Ruby Njoroge
Cybersecurity Consultant - GRC and Security Advisory
About Me
I am an information security GRC and cyber risk professional with a background across fintech, telecommunications, cybersecurity innovation, and independent consulting. My strongest work is in security governance, IT risk, audit and assurance, control assessment, remediation, policy governance, third-party assurance, privacy, and security program development. I have built and strengthened security and GRC processes, coordinated assessments for regulated financial-services clients, and translated standards and technical findings into practical controls, evidence, remediation plans, and risk decisions for technical teams, management, clients, and auditors.
My broader technical background in security operations, vulnerability management, incident response, digital forensics, product security, and secure software development gives me a practical foundation for GRC. It helps me evaluate how controls operate across systems, products, access, logging, change management, evidence, and reporting rather than treating compliance as a documentation exercise.
I am currently building practical capability in Python, AWS, Terraform, control validation, and continuous-compliance workflows through structured, hands-on portfolio projects. I also serve as Founding President of the GRC Engineering Club Kenya Chapter. I am exploring opportunities across information security GRC, cyber risk, audit and assurance, control assurance, product security governance, security program management, and related technical GRC roles, particularly work that connects risk, controls, technology, evidence, and accountable action.
Experience Highlights
- Established Craft Silicon's first dedicated information security and GRC function after repeated client audit findings.
- Performed a 245-point IT general controls and information security assessment across 11 domains, then led remediation of 95 findings, including 57 high-risk weaknesses, and achieved validated closure of 74 through evidence review and retesting.
- Coordinated security assessments for regulated financial services clients, including banks and SACCOs, from scoping and evidence collection through remediation, retesting, and closure.
- Co-architected and operationalised Craft Silicon's first AlienVault USM deployment across 37+ critical assets, establishing centralised monitoring, triage, escalation, evidence handling, and reporting.
- Led a multidisciplinary digital forensics research and software engineering function and expanded the portfolio from one inherited system to three forensic and investigative products.
- Embedded GRC, privacy, laboratory quality, evidence integrity, identity and access, and product security controls across three forensic and investigative products supporting 13 forensic disciplines.
- Established secure SDLC governance across three products, from security requirements and threat modelling through testing, deployment approval, and remediation.
- Authored a risk-based product security review plan covering 43 Android applications and 10 web applications.
- Supported 15+ digital investigations and later directed specialist DFIR support for law enforcement led financial fraud investigations.
- Delivered DFIR, Mobile Security, and Reverse Engineering training to 200+ professionals across government, higher education, industry, and community programs.
Get in Touch
LinkedIn DM is the best way to reach me. You can also contact me at ruby.p.njoroge@gmail.com.
Specializations
Languages & Tools
Frameworks
Certifications
Projects
An identity-first, read-only AWS GRC workflow covering resource inventory, selected S3 and IAM control assessments, deterministic findings, management reporting, and integrity-verified evidence packaging using SHA-256 digests. Supported by 453 automated tests.
An active fictional SOC 2 lab using Probo for scope, risk, asset, third-party, control, and task management, with Prowler being added for AWS assessment, findings, and evidence workflows.
A Terraform implementation of selected AWS S3 controls, including encryption, versioning, public-access blocking, access logging, governance tags, and machine-readable plan evidence.
A Python validator for fictional CSV control registers, with required-field, accepted-value, and cross-field checks, readable findings, process exit codes, and 14 automated tests.