๐ Certified IS Auditor and Certified in Cybersecurity with a keen eye for IT security, IT Risk & Controls, SOC, ITGC, ITAC, compliance, and risk management. I specialize in evaluating IT systems, ensuring regulatory compliance, and strengthening cybersecurity controls (covering logical accesses, change management and IT operations) to protect businesses from threats and vulnerabilities.
What I Offer:
โ IT & Internal Audit engagement (ISO 27001, NIST, COBIT, SOX, HIPAA, PCI-DSS)
โ Risk Assessment & Control Evaluations
โ Cybersecurity Assessments & Compliance Checks
โ IT Governance & Internal Control Reviews
โ Security Policy Development & Implementation
โ IT General Control Testing, IT Application Control Testing
โ Business Continuity & Disaster Recovery Planning
Why Work With Me?
โ 5+ years of experience in IT auditing, SOC Assessment. Internal Audit, Cybersecurity, and Compliance
โ Expertise in regulatory frameworks & industry best practices
โ Strong communication skillsโclear, actionable reporting
โ Commitment to helping businesses secure their IT environment
๐ก Letโs work together to strengthen your IT security, Business controls, ensure compliance, and mitigate risks effectively. Contact me today to discuss your project!
Security Policies & Procedures Documentation
OS Security
Internal Auditing
IT General Controls Testing
Information Security Audit
SOC 2
Application Audit
IT Compliance Audit
SOC 1
GDPR Compliance Review
ISO 27001
SAP
Policy Writing
Sarbanes-Oxley Act
Cybersecurity Management
NIST Cybersecurity Framework
Hamza F.
Rawalpindi, Pakistan
$25/hr
4.7
13 jobs
Experienced professional with extensive expertise of Big4 (Deloitte and PwC) in accounting, assurance, and governance, risk, and compliance.
Worked across diverse regions, including Saudi Arabia, UAE, China, and Pakistan, with a strong focus on telecom and technology sectors. Successfully collaborated with leading organizations such as STC, e&, Mobily, and China Mobile, providing tailored solutions that drive operational excellence and compliance.
1. Extensive experience of IFRS/US GAAP implementation, finance digital/ AI transformation, climate finance and bookkeeping services.
2. Demonstrated success in internal audits across finance, commercial operations, and network operations, focusing on compliance, operational efficiency, and policy and process standardisation.
3. Adept at conducting Internal Control Reviews (ICR), quality audits, annual risk assessments, and financial reporting audits to ensure accuracy and reliability.
4. Skilled in designing and improving policies and processes as part of management consulting engagements, delivering enhanced controls and risk mitigation strategies.
Financial Audit
Bookkeeping
Internal Control
Intuit QuickBooks
Financial Reporting
Microsoft Office
Policy Writing
Financial Analysis
International Financial Reporting Standards
Business Continuity Plan
Financial Planning
Governance, Risk Management & Compliance
Environmental, Social & Corporate Governance
Digital Transformation
AI Consulting
Hammad T.
Islamabad, Pakistan
$10/hr
5.0
2 jobs
Automated systems flag obvious risks, but the real threats and costliest false positives hide in the edge cases. With over two years of hands-on experience in the FinCrime operations of a global fintech giant, I specialize in frontline screening, risk assurance, and compliance process optimization.
I do not simply process complex alerts; I audit the workflows behind them to ensure your defense systems are impenetrable, perfectly aligned with global regulations, and operationally efficient.
Core Areas of Expertise:
Financial Crime Compliance: Anti-Money Laundering (AML), Sanctions & PEP Screening, and Adverse Media investigations.
Due Diligence & Onboarding: Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), and meticulous KYC/KYB document verification (authenticating IDs and spotting forged/synthetic submissions).
Risk & Fraud Operations: Fraud Investigation, Transaction Monitoring, Behavioral Analysis, and end-to-end Case Management.
Quality Assurance & Auditing: Risk Assessment, reviewing analyst investigations, identifying procedural gaps, and driving SOP updates to improve team accuracy.
The Technical Edge:
I leverage advanced data analysis (Google Sheets, pivot tables, complex data structures) and AI-assisted scripting to automate reporting workflows, track compliance KPIs, and significantly reduce processing times.
Recognized for strong analytical thinking, uncompromising attention to detail, sound judgment, and a commitment to maintaining the highest standards of compliance.
Anti-Money Laundering
Know Your Customer
Financial Risk
Regulatory Compliance
Fraud Detection
Quality Assurance
Risk Assessment
Governance, Risk Management & Compliance
Virtual Assistance
Google Sheets
FinTech
Risk Analysis
Hameed U.
Islamabad, Pakistan
$25/hr
5.0
6 jobs
Upwork Top Rated ยท 100% Job Success ยท CISM Certified ยท 10 Years Experience
I help SaaS and cloud-native companies reach audit-ready status for SOC 2, ISO
27001, ISO 42001 and GDPR โ on schedule, without disrupting your product roadmap or
slowing down your sales cycle.
I have led compliance programmes across the full lifecycle โ from
initial gap assessment and policy design through to auditor coordination
and surveillance audit preparation. My engagements cover every department
that auditors touch: IT, HR, Legal, Finance, DevOps, and Procurement โ so
nothing falls through the cracks and you walk into audit day confident.
โโโโโโโโโโโโโโโโโโโโโโโโโโโ
WHAT I DELIVER
โโโโโโโโโโโโโโโโโโโโโโโโโโโ
โธ SOC 2 Type I & II Readiness
Full gap assessment, control mapping, policy library, and auditor
coordination โ from kickoff to clean audit report.
โธ ISO 27001 Certification & Surveillance Support
ISMS design and implementation, Statement of Applicability, risk
register, internal audit programme, and evidence preparation for
certification and surveillance audits.
โธ GDPR Compliance
Data mapping, Records of Processing Activities (RoPA), DPIAs, privacy
notices, Data Processing Agreements, and breach notification procedures.
โธ AI Governance & ISO 42001
Emerging framework โ policy design and readiness assessments for
organisations integrating AI into their products and workflows.
โธ Security Policy Library
30+ audit-ready policies written in plain language โ policies your
engineers will actually read and follow, not 40-page documents that
sit on a shelf.
โธ Vendor & Third-Party Risk Management
Supplier security assessments, due diligence questionnaires, contract
security clauses, and ongoing monitoring frameworks.
โธ Audit Coordination & Evidence Management
I act as your single point of contact with external auditors โ
managing evidence requests, Information Request Lists (IRLs), and
auditor communications so your team can stay focused on the product.
โโโโโโโโโโโโโโโโโโโโโโโโโโโ
FRAMEWORKS & STANDARDS
โโโโโโโโโโโโโโโโโโโโโโโโโโโ
SOC 2 ยท ISO 27001:2022 ยท GDPR ยท PCI DSS ยท NIST CSF ยท ISO 42001 ยท HIPAA ยท CIS Controls
ISO 9001 ยท ISO 20000-1
โโโโโโโโโโโโโโโโโโโโโโโโโโโ
WHY CLIENTS CHOOSE ME
โโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ I understand your stack before you explain it
I work exclusively with SaaS and cloud-native teams on AWS, GCP, and
Azure. I speak the language of your engineers, not just your auditors.
โ I write policies people actually follow
Every policy I deliver is proportionate, readable, and built around
your actual workflows โ not copied from a template library.
โ I cover the full scope โ not just one layer
Most consultants focus on IT controls. I work across HR, Legal,
Finance, DevOps, and Procurement โ the departments auditors always
reach into and that always catch companies off guard.
โ I have coordinated with major audit firms
I have prepared evidence packages and managed IRL submissions for
surveillance and certification audits coordinated with firms including - so I know exactly what auditors look for and what they push back on.
โ I deliver structure, not just advice
Every engagement produces working artefacts: trackers, dashboards,
policy documents, risk registers, and roadmaps โ not slide decks with
recommendations you have to figure out how to implement.
โโโโโโโโโโโโโโโโโโโโโโโโโโโ
WHO I WORK WITH
โโโโโโโโโโโโโโโโโโโโโโโโโโโ
I work primarily with SaaS companies preparing for their
first SOC 2 or ISO 27001 audit, and with established companies managing
surveillance audits or expanding their compliance scope into GDPR or
AI governance.
Typical client profile:
โ 20โ300 employees
โ Cloud-native infrastructure (AWS / GCP / Azure)
โ Small or no internal security team
โ Facing an enterprise customer security review or upcoming audit
โ Compliance is blocking a deal or a funding round
Risk Management
ISO 27001
SOC 2
PCI DSS
GDPR
Privacy Policy Writing
Privacy Impact Assessment
California Consumer Privacy Act
IT Compliance Audit
SaaS
Data Privacy
Maheen F.
Rawalpindi, Pakistan
$30/hr
4.9
20 jobs
"We need to become compliant... but where do we even start?"
This is one of the most common conversations I have with business leaders.
For many organizations, cybersecurity compliance is viewed as a necessary burden rather than a business enabler.
There are regulations to satisfy.
Customers asking for certifications.
Enterprise clients demanding security questionnaires.
Audits approaching.
Teams unsure where to begin.
And management wondering...
"Will all of this actually add value to the business?"
The answer is yesโif compliance is implemented correctly.
A well-designed Compliance Management Program is far more than a collection of policies or an audit checklist.
It helps organizations:
โ Meet regulatory obligations with confidence.
โ Win customer trust and unlock new business opportunities.
โ Reduce cybersecurity and privacy risks.
โ Establish repeatable governance processes.
โ Prepare for audits without the last-minute panic.
Whether your organization needs to comply with ISO 27001, SOC 2, ISO 42001, GDPR, HIPAA, PDPL, NIST, SAMA, CTDISR, or requires an integrated compliance program that combines multiple frameworks, the objective should always be the same:
Build compliance once. Reuse it across multiple regulatory and business requirements.
That is exactly where I help.
I work alongside organizations from the very beginningโnot simply as an auditor, but as a trusted compliance partner.
I help organizations:
โข Assess their current maturity and identify compliance gaps.
โข Design a practical, business-aligned Compliance Management Program.
โข Develop policies, procedures, governance structures, and technical controls.
โข Conduct risk assessments and internal audits.
โข Prepare for certification and regulatory assessments.
โข Build meaningful KPIs and compliance metrics for executive reporting.
โข Create cost-effective solutions by integrating multiple frameworks instead of treating every regulation as a separate project.
Most importantly...
I don't just deliver documents and leave.
One of the biggest reasons compliance programs fail is because employees are never properly onboarded.
A successful compliance program depends on people.
That's why I personally work with teams to:
โ Explain why each control exists.
โ Conduct practical awareness sessions and hands-on workshops.
โ Train process owners and control owners.
โ Help employees understand their responsibilities.
โ Ensure the organization can independently sustain the program after my engagement ends.
My objective is simple:
When I offboard, your organization should not become dependent on meโit should become confident enough to manage compliance on its own.
Over the past 9+ years, I've had the privilege of supporting organizations across government, healthcare, financial services, telecom, SaaS, and technology sectors on national and international engagements.
Some of the work I'm proud to have contributed to includes:
โข Enabling an application to achieve compliance required for approval by the Australian Taxation Office (ATO).
โข Supporting organizations in achieving ISO 27001, SOC 2, PDPL, and other regulatory compliance objectives.
โข Developing cybersecurity governance and policy frameworks for organizations in Saudi Arabia.
โข Assisting a client in obtaining product licensing through compliance with Qatar PDPL.
โข Preparing AI governance playbooks aligned with the EU AI Act.
โข Conducting internal audits, compliance assessments, and remediation programs across government and private-sector organizations.
Certifications
โข Certified Information Privacy Professional (CIPP/E)
โข ISO/IEC 27001 Lead Auditor
โข ISO/IEC 42001 Lead Auditor
โข Certified in Cybersecurity (CC) โ ISCยฒ
โข ISO/IEC 27001 Information Security Associate
โข ISO/IEC 20000 IT Service Management Associate
I genuinely believe that compliance should never slow down businessโit should enable growth, strengthen customer confidence, and improve organizational resilience.
If your organization is planning its first compliance initiative, struggling with multiple regulatory obligations, or looking for a practical and cost-effective compliance partner, let's connect.
I'd be happy to help turn compliance into a business advantage.
๐ Standards & Frameworks I Work With:
ISO 27001 | ISO 42001 | ISO 22301 | ISO 27011 | ISO 15408 (Common Criteria) | SOC 2 | NIST 800-53 | NIST CSF | CIS Controls | PCI DSS | HIPAA | GDPR | SAMA | CTDISR | PDPL-UAE| PDPL-Qatar| PDPL- KSA
๐ Keywords:
Internal Audit | Cybersecurity GRC | Risk Assessment | Gap Analysis | ISO 27001 | SOC 2 | Compliance | NIST CSF | GDPR | HIPAA | AI Compliance | Policy Development | Audit Reporting | Remediation Planning | Cost-effective Security Solutions | ISO 42001 | CTDISR | CIS Controls | AI Risk Management| SAMA| PDPL| CTDISR| Risk Management| Audit Documentation| Policy Review and Update| Research| CIPP/E
Risk Management
ISO 27001
IT Compliance Audit
Information Security Audit
Governance, Risk Management & Compliance
Policy Development
NIST Cybersecurity Framework
NIST SP 800-53
Gap Analysis
Compliance Consultation
GDPR Compliance Review
Artificial Intelligence
Privacy Impact Assessment
Certified Information Privacy Technologist
Muhammad Muqeet K.
Lahore, Pakistan
$35/hr
4.9
29 jobs
Top Rated Freelancer on Upwork for more than 3 years specializing in PCI DSS, SOC2 certifications, vCISO, penetration testing and vulnerability assessment services.
Got 5+ long term clients after building their Information Security Governance program from the scratch and getting them certified against SOC2 Type 2 and PCI DSS certifications.
A high ratio of client retention by delivering top notch penetration test and vulnerability assessments reports.
Seasoned professional with 10 years of experience in Information Security Governance, operations, Risk & Compliance. I provide PCI DSS and SOC2 audit certification services, conduct penetration tests and implementation and management of SIEM solutions.
Enterprise Risk Management
Penetration Testing
Vulnerability Assessment
Cybersecurity Management
Information Security Consultation
Information Security Audit
PCI
Information Security Governance
Documentation
LogRhythm
ISO 27001
SOC 2 Report
Risk Assessment
IT Compliance Audit
Web App Penetration Testing
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
โUpwork provides an umbrella-level of security. I can see a talentโs work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.โ
KD
Kim Darling
Emerald Tiger
โUpwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.โ
DM
David Merry
Kinetic Investments
โOur very specific requirements can be a challengeโWith Upwork, weโre able to access a bigger community to ensure the success of our projects.โ
KK
Katja Krohn
Summa Linguae
How do I hire a Enterprise Risk Management Freelancer in Pakistan on Upwork?
You can hire a Enterprise Risk Management Freelancer in Pakistan on Upwork in four simple steps:
Create a job post tailored to your Enterprise Risk Management Freelancer project scope. We'll walk you through the process step by step.
Browse top Enterprise Risk Management Freelancer talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Enterprise Risk Management Freelancer profiles and interview.
Hire the right Enterprise Risk Management Freelancer for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Enterprise Risk Management Freelancer?
Rates charged by Enterprise Risk Management Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Enterprise Risk Management Freelancer in Pakistan on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Enterprise Risk Management Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Enterprise Risk Management Freelancer team you need to succeed.
Can I hire a Enterprise Risk Management Freelancer in Pakistan within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Enterprise Risk Management Freelancer proposals within 24 hours of posting a job description.
Find more freelancers
Top cities for Enterprise Risk Management Freelancers in Pakistan