I built a fictional fintech's entire security programme to prove I can do the job before I'm hired.
20 NIST 800-53 policies. PCI DSS v4.0. CBN & NDPA compliance. All on GitHub.
I'm a GRC Analyst based in Lagos
https://t.co/2qrHcZCJax
I built a fictional fintech's entire security programme to prove I can do the job before I'm hired.
20 NIST 800-53 policies. PCI DSS v4.0. CBN & NDPA compliance. All on GitHub.
I'm a GRC Analyst based in Lagos
https://t.co/2qrHcZCJax
@CyberRacheal@gabbytech01@HalimatAdepegba@Officialwhyte22@cyb3rshi3ld The Personnel Policy requires credit checks for anyone with settlement authority.
I also built:
→ A separate NIST RMF policy suite for a fictional enterprise
→ A full NIST RMF authorization package for a healthcare app
All publicly available on GitHub.
@CyberRacheal@gabbytech01@HalimatAdepegba@Officialwhyte22@cyb3rshi3ld This is where it gets specific.
Because "specific" is what separates a GRC analyst from someone who just read the NIST docs.
The Access Control Policy restricts ledger access to a named list of engineers.
The IR Policy has card network breach notification procedures baked in.
Nmap still hits different in 2026 🕵️♂️
Just ran this scan during my practice lab… and it reminded me why reconnaissance will never go out of style.
Quick breakdown of what I found:
Port 22 (SSH) → Open
Port 80 (HTTP) → Open (web app target)
Port 587 (Submission) → Open
Some unusual high ports (9929 & 31337) → Immediate red flags
In Cloud & Application Security Engineering, a good Nmap scan is usually my first real intelligence on any target.
It helps me answer critical questions like:
What’s actually exposed?
Where should I focus my web app testing?
Are there risky services running in this cloud environment?
Whether I’m hunting web vulnerabilities or assessing cloud attack surfaces, Nmap remains one of the most valuable tools in my kit.
Old tool. Timeless value.
#Nmap #Pentesting #AppSec #CloudSecurity