This browser is several versions out of date, so this page is showing without its styling. Updating iOS or your browser will restore it.

Jamil Ahmed

💼 Work

Professional experience, newest first.

Sr. IT/OT Cybersecurity Consultant – GRC, Risk & Assurance

🏢 Cyber Value Addition· 📍 Pakistan
CURRENT📅 Jan 2021 — Present
  • Leading OT/ICS cybersecurity governance, risk, and compliance initiatives across critical infrastructure environments, ensuring alignment with ISA/IEC 62443, NIST SP 800-82, NIST CSF 2.0, ISO 27001:2022, and regional regulatory frameworks.
  • Conducting risk-based OT cybersecurity assessments and audits across industrial networks, control systems, and supporting IT environments, covering OT security controls, policies, segmentation, access control, monitoring, and incident readiness.
  • Performing integrated OT/IT risk assessments aligned with IEC 62443 security levels, zone & conduit models, and enterprise risk management practices, identifying systemic gaps and defining practical remediation roadmaps.
  • Advising clients on OT cybersecurity compliance strategies, CSMS development, risk treatment plans, and policy frameworks, bridging engineering, operations, IT, and governance teams.
  • Evaluating OT/IT governance, infrastructure, applications, and IAM controls, including RBAC for OT environments, privileged access, and identity boundaries between IT and industrial networks.
  • Developing OT-specific SOPs, cybersecurity management procedures, and assurance artifacts; testing ITGCs and application controls where IT systems support OT operations.
  • Preparing executive-ready OT cybersecurity audit and assurance reports, translating technical findings into risk-based insights for leadership, regulators, and external auditors.
  • Leveraging prior cloud security and DevSecOps experience to support secure-by-design principles for industrial digitalization, OT-adjacent platforms, and enterprise integration layers.
ISA/IEC 62443NIST SP 800-82NIST CSF 2.0ISO/IEC 27001 Lead AuditorISO/IEC 27001 Lead ImplementorOT/ICS CybersecurityGRCCSMS DevelopmentIT AuditISMS ImplementationIT Governance FrameworksRisk Assessment & ManagementNCA ComplianceAramco Cybersecurity StandardsZone & Conduit Model (IEC 62443)Security Level (SL) AssessmentPurdue Model / ISA-95OT Network SegmentationProcess Control Domain (PCD) SecurityHMI / SCADA HardeningOT Asset Inventory & Lifecycle ManagementICS Patch ManagementSCADA / PLC / DCS ProtocolsGap AnalysisRegulatory ReadinessExecutive / Board-Level ReportingISO/IEC 42001 (AI Governance)Incident ResponseIAM & RBACPrivileged AccessAudit DocumentationCompliance ReportingAudit PlanningITGC Testing

DevSecOps Engineer

🏢 Prepared Development· 📍 Pakistan
📅 Dec 2018 — Jan 2021
  • Linux server installation, administration, hardening, performance tuning, and patching.
  • Managed AWS resources and worked on IaC tools including Terraform, Ansible, and CloudFormation.
  • Designed, implemented, and maintained AWS cloud solutions to meet client requirements.
  • Built and maintained CI/CD pipelines to automate the deployment process and improve release management via Jenkins.
  • Optimised Kubernetes infrastructure for application deployment; scaled and managed containerised applications on Kubernetes clusters.
  • Maintained infrastructure as code scripts for provisioning and configuration management.
  • Applied security best practices to safeguard applications and data across cloud infrastructure.
Amazon Web Services (AWS)Google Cloud Platform (GCP)AWS Cloud Solutions ArchitectTerraformAnsibleCloudFormationKubernetesDockerJenkinsGitHub ActionsLinux AdministrationDevSecOpsCI/CD PipelinesInfrastructure as Code (IaC)Cloud SecurityProcess AutomationRelease Management

Cloud Security Engineer | Secure Application Development

🏢 Fairytalez.com· 📍 Copenhagen, Denmark
📅 Jul 2017 — Dec 2018
  • Architected and deployed security-hardened AWS infrastructure (EC2, VPC, S3, CloudFront, Lambda) with CIS benchmarks alignment.
  • Led end-to-end development and cloud deployment of the world's largest online fairy tale library, managing codebase, performance, and scalability for global traffic.
  • Built and automated CI/CD pipelines using Jenkins & GitHub Actions enabling zero-downtime deployments and rapid release cycles.
  • Implemented IAM policies, security groups, and network segmentation for multi-tier cloud applications.
  • Established CI/CD security gates via Jenkins/GitHub Actions, ensuring automated vulnerability scanning pre-deployment.
  • Designed monitoring and audit logging (CloudTrail, CloudWatch) to support security incident response and compliance evidence.
  • Secured cloud-native platform serving a global user base with 99.9% uptime, automated threat detection, and zero critical security incidents.
Amazon Web Services (AWS)EC2VPCS3CloudFrontLambdaIAM & RBACCIS BenchmarksJenkinsGitHub ActionsCloudTrailCloudWatchCloud SecurityApplication SecurityCI/CD PipelinesVulnerability RemediationWordPressPHP

Application Security & Platform Engineer | Secure Web Architecture

🏢 Weider Media· 📍 Copenhagen, Denmark
📅 Dec 2014 — Jun 2017
  • Engineered secure custom web applications and CMS platforms, implementing input validation, authentication controls, and secure API integrations.
  • Conducted security-focused code reviews and vulnerability remediation in PHP/JavaScript environments.
  • Managed secure site migrations and infrastructure hardening, reducing attack surface and improving resilience.
  • Implemented SEO and performance optimisation with security considerations (HTTPS, secure headers, access controls).
  • Integrated security checkpoints into development lifecycle, ensuring consistent hardening standards across all deliverables.
PHPJavaScriptApplication SecuritySecure Web ArchitectureCode ReviewVulnerability RemediationWordPressCMSInfrastructure HardeningHTTPSSecure HeadersFront-End DevelopmentSEO

Project Manager

🏢 Prepared Development· 📍 Lahore, Pakistan
📅 May 2012 — Oct 2014
  • Led secure delivery of 20+ web platforms for US, European, and Australian clients across diverse industry verticals.
  • Functioned as client-facing technical advisor on security-conscious platform decisions and web architecture.
  • Managed distributed development teams executing projects with embedded security and quality standards.
  • Built long-term client partnerships through transparent communication, risk mitigation, and consistent delivery excellence.
  • Established foundational delivery methodologies and security practices adopted in subsequent organisational growth.
Project ManagementWeb ArchitectureClient RelationsTeam LeadershipRisk MitigationStakeholder ManagementWordPressGCP

Research Associate

🏢 Sheikh Zayed Medical College and Hospital· 📍 Rahim Yar Khan, Pakistan
📅 May 2011 — Mar 2012

Managed editorial and research operations for a peer-reviewed medical journal, ensuring rigorous documentation standards and compliance with publication ethics. Led data analysis and technical reporting for research initiatives, while coordinating proposal development and stakeholder submissions.

ResearchData AnalysisTechnical ReportingReport WritingDocumentationPublication Ethics

Program Coordinator

🏢 Value Resources Pvt Ltd· 📍 Islamabad, Pakistan
📅 Jun 2010 — Apr 2011

Coordinated multi-phase development programs, managing documentation, stakeholder reporting, and proposal development (RFPs). Built early capabilities in project governance, data management, and cross-functional communication.

Project PlanningRFPStakeholder ManagementDocumentationProgram Coordination

Customer Service Officer

🏢 Ufone 5G· 📍 Rahim Yar Khan, Pakistan
📅 Sep 2005 — Dec 2008

Managed customer-facing operations for telecom services, handling account provisioning and technical support via web-based systems. Developed foundational skills in process adherence, data handling, and service delivery in a regulated technology environment.

Customer ServiceTelecomTechnical SupportAccount Provisioning