AKINTAYO Sofiyah Modupeola

Cybersecurity Engineer & Data Analyst/Scientist
Lagos, NG.

About

I am an accomplished Medical Scientist and GRC Engineer with 4 years of experience in data analytics, transitioning into Cyber space, AI and Data Science. Proficient in extracting and interpreting complex datasets while ensuring rigorous technical governance, risk management, and regulatory compliance. Adept at applying generative AI principles for innovative solutions, backed by a deep understanding of secure data frameworks. Eager to leverage analytical rigor and GRC expertise to develop ethical, secure, and impactful AI solutions.

Work

International Cybersecurity and Digital Forensic Academy
|

GRC Engineering Trainee

Nigeria

Student Trainee

Highlights

Compliance Documentation & Reporting System Design: Architected a centralized, data-driven compliance system for TechFlow Industries, transitioning the firm from reactive paper-based processes to a proactive digital repository with standardized reporting templates and a real-time KPI dashboard.

Authorized External Security & Compliance Assessment: Conducted a comprehensive vulnerability assessment using Nmap and Burp Suite Professional, identifying critical flaws like SQL Injection and Broken Access Control, and mapped findings to the OWASP Top 10 framework for executive remediation.

Quantitative Risk Analysis & Treatment Planning : Conducted financial risk modeling for mobile banking vulnerabilities, calculating Single Loss Expectancy (SLE) and Annualized Loss Expectancy (ALE) to demonstrate a 90% risk reduction and a high ROI for proposed security controls.

HIPAA GRC Engagement: Performed a gap analysis against the HIPAA Security Rule, designed a formal Password and Authentication Policy (PAP), and developed a ransomware recovery strategy involving forensic analysis and sanitized system restoration.

Cybersecurity Risk Assessment & Management Strategy: Developed a hybrid risk management framework for TechStart Solutions by integrating NIST and ISO 31000 standards, producing a comprehensive risk register and a three-phase remediation roadmap for 500+ clients.

Multinational Compliance Crisis Management (GlobalSync Inc.): Assumed the role of Chief Compliance Officer to resolve complex international issues including GDPR data transfer violations, FCPA bribery allegations, and the implementation of a "Tone at the Top" governance strategy.

Security Log Analysis & Threat Detection: Analyzed failed authentication and vulnerability logs to detect brute-force attacks and unaddressed critical vulnerabilities (e.g., CVE-2023-9012), proposing technical remediations like MFA and automated SIEM flagging.

Linux Security Monitoring & Auditing: Executed hands-on system auditing and hardening on Linux environments using tools such as auditd, Lynis, and journalctl to identify and remediate configuration vulnerabilities.

Ransomware Incident Response Planning (FinanceFirst Credit Union): Developed a detailed ransomware incident response playbook, establishing critical protocols for initial detection, system isolation, log preservation, and secure credential management to ensure business continuity.

Digital Transformation Risk Assessment (SecureBrew Cafe): Conducted a comprehensive risk analysis for a cloud-based POS and loyalty app ecosystem; identified high-impact risks like Man-in-the-Middle attacks and recommended isolation of public Wi-Fi from secure transaction networks.

Digital Transformation Risk Assessment (SecureBrew Cafe): Conducted a comprehensive risk analysis for a cloud-based POS and loyalty app ecosystem; identified high-impact risks like Man-in-the-Middle attacks and recommended isolation of public Wi-Fi from secure transaction networks.

Continuous Risk Monitoring & Detective Control Implementation: Designed and deployed a detective control using the Wazuh platform to monitor a designated sensitive file directory for unauthorized modifications, ensuring a centralized audit trail and real-time alerting for compliance mandates.

Disaster Recovery After-Action Analysis (FinanceFirst Bank): Authored a formal after-action report following a primary data center failure; analyzed the execution of disaster recovery protocols, data synchronization integrity, and stakeholder communication effectiveness to improve future resilience.

Crisis Communication & Data Breach Response Simulation: Orchestrated a simulated data breach response including the development of a Crisis Communication Strategy, employee notification plans, and media response statements to maintain organizational reputation and transparency.

Developed a specialized Python-based tool to automate Governance, Risk, and Compliance (GRC) workflows, transitioning qualitative risk assessments into data-driven financial models.

NITDA / Federal Government of Nigeria
|

Technical Trainee - Data Science and Machine Learning

Lagos, Lagos State, Nigeria

Summary

Undergoing hands-on fellowship focused on technical specialization, project delivery, and workplace readiness within Data Science and Machine Learning.

Highlights

Applied SQL, Python, and Azure Machine Learning services to develop real-world solutions within the African Deeptech Challenge, demonstrating practical application of advanced AI/ML concepts.

Undergoing hands-on technical specialization and project delivery, focusing on data science and machine learning, preparing for immediate workplace readiness.

Engaged in a rigorous fellowship program, building foundational expertise in AI/ML through practical assignments and collaborative problem-solving.

Applied Python in Breast Cancer Classification using different classification models.

Engineered a predictive financial tool using Python to model cybersecurity risk impact, utilizing various data points such as Single Loss Expectancy (SLE) and Annual Rate of Occurrence (ARO).

Designed a user-centric interface that allows for dynamic "What-If" scenario modeling, helping organizations visualize the financial benefit of specific security controls before deployment.

Secure Edge Technologies - LASGIPP
|

Cybersecurity Intern

Lagos, Lagos State, Nigeria

Summary

Developed audit plans and internal auditing processes, authored cybersecurity newsletters, and significantly enhanced organizational security awareness.

Highlights

Developed comprehensive audit plans and internal auditing processes, strengthening organizational security posture and compliance.

Authored impactful cybersecurity newsletters, significantly increasing employee awareness and adherence to best practices across the organization.

Contributed to enhanced overall organizational security and awareness through proactive development and dissemination of critical cybersecurity information.

Eko University of Medicine and Health Sciences
|

Technologist

Lagos, Lagos State, Nigeria

Summary

Managed the Morbid Anatomy Museum and the University's Histopathology Laboratory, ensuring efficient operations and informing improvements.

Highlights

Managed daily operations of the Morbid Anatomy Museum and Histopathology Laboratory, ensuring efficient resource utilization and compliance with academic standards.

Analyzed end-of-posting evaluation sheets to identify operational inefficiencies and inform strategic improvements in departmental effectiveness.

Streamlined laboratory workflows and museum processes, contributing to optimized operational efficiency and improved data management.

NITDA / Federal Government of Nigeria
|

Technical Trainee - Animation

Lagos, Lagos State, Nigeria

Summary

Completed hands-on training in animation, creating explainer and animated videos using various tools.

Highlights

Utilized various animation tools to create diverse explainer and animated videos, enhancing communication and visual storytelling capabilities.

Completed intensive hands-on training in animation techniques, mastering software and workflows for multimedia content creation.

Education

University of Lagos
Lagos, Lagos State, Nigeria

M. Sc.

Cell Biology and Genetics

Grade: 4.29/5.00

Ladoke Akintola University of Technology
Ogbomosho, Oyo State, Nigeria

B. Tech.

Anatomy

Grade: 4.35/5.00

Languages

English

Certificates

ISO 27001 & ISO 42001 Lead Implementer

Issued By

International Cybersecurity and Digital Forensic Academy

Data Science/Machine Learning

Issued By

DeepTech Ready by Data Science Nigeria

Microsoft Certified: Azure AI Fundamentals

Issued By

Microsoft

ISO/IEC 20000:2018 I. T Service Management Systems (ITMS) Foundation

Issued By

SandBP

Career Essentials in Generative AI

Issued By

Microsoft and LinkedIn

ISO/IEC 22301:2019 Business Continuity Management Systems (BCMS) Foundation

Issued By

SandBP

Google Data Analytics

Issued By

Google

Skills

Data Analytics

Data Analytics, Data Interpretation, Data Visualization, Complex Datasets.

Artificial Intelligence

Generative AI, AI Fundamentals, AI Solutions, Azure AI Services.

Machine Learning

Machine Learning, Azure Machine Learning.

Programming Languages

Python, SQL.

Data Tools & Platforms

Power BI, Microsoft Excel, Microsoft Azure AI services, Linux.

Animation & Design

Animation, Explainer Videos, Adobe AfterEffect, Adobe Illustrator, Alice.

Microsoft Office Suite

MS Word, Excel, PowerPoint.

Soft Skills

Attention to Detail, Problem-Solving, Critical Thinking, Communication & Storytelling, Adaptability & Flexibility, Curiosity, Continuous Learning, Collaboration, Teamwork.

Vendor & Third-Party Risk Management (TPRM)
Cybersecurity Technical Tools and Platforms

Security Monitoring & SIEM: Wazuh, Vulnerability Scanners: Burp Suite Professional, Nmap, Nikto, and Nuclei., Linux Auditing & Log Analysis, Netdiscover, Cloud & Virtualization: VirtualBox, VMware, and Ubuntu Server environments..

Risk Assessment & Modeling

Quantitative Risk Analysis, Financial Impact Analysis, Qualitative Assessment.

Governance & Policy Design

Policy Development, Compliance Framework Mapping, Framework Implementation.

Incident Management & Resilience

Incident Response (IR), Business Continuity & Disaster Recovery (BCDR), Crisis Communication.

AKINTAYO Sofiyah Modupeola