Summary
Overview
Work history
Education
Skills
Certification
ADDITIONAL CERTIFICATES
Timeline
Generic

MATTHEW HASELTON CA

London,United Kingdom

Summary

Chartered Accountant (CA) and Cybersecurity Consultant with experience spanning financial auditing, risk management, and information security. Began career in accounting and advisory at Deloitte and Findex, building strong financial and business acumen, before transitioning into cybersecurity and digital risk. Experienced in working across complex technology environments including legacy systems, cloud, networking, managed services, and SaaS, with exposure to frameworks such as ISO 27001, NIST, NZISM, and Australian Cyber Essentials. Currently based in London with EY UK&I, bringing a blend of technical understanding, regulatory awareness, and strong analytical skills. Working towards CIISec Principal certification.

Overview

6
6
years of professional experience
26
26
years of post-secondary education
1
1
Certification

Work history

Senior Consultant (Digital Risk)

Risk Consulting
2025.09 - 2026.06
  • Seconded to Comcast (Fortune 50 global Cable, Media & Telecommunications provider) as a Senior Technology Internal Auditor, leading audits across customer networks, mobile services, and billing operations within a complex, large-scale enterprise environment.
  • Delivered end-to-end audits from planning to reporting, including scope definition, risk assessment, control evaluation, test design (test matrices), evidence gathering, and production of clear, actionable findings summaries.
  • Assessed technical and operational controls across infrastructure, networks, applications, and cloud (data) platforms, identifying control gaps and driving risk-based remediation aligned to industry frameworks (e.g. NIST, ISO 27001).
  • Performed detailed reviews across key security domains including IAM, network security, vulnerability management, secure configuration, incident management, and asset lifecycle controls.
  • Evaluated product security and SDLC practices, alongside data protection controls such as encryption, certificate management, and access governance across customer-impacting systems.
  • Led client engagement throughout audit execution, including walkthroughs, challenge sessions, and issue discussions, influencing stakeholders from engineering teams through to senior leadership.
  • Produced high-quality audit outputs, clearly articulating risk, root cause, and business impact, supporting informed decision-making and control improvement across critical services.
  • Operated as a senior audit lead on engagements, coordinating activities across stakeholders and ensuring timely delivery in a fast-paced environment.
  • Contributed to internal capability building through training delivery, and supported business development via RFP responses and executive-level presentation materials.

(Cyber) Security Consultant

PrivSec Consulting Ltd
Wellington, New Zealand
2023.03 - 2025.03
  • Conducted certification and accreditation audits within Governance, Risk, and Compliance (GRC) framework.
  • Delivered security risk assessments and compliance activities aligned with the NZISM — New Zealand’s national information security framework — functionally equivalent to UK standards such as ISO 27001, NIST CSF, NSCC and NIST 800-53 or ISM (Australia). Applies to any government agency or third party (e.g. MSPs or vendors).
  • Experienced in assessing controls and assurance processes for classified and sensitive government systems — including personnel vetting, risk registers, system accreditation, and incident response planning.
  • Performed IT risk assessments, identified vulnerabilities, assigned risk ratings, and recommended remediation.
  • Led security audits, gathering evidence from subject matter experts (SMEs), and presenting reports to management to ensure system accreditation.
  • Conducted annual audits and remediation reviews for a Telecommunications-as-a-Service (TaaS) providers. Specific to Vendors suppling Telecom services within New Zealand.
  • Reviewed security implementations for vendors’ products, such as Fortinet, Azure, AWS, Palo Alto, Darktrace, Cisco, and F5.
  • Assessed security artifacts (e.g., incident response plans, BCP/DRP, firewall rules, and data centre reports).
  • Seconded to a government agency, conducting security assurance on vendors, including SOC 2 Type 2 and ISO 27001 reviews.
  • Audited security policies and controls for NZISM compliance.
  • Conducted system design reviews and provided security improvement recommendations.
  • Knowledge of NIST, CIS, cloud security, identity access and management (IAM), network security, and incident response.

Senior Consultant

Deloitte
Wellington, New Zealand
2022.12 - 2023.04
  • Performed financial analysis, and stakeholder management.
  • Evaluated client needs and developed plans to provide solutions.
  • Expanded management responsibilities include consulting, mentoring, and training new graduates to integrate them into the team.
  • Seconded to State NZ due to expertise in Oracle ERP/EPM, supporting system administration, and accounting functions.
  • Managed business-as-usual (BAU) tasks while balancing dual responsibilities across sysadmin and accounting.
  • Led stakeholder engagement, system testing, and the implementation of patches and internal controls.
  • Oversaw JIRA task management, including ticket assignment, testing, and validation.
  • Provided cross-functional support across Deloitte, backfilling roles due to adaptability and fast learning.

Consultant

Deloitte
Wellington, New Zealand
2022.06 - 2022.12
  • Xero expert within the office, providing system and software support.
  • Prepared accurate financial reports, highlighting progress, issues, and solutions.
  • Delivered virtual CFO (VCFO) services, managing monthly financials, payroll, and advisory for clients across multiple industries.
  • Advised on payroll systems, ensuring compliance, and operational efficiency.
  • Conducted financial forecasts and trend analysis using forecasting software.
  • Prepared various compliance documents for companies, trusts, partnerships, and individuals.
  • Managed monthly and year-end financial closings, including financial statements, and invoices.
  • Applied critical thinking to solve financial and operational challenges.

Assistant Accountant

Statistics New Zealand
Wellington, New Zealand
2021.05 - 2022.06
  • Managed Accounts Payable (AP) and Accounts Receivable (AR), ensuring efficient processes, and minimal debt write-offs.
  • Liaised with suppliers, banks, and financial institutions for account maintenance, credit cards, and payments.
  • Conducted bank reconciliations and maintained supplier and customer relationships.
  • Provided internal training on financial systems and processes for staff and customers.
  • Ensured accurate financial reporting, including accruals, general ledger reconciliations, and variance analysis.
  • Led month-end and annual account preparations, supporting external auditors for successful outcomes.
  • Maintained robust internal controls, policies, and financial compliance.
  • Managed FX payments with the treasury.

Graduate Accountant Business Advisory & Digital

Findex
Nelson, New Zealand
2020.01 - 2021.05
  • Prepared financial statements, income tax returns, FBT, and GST returns for companies, trusts, partnerships, sole traders, and individuals.
  • Collected and reconciled banking transactions, ensuring accurate balances.
  • Conducted balance sheet analysis to identify and correct discrepancies.
  • Provided administrative support to streamline accounting operations.
  • Maximized tax refunds by identifying deductible expenses, allowances, and taxable income.
  • Part of the digital transformation team, implementing Xero and MYOB for various entities.
  • Delivered Xero and MYOB training to clients and colleagues.
  • Analyzed financial and income statements to assess company performance.
  • Reviewed and resolved discrepancies in accounts and financial documentation.

Education

Graduate Diploma of Chartered Accounting -

Chartered Accountants Australia & New Zealand (CAANZ)
2001.04 - 2023.03

Bachelor of Commerce - Accounting & Economics

University of Otago
2016.02 - 2019.10

St John's College
Johannesburg, South Africa, South Africa

Skills

  • Cybersecurity certification audits & risk assessments
  • Information security policies & procedures
  • IT Governance & Compliance (Aus CyberEssential, SO 27001, SOC 2, NZISM, NIST, CIS Benchmarks, TSA ACT, PCI DSS)
  • System administration & security assurance
  • Experience with KnowBe4, JIRA, and GitLab, AWS, Azure, GCP, Palo Alto, Cisco, F5, Fortinet, Darktrace, Splunk, Data Bricks, Linux, Windows, etc
  • Stakeholder management & engagement
  • Financial analysis, forecasting, & budgeting
  • Payroll processing & Virtual CFO (VCFO) functions
  • Financial compliance & reporting (Tax, GST, FBT, financial statements)
  • Business acumen & risk management
  • Microsoft Navision, Oracle ERP & EPM and TeamMate
  • Microsoft Office Suite (Visual Code, Viso, Excel, PowerPoint, Word) – Advanced proficiency
  • Strong analytical skills & problem-solving abilities
  • Adaptable with attention to detail & collaboration skills

Certification

  • Certified Information Systems Auditor (CISA, 2025) | ISACA
  • CompTIA Security+ | CompTIA (July 2024)
  • Google Cybersecurity Certificate | Google (September 2023)
  • Certified in Cybersecurity (CC) | ISC2 (April 2023)

ADDITIONAL CERTIFICATES

  • Fortinet Network Security Expert 3: Certified Associate – Fortinet
  • Google Cloud Platform (GCP) Cert: Associate Cloud Engineer – Udemy
  • Cloud Security – Bronze Learning Badge – EY
  • EY – Artificial Learning – Cybersecurity – AI – Bronze Learning
  • GDPR and Data Protection (Diploma) – Alison
  • Security, Compliance, and Governance of AI Solutions – AWS
  • AWS Generative AI Applications – AWS
  • Machine Learning for All – UCL
  • PCI Compliance Foundation – Qualys
  • IBM: Cybersecurity Tools & Attacks, Network Security, Incident Response, System Administration
  • HarvardX: Business Analysis & Cybersecurity
  • Harvard EdX: Certificate in Data Science
  • LinkedIn Learning: Business Analysis & Project Management
  • Codecademy: Defending Against AI-Generated Attacks

Timeline

Senior Consultant (Digital Risk)

Risk Consulting
2025.09 - 2026.06

(Cyber) Security Consultant

PrivSec Consulting Ltd
2023.03 - 2025.03

Senior Consultant

Deloitte
2022.12 - 2023.04

Consultant

Deloitte
2022.06 - 2022.12

Assistant Accountant

Statistics New Zealand
2021.05 - 2022.06

Graduate Accountant Business Advisory & Digital

Findex
2020.01 - 2021.05

Bachelor of Commerce - Accounting & Economics

University of Otago
2016.02 - 2019.10

Graduate Diploma of Chartered Accounting -

Chartered Accountants Australia & New Zealand (CAANZ)
2001.04 - 2023.03

St John's College
MATTHEW HASELTON CA