Hello, I’m Zuby Ani, a hands-on information security professional with 9+ years’ experience spanning GRC/compliance and day-to-day security operations. I build ISO 27001-aligned ISMS, support SOC 2 readiness, and assure PCI DSS/3DS controls while staying close to the technical work—vulnerability management, IAM, logging/alert triage, and incident support. I keep things practical: clear policies that teams can follow, audit-ready evidence, plain-English risk messaging, and remediation that actually lands. In my current role at DeBeers Group, I translate requirements into practical controls, foster ownership, and produce executive reports on compliance, risk, and security metrics. I enjoy turning gaps into measurable improvements, strengthening access governance, and embedding security into design and delivery across cloud, on-premises, and hybrid environments.…

Zuby Ani

Hello, I’m Zuby Ani, a hands-on information security professional with 9+ years’ experience spanning GRC/compliance and day-to-day security operations. I build ISO 27001-aligned ISMS, support SOC 2 readiness, and assure PCI DSS/3DS controls while staying close to the technical work—vulnerability management, IAM, logging/alert triage, and incident support. I keep things practical: clear policies that teams can follow, audit-ready evidence, plain-English risk messaging, and remediation that actually lands. In my current role at DeBeers Group, I translate requirements into practical controls, foster ownership, and produce executive reports on compliance, risk, and security metrics. I enjoy turning gaps into measurable improvements, strengthening access governance, and embedding security into design and delivery across cloud, on-premises, and hybrid environments.…

Available to hire

Hello, I’m Zuby Ani, a hands-on information security professional with 9+ years’ experience spanning GRC/compliance and day-to-day security operations. I build ISO 27001-aligned ISMS, support SOC 2 readiness, and assure PCI DSS/3DS controls while staying close to the technical work—vulnerability management, IAM, logging/alert triage, and incident support. I keep things practical: clear policies that teams can follow, audit-ready evidence, plain-English risk messaging, and remediation that actually lands.

In my current role at DeBeers Group, I translate requirements into practical controls, foster ownership, and produce executive reports on compliance, risk, and security metrics. I enjoy turning gaps into measurable improvements, strengthening access governance, and embedding security into design and delivery across cloud, on-premises, and hybrid environments.

See more

Experience Level

Expert
Expert
Expert
Intermediate
Intermediate
Intermediate
Intermediate
Intermediate
Intermediate
Intermediate
See more

Language

English
Fluent

Work Experience

Senior Information Security Consultant at DeBeers Group
April 1, 2023 - Present
Lead day-to-day ISMS activities aligned to ISO 27001 and NIST CSF, translating requirements into practical controls with clear ownership and audit-ready evidence. Built a repeatable security assessment approach for project lifecycle (infrastructure, cloud and applications). Performed risk assessments and control effectiveness reviews, documented risks in plain English with measurable treatment actions. Supported incident response by reviewing alerts/logs and coordinating post-incident actions. Led gap analyses and remediation planning, tracked actions to completion with defined evidence standards. Produced executive-ready reporting on compliance status, key security metrics (risk, vulnerabilities, access reviews, policy compliance) and programme milestones. Improved access governance and device compliance across macOS/Linux estates (JumpCloud).
Information Security Consultant at InstantON IT
February 1, 2019 - March 1, 2023
Supported ISO 27001, SOC 2 and PCI DSS compliance programmes end-to-end: evidence collection, audit preparation, auditor liaison, and remediation tracking until closure. Delivered risk-based control assessments (ToD/ToE) and design reviews with clear findings and actionable remediation for Engineering and Ops. Managed vulnerability management cycles using Qualys/Nessus: scheduled scans, validated findings, prioritised remediation, and KPI reporting. Triaged security alerts, coordinated investigations with IT/SecOps, and documented lessons learned for continuous improvement. Maintained risk registers and security metrics (patching, access reviews, awareness, vendor risk) to drive prioritised action and audit readiness. Implemented data protection controls using Microsoft Purview (DLP, labeling/classification).
Information Security Officer at NodeOne
April 1, 2016 - January 1, 2019
Supported the organisation’s security programme across governance and operations, aligning policies and controls to ISO 27001 and Cyber Essentials. Maintained security policies, standards and procedures; ran review cycles and supported teams to adopt them day-to-day. Conducted risk assessments, documented risks, agreed treatment plans, and tracked completion with owners. Supported audit readiness by organising evidence, validating control operation, and driving corrective actions. Monitored security logs/alerts and supported incident response, including post-incident reviews and improvements. Maintained BC/DR documentation and supported exercises; delivered role-based security awareness training.
Cloud Systems Engineer at Adare International, Dunton
July 1, 2015 - March 1, 2016
Supported cloud and hybrid infrastructure, collaborating with teams to embed security controls, monitoring, and best practices into design and operations.
Support Engineer at Ford, Dunton
April 1, 2014 - June 1, 2015
Provided IT support and security-related assistance for vehicle systems and enterprise IT, contributing to ongoing improvements in incident response and operational resilience.
Field IT Engineer at EmpoweredSMS
August 1, 2012 - March 1, 2014
Delivered field IT support, deployments and troubleshooting for client environments, contributing to security baseline enforcement and operational stability.

Education

MSc, Network and Information Security with Management Studies at Kingston University, London
January 1, 2012 - January 15, 2026
BEng, Electrical & Electronic Engineering at Covenant University, Ota
January 11, 2030 - June 1, 2008

Qualifications

ISO 27001 Certified Lead Auditor (IBITGQ)
January 11, 2030 - January 15, 2026
ISO 27001 Certified Lead Implementer (IBITGQ)
January 11, 2030 - January 15, 2026
Microsoft 365 Certified: Security Administrator Associate
January 11, 2030 - January 15, 2026
Microsoft 365 Identity and Services (MS-100)
January 11, 2030 - January 15, 2026
AWS Certified Solutions Architect – Associate
January 11, 2030 - January 15, 2026
Cisco Certified Network Associate (CCNA)
January 11, 2030 - January 15, 2026

Industry Experience

Professional Services, Software & Internet, Financial Services, Government, Other