whoami

Results-driven Cybersecurity Engineer with 10+ years of enterprise experience across threat detection, incident response, identity & access management, and cloud security governance. Proven record securing hybrid environments (AWS, Azure, GCP) for 200+ enterprise customers and 6,000+ users, achieving ISO 27001 certification and sustaining 99.999% availability. Skilled in vulnerability assessment, security architecture design, PKI, privileged access governance, and authentication protocol implementation. Adept at translating complex risk landscapes into actionable security strategies and driving continuous improvement through ITIL-aligned processes, scripting automation, and cross-functional stakeholder engagement.

Reuben Comla
CompTIA Security+
SEC+
EC-Council Certified Security Specialist
ECSS
Microsoft Certified: Solutions Associate - Windows Server 2016
MCSA
Darktrace Academy Threat Visualizer Certified
DARKTRACE
Microsoft Certified: Identity and Access Administrator Associate
SC-300
Microsoft 365 Certified Security Administrator Associate
MS-500
Aviatrix Certified Engineer (ACE)
AVIATRIX ACE
LOGO
CISA
LOGO
CISM
LOGO
CISSP
cat about.md

About

Tools

Skills

ls competencies/

Core Competencies

DETECTION & RESPONSE
  • Threat detection & incident response
  • Vulnerability assessment & pen testing
  • SIEM & endpoint protection
  • Threat hunting (APTs, lateral movement)
IDENTITY & ACCESS
  • IAM, PKI, MFA
  • SAML, OAuth 2.0, OIDC, LDAP, Kerberos
  • RBAC, ADFS, privileged access governance
  • Zero Trust architecture
CLOUD & NETWORK
  • AWS, Azure, GCP
  • Network security & firewalls
  • VPN & segmentation policy
  • TLS/certificate lifecycle management
COMPLIANCE & RISK
  • ISO 27001, NIST CSF, SOC 2
  • HIPAA, PCI DSS, PIPEDA
  • Risk management & audit documentation
  • Compliance strategy & reporting
AUTOMATION
  • PowerShell, Python, Bash scripting
  • Security workflow automation
  • LLM-integrated tooling
  • Identity governance automation
LEADERSHIP
  • Training & stakeholder communication
  • Cross-functional team leadership
  • ITIL-aligned process design
  • Executive-level reporting
tail -f experience.log

Professional Experience

MAY 2023 TO PRESENT

Cybersecurity Engineer

Tompkins Canada, Toronto, ON
  • Design and enforce Zero Trust security policies across hybrid cloud (AWS/Azure) and on-premises infrastructure.
  • Lead threat hunting and proactive monitoring using SIEM tools to detect APTs and anomalous behaviour enterprise-wide.
  • Architect and maintain PKI infrastructure and TLS certificate lifecycle management, eliminating certificate-related outages.
  • Collaborate with compliance and legal teams on ISO 27001, NIST CSF, SOC 2, and PIPEDA alignment; prepare audit evidence.
  • Automate identity governance and compliance workflows with PowerShell and Python, cutting manual effort significantly.
SEP 2024 TO DEC 2025

Lead Graduate Teaching Assistant, Cybersecurity Audit & Compliance

Northeastern University, Boston, USA
  • Delivered graduate-level instruction on Identity and Access Management (IAM) design, ISO 27001, NIST 800-53, HIPAA, SOC 2, and PIPEDA for enterprise and IoT contexts.
  • Led lecture sessions and lab walkthroughs translating regulatory frameworks (HIPAA, SOC 2, PIPEDA) into practical, auditable control sets students could apply to real-world case studies.
  • Developed supplementary teaching materials, including slide decks, control mapping worksheets, and audit checklists, to reinforce lecture content and give students hands-on frameworks for compliance analysis.
  • Facilitated discussion sections breaking down complex regulatory language (e.g., NIST 800-53 control families, ISO 27001 Annex A) into digestible, actionable guidance for students without prior compliance backgrounds.
  • Guest-lectured or co-taught modules on IoT security architecture, bridging traditional enterprise compliance frameworks with emerging IoT-specific risk models.
JAN 2024 TO JUN 2025

Cyber Security Analyst (Consultant)

World Wireless Solutions Inc., Toronto, ON
  • Conducted security assessments, including IAM reviews, network vulnerability analysis, and threat modelling, delivering actionable remediation plans.
  • Performed vulnerability scans across client network infrastructure, prioritizing findings by exploitability and business impact to guide remediation sequencing.
  • Ran threat modelling exercises against client architectures, identifying attack paths and mapping them to mitigating controls before deployment or major changes.
  • Reviewed identity and access management configurations for client environments, flagging excessive permissions, orphaned accounts, and misaligned role assignments.
  • Implemented RBAC and least-privilege monitoring controls; produced incident reports and executive compliance summaries.
  • Designed role-based access structures tailored to client organizational hierarchies, reducing unnecessary standing privileges across systems.
  • Configured monitoring and alerting for access anomalies, enabling faster detection of policy violations or suspicious account activity.
  • Authored incident reports translating technical findings into business-relevant language for executive stakeholders, supporting informed risk decisions.
  • Built LLM-integrated automation tools in Python/PowerShell, reducing manual reporting effort by ~40%.
MAY 2023 TO MAY 2024

Systems Administrator (Volunteer)

Society for the Living Food Bank, Toronto, ON
  • Managed end-to-end user lifecycle administration and operational reporting in compliance with data protection standards.
  • Provisioned, modified, and deprovisioned volunteer and staff accounts across internal systems, ensuring access aligned with role changes and organizational turnover.
  • Enforced least-privilege access principles across shared systems, periodically auditing user permissions to prevent unnecessary access accumulation.
  • Reviewed and remediated database anomalies to maintain data integrity across donor, inventory, and volunteer records.
  • Performed routine data validation checks, identifying duplicate entries, formatting inconsistencies, and orphaned records, then corrected them to preserve reporting accuracy.
AUG 2020 TO MAY 2023

Head, IT Data Architecture & Security

National Food Buffer Stock Company Ltd, Accra, Ghana
  • Directed the organization's ISO 27001 compliance program, setting strategic priorities that brought 500+ endpoints and IAM policy for 300+ users into alignment with certification requirements.
  • Owned accountability for compliance outcomes at the executive level, overseeing gap remediation planning and audit readiness rather than day-to-day control implementation.
  • Established governance structures, including policy approval chains, access review cadences, and audit reporting lines, that gave leadership ongoing visibility into the organization's compliance posture.
  • Set the organization's overall security strategy, driving a 75% reduction in security incidents while sustaining 99.9% uptime over 3 years.
  • Defined risk tolerance and investment priorities for the security function, balancing hardening initiatives against operational continuity commitments to the business.
  • Reported security posture and incident trends to senior leadership, translating technical risk into business impact to inform organizational decision-making.
  • Built and led the organization's IT security function from the ground up, establishing it as a formal capability where none previously existed.
  • Set direction for identity governance and network security policy (firewall, VPN, segmentation) across critical infrastructure, delegating execution while retaining strategic accountability.
JAN 2014 TO JUN 2020

Senior Network Security Manager, Field Operations

Ghana Community Network Services Ltd (GCNet), Accra, Ghana
  • Led a team of 12 engineers managing IAM and access governance for LAN/WAN/MAN infrastructure serving 200+ enterprise customers.
  • Mentored engineers on access governance best practices, security incident triage, and network hardening techniques, building a more security-conscious field operations team over time.
  • Coordinated cross-functional collaboration between network operations, security, and customer-facing teams to align infrastructure changes with security requirements.
  • Established access review cadences and approval workflows for IAM changes across the 200+ enterprise customer base, reducing unauthorized or stale access.
  • Sustained 99.999% uptime over 6 years applying ITIL-aligned incident, change, and problem management.
  • Ran structured incident response processes under ITIL frameworks, minimizing service disruption windows and maintaining consistent post-incident review cycles.
  • Managed change control procedures for network infrastructure updates, balancing the need for security patching against uptime commitments to enterprise customers.
  • Conducted root cause analysis on recurring network issues, feeding findings back into problem management processes to prevent repeat outages.
  • Designed Zero Trust network architecture, cutting incident response time by 70% and security incidents by 80%.
  • Segmented network zones and enforced micro-segmentation policies as part of the Zero Trust rollout, limiting lateral movement in the event of a compromise.
  • Implemented continuous verification and least-privilege access enforcement across LAN/WAN/MAN infrastructure, replacing legacy perimeter-based trust assumptions.
ls projects/

Key Projects

TalonsPT
Founder & Platform Architect · Independent Venture

A security tooling platform for vulnerability assessment, penetration testing, and attack simulation. I single-handedly designed and built TalonsPT to unify vulnerability assessment, CVE intelligence, penetration testing workflows, and red team/blue team simulation in one place. Its scanning and detection engine consolidates vulnerability findings and CVE data into actionable, prioritised results for remediation, while the red/blue team simulation tooling validates how controls and detections hold up against realistic attack scenarios. I also led its competitive positioning against established vulnerability assessment tools.

Wishscroll gesture-controlled scrolling app screenshot
Wishscroll
Northeastern University · Jan 2026 to Apr 2026

A gesture-accessible curation platform originally conceived for hospital patients and seniors aged 55+, evolved into a broader-audience tool for distraction-free, positive content. Hands-free gesture control is powered by TensorFlow.js, letting users navigate content without a mouse, keyboard, or touchscreen.

Smart Home Security System Ubidots IoT dashboard
Smart Security & HVAC System
Northeastern University · Sep 2025 to Dec 2025

An integrated IoT system combining a Python-based Central Device Application and a Java Gateway Device Application, collecting sensor data from emulated Raspberry Pi Sense HAT devices and managing adaptive HVAC control with intelligent thresholds, synchronized in real time through the Ubidots cloud platform.

GCNet ecosystem diagram showing banking and stakeholder integrations
Banking System Integration
GCNet · Jun 2016 to Dec 2020

GCNet (Ghana Community Network Services Limited) is a public-private partnership that modernized Ghana's economy by digitizing and automating trade, customs processing, and revenue mobilization. It developed the country's first Single Window Platform, linking government agencies, logistics providers, and traders to eliminate inefficient, paper-based protocols. I was part of the team that integrated banking systems and connected remote offices to the network nationwide, implementing multi-factor authentication, identity and access management, and PowerShell automation that cut deployment time from two weeks to two days, with zero security breaches sustained across six years of operation.

MPS project
MPS Project
Jan 2016 to Jun 2020

The MPS Tema Port Expansion Project is a major maritime infrastructure initiative in Ghana, centered on developing Terminal 3 of Tema Port into a leading West African transshipment hub. Operated by Meridian Port Services Ltd (MPS), the project was commissioned in late 2025 following massive land reclamation. I was part of the team that deployed and configured radio links, internet connections, and security infrastructure, and integrated MPS systems with GCNet systems as well as approved banks for revenue mobilization.

SGS / GCNet ISO 27001
SGS / GCNet ISO 27001
Jan 2015 to Jan 2016

SGS (formerly Société Générale de Surveillance) is a Swiss multinational headquartered in Geneva and the world's leading testing, inspection, and certification organization, operating a global network of over 2,500 laboratories to verify that products, materials, and processes meet international health, safety, and regulatory standards. I was part of the team that helped GCNet attain ISO 27001 certification, deploying endpoints nationwide, installing and configuring Active Directory, connecting all nodes to HQ, and closing out compliance gaps identified against the standard. My work included rolling out software patches, deploying Desktop Central across all nodes for centralized endpoint management, implementing VPNs for secure remote access, and auditing VSAT, E1, and radio connections to ensure the network met the availability and security controls required for certification.

verify --credentials

Education & Certification

MSc, Cyber-Physical Systems
Northeastern University, Toronto, Canada
SEP 2024 TO APR 2026
Cyber Security Specialist Diploma
Toronto School of Management, Canada
MAY 2023 TO JUL 2024
BSc, Information Technology
University of Cape Coast, Ghana
AUG 2005 TO JUL 2009
  • CompTIA Security+
  • EC-Council Certified Security Specialist (ECSS)
  • Darktrace Certified (Threat Visualizer)
  • Microsoft 365 Security Administration
  • Microsoft Certified Solutions Associate (MCSA)
  • Microsoft Certified: Identity and Access Administrator (SC-300)
  • Aviatrix Certified Engineer
Graduation photo
honors --list

Awards

CTF Ethical Hacking Competition
Winner: CTF Ethical Hacking Competition
Toronto, Canada · 2024

Placed first in a live capture-the-flag competition testing offensive security skills across web exploitation, network penetration, and cryptography challenges. Competed against peer security professionals under time pressure, applying tools like Burp Suite, Nmap, and Metasploit to identify and exploit vulnerabilities in simulated enterprise environments.

Academic Excellence Award
Academic Excellence Award
Toronto School of Management · 2024

Recognized for top academic performance in the Cyber Security Specialist Diploma program, reflecting consistent achievement across coursework covering threat detection, security architecture, compliance frameworks, and applied incident response.