Summary
Overview
Work history
Skills
Professional Affiliations & Recognition
Education
Tools
Teaching & Mentoring
References
Timeline
Generic

Maria Zaine

Summary

Senior Cyber Security professional with 6 years of experience spanning industry practice and academic engagement, bringing real-world depth into the classroom. Currently guest lecturing at the University of Roehampton, with prior academic mentoring at Kingston University and SEO London. Undergraduate research involved surveying CISOs on email security effectiveness within financial institutions. Maintains a Medium security blog for students and security professionals. Holds CCZT; pursuing CISSP and CCSK.

Overview

6
6
years of professional experience

Work history

Senior Security Architect | Consultant

Cyberfort
2024.11 - Current

Client engagements — Quickline Communications & Which?; additionally appointed as Information Security Manager.

  • Conducted ISO27001 and TSA gap analysis, facilitating stakeholder sessions to identify control gaps and deliver remediation plans.
  • Designed security policies, standards, and control specifications ensuring compliance with PCI DSS, NIST 2.0, Cyber Essentials, CIS 18, and ISO 27001/2.
  • Developed enterprise-wide Incident Management procedure, incorporating RASCI, SLAs, BIAs, and DFIR.
  • Acted as technical authority and trusted advisor during audits, managing scope, evidence collection, and communicating complex designs to stakeholders.
  • Led security strategy as SME for a 40-person development and data team, embedding secure-by-design practices and overseeing PoC security reviews.

Security Architect | Consultant

Mthree
2022.05 - 2024.10

Client engagement — Nomura International | Progressed from Security Analyst & Incident Responder to Security Architect.

  • Defined Zero (CISA ZTMM) Trust and IAM capabilities for a 6-year enterprise implementation roadmap, utilising TOGAF and SABSA.
  • Designed HLDs and LLDs to guide engineering and development teams through enterprise transformation.
  • Applied STRIDE threat modelling and MITRE ATT&CK-aligned attack trees to guide architectural decisions and support global API integration.
  • Developed custom playbooks to automate security operations and resolve process and control gaps, improving overall efficiency.
  • Managed identity and access control requests, leveraging CIS 18 controls where applicable to enforce organisational policy compliance.

Security Analyst

The Ardonagh Group
2020.09 - 2020.09
  • Led third-party risk assessments and privacy impact analyses (VRAs, KYS, PIAs) to support secure vendor onboarding.
  • Developed and maintained a security risk register (risk assessment, risk matrices), supporting remediation plans in liaison with the GRC team.
  • Defined pentesting scope and testing strategies, identifying vulnerabilities and informing risk treatment decisions.

Skills

  • Incident Management & Response
  • Governance, Risk & Compliance
  • Security Architecture & Strategy
  • Network Security Fundamentals
  • Communication, Writing & Public Speaking

Professional Affiliations & Recognition

  • CIISEC, Gartner, Cybrary
  • CSA UK Panel Member (2023)

Education

BSc Cybersecurity & Computer Forensics 2:1, Kingston University (2022)

  • Co-Founder, Kingston University Cyber Security Society, KUCSS.
  • Awarded with honours.
  • Final Year Project: Applying Security Frameworks & Defence-in-Depth to Email Security

Tools

  • GRC: Eramba, OneTrust, MyCompliance, Risk Ledger
  • Network: Zscaler ZIA, Palo Alto, Wireshark, Nessus, Packet Tracer
  • SIEM: Splunk, Rapid7, Accenture MSS, Tipping Point SMS, ServiceNow
  • Security Testing: Kali Linux, Metasploit, Nmap, Cymulate
  • OSINT: Digital Shadows, RF
  • Forensics: Autopsy, FTK Imager
  • IAM: AD Manager & Audit Plus
  • Architecture: Visio, Lucidchart

Teaching & Mentoring

Guest Lecturer | University of Roehampton | Nov 2025 - Present

  • Delivering guest lectures, bridging real-world industry practice with academic learning, covering topics including GRC and AI.

Academic Mentor | Kingston University | Jan 2019 - Sep 2021

  • Supported undergraduate students through workshops covering computing fundamentals and networking.

Coach & Mentor | SEO London & France | Sep 2022 - Sep 2024

  • Provided structured career mentoring to Master's and undergraduate students. Mentored high school students through a three-day ESG-focused hackathon, guiding Python development, project delivery, and panel presentations.

References

References available upon request.

Timeline

Senior Security Architect | Consultant

Cyberfort
2024.11 - Current

Security Architect | Consultant

Mthree
2022.05 - 2024.10

Security Analyst

The Ardonagh Group
2020.09 - 2020.09
Maria Zaine