About Me
Hey, I'm Nehaal — a Technology Risk and Cybersecurity Consultant based in Sydney, Australia. I spend my days helping organisations identify and manage cyber risks, and this blog is where I write about the things I find interesting along the way.
I'm currently working as a Technology Risk Associate at a consulting firm, where I work across API and IT audits, GRC initiatives, and penetration testing. My work is grounded in frameworks like SOC 2, ISO 27001, and NIST — but I'm always more interested in the practical side: what does good security actually look like for a real organisation, and how do you get there?
Before that, I spent over two years at another consultancy as a Technology and Transformation Consultant, focusing on enterprise HR technology platforms. That experience gave me a solid appreciation for how risk lives inside large, complex systems — and how easy it is to overlook.
On the education side, I hold a bachelor's degree in Digital Technologies and I'm currently finishing a master's in Cyber Security. I'm also an eLearnSecurity Junior Penetration Tester (eJPT).
Outside of work, I'm a cybersecurity nerd who enjoys going deeper on the technical side — especially anything to do with penetration testing and offensive security. This blog is my space to think out loud, share what I'm learning, and hopefully make cybersecurity a little less intimidating for anyone reading.