Skip to content
View NajmaGRC's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report NajmaGRC

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
NajmaGRC/README.md

Najma Abdi Omar | ICT Business Analyst & GRC Professional

I find where systems, risk and reality don't match — and fix it.

7+ years in banking technology and regulated environments. This portfolio documents 9 months of intensive, skills-based GRC training — from foundational frameworks to a live AWS cloud deployment.


☁️ AWS Integrated GRC Platform  ⭐ Flagship

Designed, deployed and governed a live enterprise-grade GRC platform on AWS. CloudFormation, Lambda, RDS, DynamoDB, CloudTrail, KMS. 22/22 automated tests passed. 49 compliance reports generated.

View Project →


🚨 Incident Response Portfolio

End-to-end IR programme — policy, response plan, CSIRT structure, live ransomware simulation, stakeholder communications, after-action review and improvement plan.

View Project →


✅ Compliance Frameworks & Breach Analysis

Comparative breach analysis (Worldcoin Kenya vs MGM Resorts), compliance crisis management under AML + PCI DSS violations, and institutional security policy development.

View Project →


⚠️ Risk Assessment Labs

Quantitative risk analysis (ALE/SLE/ARO), phishing simulation metrics, live Wazuh SIEM deployment, small business risk assessment and M365 project risk register.

View Project →


🏛️ GRC Governance Portfolio

GRC framework design, multi-jurisdictional regulatory mapping, CISO leadership analysis, SIEM log analysis and security integration into healthcare business processes.

View Project →


🌐 Connect

LinkedIn: Najma Abdi Omar


Multilingual: English · Swahili · Somali · Turkish · Arabic

Pinned Loading

  1. Incident-Response-Portfolio Incident-Response-Portfolio Public

    End-to-end incident response programme — IR policy, response plan, CSIRT structure, ransomware simulation, stakeholder communications, AAR and improvement plan.

  2. Compliance-Frameworks Compliance-Frameworks Public

    Compliance programme design, breach analysis across two jurisdictions, and security policy development — Kenya DPA, GDPR, PCI DSS, AML.

  3. GRC-Governance GRC-Governance Public

    GRC Governance Portfolio

  4. Risk-Assessment-Labs Risk-Assessment-Labs Public

    Risk Assessment & Management Labs