Abdullah Bin
Zarshaid
I am a hybrid cybersecurity leader: technical, compliance-driven, client-facing and business-aware. For a decade I have worked at the intersection of technical security, compliance, service delivery and business risk.
My work spans offensive security, AI and ML security, GRC, SOC leadership and incident response, delivered across international regulated industries including finance, healthcare, government, transport and technology.
I plan and oversee authorized security assessments across web, API, mobile, network and cloud, define scope and rules of engagement, validate findings, and turn them into executive and technical reports leadership can act on. On the governance side I lead ISO 27001, SOC 2, NIST and PCI DSS programs, risk registers, control mapping and audit preparation.
I also build teams. I have delivered security awareness and hands-on training to thousands of people, because most security fails when teams were never shown how attacks actually work.
A decade of measurable impact.
// what i bring
Depth across the whole stack
Offensive security
Manual-led penetration testing across web, API, mobile, network and cloud — mapped to OWASP WSTG, PTES and NIST SP 800-115.
Compliance & GRC
ISO 27001, SOC 2, PCI DSS and NIST CSF readiness — gap assessment, control mapping, evidence and audit coordination.
AI & LLM security
Testing AI-powered products against prompt injection, data leakage and excessive agency — the full OWASP LLM Top 10.
Security leadership
Virtual CISO advisory: risk registers, board reporting, security programme design and vendor assessments.
Incident response
Calm, evidenced handling when it matters — containment, scope assessment, and closure your board can act on.
Hands-on training
Security awareness and technical upskilling delivered to thousands — because teams defend best when they have seen the attack.
Why I work the way I do
Over a decade in cybersecurity, I saw the same pattern too often: organisations paying for "penetration tests" that were really just automated scans, delivered by juniors, wrapped in a long report nobody could act on. The findings were noise. The real risks stayed hidden.
ABZSECURE exists to be the opposite of that. When you engage me, you work directly with the person doing the testing — not a salesperson, not a rotating team of juniors. Every finding is proven with reproducible evidence. Every report is written to be used: one version your board can read, one your engineers can act on.
I hold CISSP and CEH certifications and an MSc in Computer Networks & Security. But credentials only matter if the work is real. That is why retests are included, evidence is always reproducible, and I would rather report five findings that matter than fifty that don't.
— Abdullah Bin Zarshaid, MSc, CEH