Glory Okonofua

Information Security / GRC / AI Governance

Glory Okonofua

My work focuses on making security governance, audit readiness, privacy, and responsible AI easier to understand, document, and defend.

Lisbon, PortugalISO 27001 / 27701 / 42001 / SOC 2 / DORA

Focus

Information Security Governance

Experience

4+ years experience

Current work

Defined.ai

Frameworks

ISO 27001 / 27701 / 42001, SOC 2

Practical security governanceClear audit evidencePrivacy and AI governance that line upDocumentation people can useRisk registers and control mappingControl ownership across teamsPractical security governanceClear audit evidencePrivacy and AI governance that line upDocumentation people can useRisk registers and control mappingControl ownership across teams

Profile

I care about trust that can be explained.

This site is here to make the practical parts of my work easy to understand: the frameworks I work with, the evidence I care about, and how I think about keeping governance usable inside real teams.

I work across information security, governance, risk, and compliance, with a focus on ISO management systems, SOC 2 controls, privacy, and strategic IT management.

I am especially interested in work where security, privacy, and responsible AI need to be clear enough for real teams, real reviews, and real decisions.

Practical security governance
Clear audit evidence
Privacy and AI governance that line up
Documentation people can use
Risk registers and control mapping
Control ownership across teams

Experience

My recent full-time roles.

A shorter view of the work covered in my CV, focused on the security, GRC, risk, and compliance responsibilities that have shaped my career so far.

June 2025 - Present

Information Security Specialist - GRC

Defined.ai

GRCVendor riskDORABusiness continuity

My current role sits across GRC program management, audit support, vendor risk, and risk ownership.

  • Manage GRC work across ISO 27001, ISO 27701, SOC 2, and DORA, including audit support and core documentation.
  • Lead vendor risk assessments and review third-party evidence across ISO/SOC reports, IAM, backups, encryption, and endpoint protection.
  • Maintain the enterprise risk register, support risk assessments, and work with risk owners on treatment actions.
  • Review new tools and vendors for data handling, architecture, and compliance risks.
  • Support business continuity and crisis communication documentation, including activation workflows and escalation processes.
  • Collaborate with Engineering, Legal, People, and Ops teams to strengthen controls and compliance across the organization.

May 2022 - May 2025

IT Specialist

Strolid

IT securityRisk assessmentsAccess controlsSecurity awareness

This role built the foundation for my security and compliance work across policies, audits, incidents, and IT controls.

  • Implemented and maintained IT security policies across ISO 27001, PCI DSS, NIST, GDPR, and related requirements.
  • Conducted risk assessments, managed IT risk registers, and supported audits.
  • Monitored security incidents, assessed vulnerabilities, and supported compliance activities.
  • Worked with IT security tools, access controls, and business continuity planning.
  • Collaborated with stakeholders on security awareness and vendor compliance.

What I Work On

The areas I keep building experience in.

01

GRC Program Support

My work includes policies, control mapping, risk registers, audit evidence, and ownership models that teams can maintain.

02

ISO Management Systems

I support ISO 27001, ISO 27701, and ISO 42001 work across information security, privacy, and AI management.

03

SOC 2 Readiness

I organize evidence, map trust services criteria, support customer and vendor responses, and work with control owners.

04

AI Governance

I work on responsible AI governance with attention to data handling, transparency, and regulatory expectations.

How I Work

From unclear requirements to evidence people can stand behind.

I start by understanding the current setup, then connect the requirements to practical controls, evidence, and reporting that people can actually use.

01

Understand the setup

I start by getting clear on scope, owners, business context, evidence gaps, and the risks that need attention.

02

Map what matters

I connect ISO, SOC 2, privacy, and AI governance requirements to the work teams already do.

03

Get the evidence in order

I work on documentation, review routines, exception handling, and evidence libraries that are easy to use.

04

Keep improving

I turn findings into clear reporting, remediation plans, and habits that improve the program over time.

Framework

ISO 27001

Information security management

Risk treatment, controls, policies, internal audit, management review

ISO 27701

Privacy information management

PII processing, privacy controls, roles, retention, supplier handling

ISO 42001

AI management system governance

AI risk checkpoints, accountability, transparency, lifecycle documentation

SOC 2

Trust services control readiness

Control narratives, owner evidence, exception tracking, audit response

Work Themes

The work I keep coming back to.

View my CV

Keeping audit evidence usable

I work on control performance, ownership, exceptions, and review cadence without turning evidence into busywork.

  • Control narratives
  • Evidence libraries
  • Audit responses

Connecting privacy and security

I bring privacy expectations into security control work so policies, assessments, and procedures support each other.

  • PII controls
  • Risk documentation
  • Clear reporting

Making AI governance practical

I support AI governance with controls for accountability, data provenance, risk review, and management documentation.

  • ISO 42001 alignment
  • AI risk reviews
  • Governance documents

Frameworks and background

ISO 27001ISO 27701ISO 42001SOC 2DORAPCI DSSNISTGDPRInformation SecurityPrivacyAI GovernanceVendor RiskBusiness ContinuityRisk ManagementMSc Information Systems Management

CV

You can read my CV here.

It gives a fuller view of my experience, education, and the security and governance work I have been building.

CV preview

Glory Okonofua CV.pdf

PDF

Contact

For professional conversations, this is the easiest way to reach me.