OT

Oswald Eyram Toku

4 years of experience

GRC & IT Auditor at Yesyoucan Cybersecure LLC

Areas of Expertise

Business Continuity and Disaster RecoveryGovernance Risk and CompliancePhysical SecuritySecurity Awareness TrainingAccess ControlSocial Engineering PreventionIncident ResponseCloud SecurityVulnerability ManagementData ProtectionZero Trust SecurityCybersecurity Policy DevelopmentCybersecurity Risk AssessmentSupply Chain SecuritySecurity Auditing

Profile

Detail-oriented and results-driven GRC and IT Audit professional with experience spanning cybersecurity governance, policy advisory, risk management, compliance, and independent assurance across consulting, technology, and financial services environments. I bring a risk-focused approach to identifying control gaps, assessing business and cybersecurity risks, strengthening governance frameworks, and providing actionable recommendations to improve organisational resilience and security posture. My experience encompasses security incident management, third-party and vendor risk management, threat and vulnerability management, business continuity management, disaster recovery, security assessments, compliance reviews, and IT control assurance. I have led and contributed to results-oriented projects in complex and regulated environments, demonstrating strong analytical and critical-thinking abilities, excellent reporting and documentation skills, effective communication, leadership, and the ability to collaborate across multidisciplinary teams. I have working knowledge of regulatory and compliance requirements including the Sarbanes-Oxley Act (SOX), General Data Protection Regulation (GDPR), Ghana Data Protection Act, Ghana Cybersecurity Act, and HIPAA. I also have experience working with and applying industry frameworks and standards including ISO/IEC 27001, ISO/IEC 42001, ISO 22301, ISO 31000, ISO 9001, NIST Cybersecurity Framework (NIST CSF), NIST Risk Management Framework (NIST RMF), COSO, PCI DSS, SOC 1, SOC 2, and COBIT. I am committed to helping organisations strengthen their security and control environments by protecting critical assets, keeping risks within acceptable levels, evaluating the effectiveness of security controls, promoting policy compliance, strengthening resilience, and supporting the prevention and detection of fraud.