Portfolio Demo

Enterprise GRC & SIEM Architecture

A comprehensive demonstration of Security Architecture, GRC Implementation, and Secure Software Development capabilities.

Designed and Built by Dotun Arowolo.

Meet the Architect

Cybersecurity Leader & GRC Expert

DA

DOTUN AROWOLO

Cybersecurity Leader

CORE COMPETENCIES
Security Architecture Zero Trust Cloud Security Secure SDLC
GRC Frameworks ISO 27001 NIST CSF PCI-DSS SOC 2
Cloud Platforms Google Cloud AWS Azure
DevSecOps Python PHP SQL CI/CD
PROFESSIONAL SUMMARY

Highly accomplished and results-oriented Cybersecurity Leader with over 12 years of progressive experience in architecting, implementing, and managing comprehensive security programs. Proven expertise in GRC, Cloud Security, Threat & Vulnerability Management, and Incident Response. Strategic thinker dedicated to aligning cybersecurity initiatives with business objectives.

EXPERIENCE HIGHLIGHTS
Loblaw Inc.
2024 – Present

Senior Specialist, Cyber Security and Technology Risk

Leading cyber risk dashboards, project risk assessments, and global policy enforcement.

Thentia Corporation
2023 – 2024

Senior Information Security Analyst

Managed Google Cloud security posture and implemented SAST/DAST processes.

BCT Limited
2020 – 2022

EMEA Senior IT Security Manager

Spearheaded "Security as a Service" and enhanced AWS/Azure cloud security.

Architectural Capabilities

Advanced Security Engineering

This demo application is built to showcase advanced engineering capabilities in AI integration, offensive security, and GRC automation.

AI-Powered Ecosystem

Leveraging Google Gemini and Ollama local LLMs to drive intelligent decision making across the platform.

  • Automated Architecture Diagrams: Generates MermaidJS network charts from text descriptions.
  • Smart Risk Assessment: AI analyzes vulnerability data to predict likelihood and impact scores.
  • Policy Generation: Drafts comprehensive GRC policies tailored to specific frameworks.
Google Gemini Ollama RAG Architecture

Autonomous Offensive Security

A fully integrated AutoPentest module capable of conducting autonomous reconnaissance and vulnerability scanning.

  • AI Payload Optimization: Dynamically adjusts attack payloads based on WAF responses.
  • Smart Reconnaissance: Automated subdomain enumeration and service fingerprinting.
  • Chain-of-Thought Attack planning: AI plans multi-step attack vectors.
Python Scanners Payload Mutation Automated Reporting

Unified GRC & Operations

Bridging the gap between Compliance (Governance) and Security Operations (Execution) in a single pane of glass.

  • Dynamic Org Tree: Visual hierarchy of all organization assets, risks, and controls.
  • SIEM Integration: Real-time log monitoring linked directly to compliance controls.
  • Multi-Framework Mapping: Cross-map controls between ISO 27001, SOC 2, and NIST CSF.
ISO 27001 SOC 2 SIEM/SOAR

Implemented Modules

A full suite of functional modules developed for this demo.

Vendor Mgmt
Vuln Mgmt
SIEM
Compliance
Asset Mgmt
Incident Resp
BCDR
Policy Mgmt