Where my attention goes

Two things, mostly. The application security program at Cyberia, and GRC Core, the product I'm building for teams that operate under NCA and PDPL.

Current role

Cyberia · Feb 2016 to Present

Supervisor, Business Applications Security

Owning secure SDLC, design review, and remediation across the application estate; running the AppSec side of the NCA ECC and Saudi PDPL programs.

IN DEVELOPMENT

GRC Core

GRC Core is a multi-tenant governance, risk, and compliance platform designed for the shape of Saudi regulation. Controls, evidence, and audit workflows modeled directly against NCA ECC, CCC, and PDPL instead of retrofit from a generic global framework.

It targets the specific pain point I hit again and again: keeping a control library, an evidence trail, and an audit narrative in sync across engineering, security, and legal, without stitching together five spreadsheets and a shared drive.

The waitlist is for practitioners who want early access, want to shape the roadmap, or want to talk about pilot deployment.