security Analyst & Incident Responder | Consultant

Nomura International | May 2022 - Jan 2024

  • Drove security automation by developing custom playbooks to enhance operational efficiency.
  • Managed identity and access control requests, ensuring compliance with organisational policies.
  • Identified and resolved process and control gaps in collaboration with senior management.
  • Served as the primary advisory and approval authority for proxy-related operations.

Cyber Security Analyst

The Ardonagh Group
09.2020 - 09.2021
  • Led privacy and third-party risk assessments (PIAs and KYS reviews) or onboarding vendors.
  • Developed and managed a security risk register for audit and remediation purposes.
  • Defined pentesting scope and testing strategies, identifying weaknesses and inform risk treatment decisions.

Cyber Security Academic Mentor

Kingston University
01.2019 - 09.2021
  • Assisted in university workshops for computing fundamentals module, supporting student understanding of course material.
  • Facilitated peer guidance through practical exercises and collaborative projects to enhance exam and assignment readiness.

Education

Bachelor of Science - Cyber Security And Computer Forensics (Hons)

Kingston University
London
08-2022

Skills

    Education

  • BSc Cyber Security & Computer Forensics (Honours) Kingston University 2:1
  • Skillsets:

  • Secure by design architecture
  • Defence-in-depth
  • Incident Management & Response
  • Governance and risk framework
  • Interpersonal communication
  • Technical and non-technical writing
  • Achievements

  • 2025 - 2026 Roehampton Guest Speaker
  • 2023 CSA UK Panel Member Starting Your Career in Cyber
  • Certifications

  • 2026: Certificate of Cloud Security Knowledge (CCSK) CSA In Progress
  • 2026: Certified Information Systems Security Professional (CISSP) ISC2 In Progress
  • 2025: Competence in Zero Trust (CCZT) CSA Complete
  • 2024: Zero Trust Security Model; Best Practices Framework Microsoft Complete
  • Knowledge & Experience with:

  • NIST CSF 1 & 2
  • NIST Publications ( NIST 800-207, NIST 800-53)
  • ISO 27001/2 and other ISO publications like ISO 42001
  • MITRE ATT&CK
  • CSA Cloud Control Matrix (CMM)
  • CIS 18 controls
  • CISA ZTMM
  • TOGAF and SABSA
  • NCSC CAF
  • Personal Projects:

  • Network Discovery and Security Auditing
  • Securing Inboxes: The Intersection of Email Security and NIST Framework Final Year Project
  • Memberships

  • Cybrary
  • CIISEC
  • CSA
  • Gartner
  • Community Involvement

  • Black Hat Europe 2025
  • WiCyS Meetup 2024
  • The Security Event 2024
  • Tools:

  • Eramba
  • Risk Ledger
  • One Trust
  • Microsoft Visio
  • Lucidchart
  • Confluence
  • ServiceNow
  • Zscaler ZIA
  • Palo Alto Networks
  • Packet Tracer
  • Wireshark
  • Nessus
  • Nmap
  • Wireshark
  • Packet Tracer
  • MX Toolbox
  • Cymulate
  • MyCompliance
  • Fail2ban
  • Autopsy
  • FTK Imager
  • Rapid 7
  • Splunk
  • Accenture MSS
  • Digital Shadows
  • Tipping-Point SMS
  • AD Manager & Audit Plus

  • Languages

  • English Native
  • Arabic Native
  • Hobbies

  • Nature walking

Timeline

Senior Cybersecurity Architect & Consultant

Cyberfort Ltd
11.2024 - Current

Cybersecurity Consultant

MThree
05.2022 - 11.2024

Cyber Security Analyst

The Ardonagh Group
09.2020 - 09.2021

Cyber Security Academic Mentor

Kingston University
01.2019 - 09.2021

Bachelor of Science - Cyber Security And Computer Forensics (Hons)

Kingston University

References

References available upon request.

Volunteering

Coach & Mentor, SEO London & France, Sep 2022 - Sep 2024

  • Supported Master’s and undergraduate students through 6-month mentoring engagements over a 2-year period, providing career development guidance and support.
  • Mentored students during a three-day ESG-focused hackathon, guiding teams in developing Python projects, driving innovation, and delivering high-quality presentations.

Guest Speaker, University of Roehampton, Nov 2025 - Present

  • Delivering ongoing guest lectures on areas of expertise, bridging academic concepts with real-world industry practices.
  • Topics covered include: "Human Thinking Enhanced by AI, Not Replaced", "Introduction to GRC".
Maria Zaine