Otas Ukpebitere

Otas Ukpebitere

Information Security Consultant

Sunderland, United Kingdom

About Me

I’m an IT information Security professional with experience across governance frameworks, compliance assurance, and technology-driven risk management. I focus on translating regulatory and security requirements into practical, scalable solutions that support delivery teams and strengthen security by design cultures. Passionate about bridging the gap between governance and execution to help organisations build resilient, well governed systems.

I have a background and hands-on experience as an ISO 27001 Lead Auditor, with experience in compliance and assurance, ISO-based governance, risk management, information security operations, and project management.

Throughout my career, I have worked across a range of spaces - from being a risk management specialist to a freelance Management system Consultant/ ISO Auditor to project management and information security, doing 3rd party project and security consulting, with my most recent role as an Information Security Consultant at Opencast Software. My breadth of industry exposure helped me learn how to design and implement scalable compliance frameworks where they are needed most, get in the weeds of broken processes, and build solutions that hold up when it matters.

I am passionate about going beyond checkbox compliance, ensuring risks are used to inform governance and compliance. I focus on people, processes, and technology, helping organisations translate regulatory requirements into practical, workable solutions.

Beyond my technical skills, I bring strong stakeholder engagement experience. I've worked closely with engineering teams, senior leadership, and external auditors to ensure clarity, alignment, and smooth delivery of security outcomes. My background in project management also helps me communicate effectively and keep complex initiatives moving forward.

Beyond my day-to-day work, I am a contributing member of one of ISC2 committees focused on enabling smaller organisations less susceptible to cyber attacks. I am proud to serve as volunteer for the MS (Multiple Sclerosis) Society.

Experience Highlights

  • Successfully implemented an Integrated Management System (IMS)
  • Freelance Management System/ ISO Compliance Auditor, executed compliance Audit & assessment covering ISO 27001, ISO 9001, ISO 14001, & OSHAS 18001
  • Delivered different security projects such as Incident management process bot upgrade, Web Application Firewall implementation, SSO migration from Duo to Okta, etc.
  • Led secure delivery of digital services used by over 2M+ UK citizens annually
  • I have created multiple GRC projects to improve my coding abilities

Get in Touch

Feel free to reach out via email or LinkedIn about anything!

Specializations

Audit & AssuranceRisk ManagementSecurity GovernanceThird-Party RiskProject management

Languages & Tools

PowerShellPythonTerraformGithubGit

Frameworks

GDPRISO 27001NIST CSFNIST RMF

Certifications

ISO 27001 Lead AuditorISO 27701 Lead AuditorNIST Cybersecurity ProfessionalAWS Cloud PractitionerProject Risk Management (PMI-RMP®)ISO 27001 Lead Implementer

Projects

Automated AWS Access Review

AWS Access Review is a comprehensive, zero-configuration security assessment tool that automatically evaluates your AWS environment for potential security risks and compliance gaps.

S3 Security Compliance Automation

This project demonstrates how to deploy secure AWS S3 buckets using Terraform and verify compliance with key security controls using an automated Bash script.