Ayoub Fandi

Ayoub Fandi Email and Phone Number

Security Assurance Automation Team Lead @ GitLab
London, England, GB
Ayoub Fandi's Location
London Area, United Kingdom, United Kingdom, United Kingdom
Ayoub Fandi's Contact Details

Ayoub Fandi personal email

About Ayoub Fandi

I explore how leading organisations are transforming GRC from a cost center into a strategic product through automation, continuous monitoring, and engineering-driven approaches.๐ŸŽ™๏ธ The GRC Engineering Podcast features conversations with technical leaders who are redesigning compliance programs at scale. We dive deep into architecture decisions, automation strategies, and the future of security assurance.๐Ÿ“ฌ The GRC Engineer newsletter delivers spreadsheet-free insights to hundreds of security and compliance leaders weekly. From replacing screenshots with APIs to building version-controlled governance, we cover what's actually working in modern GRC programs.Featured regularly on:- Building control frameworks as code- Continuous compliance monitoring architecture- AI's impact on evidence collection- Future of security assurance- GRC automation at scaleJoin hundreds of GRC and security leaders getting fresh perspectives on modernising GRC:๐Ÿ”— Newsletter: grcengineer.com๐ŸŽง Podcast: https://creators.spotify.com/pod/show/grcengineering/The views expressed on my LinkedIn profile do not represent my current nor previous employers.

Ayoub Fandi's Current Company Details
GitLab

Gitlab

View
Security Assurance Automation Team Lead
London, England, GB
Website:
gitlab.com
Employees:
3174
Ayoub Fandi Work Experience Details
  • Gitlab
    Security Assurance Automation Team Lead
    Gitlab
    London, England, Gb
  • Gitlab
    Staff Security Assurance Engineer, Field Security
    Gitlab Jul 2023 - Present
    San Francisco, California, Us
  • Gitlab
    Senior Security Assurance Engineer, Field Security
    Gitlab May 2022 - Jul 2023
    San Francisco, California, Us
  • Grc Engineering Podcast
    Podcast Host
    Grc Engineering Podcast Nov 2023 - Present
    London, Gb
    Championing a revolution in GRC!
  • Linkedin
    Linkedin Learning Instructor
    Linkedin Oct 2022 - Present
    Sunnyvale, Ca, Us
  • Salesforce
    Security Grc Senior Analyst
    Salesforce Sep 2021 - May 2022
    San Francisco, California, Us
    - Completed a security compliance certification cycle from scratch that was started over 18 months prior in only 2 months, enabling over 20 million in revenue- Obtained the TISAX certification for 3 locations, 3 products in only 2 months, gathering over 350 pieces of evidence internally- Managed expectations and did regular status updates with Senior VPs and above (up to regional CEO) during the first phase of the program- Created an internal site hosting weekly status reports for the EMEA-wide GRC team- Drove the project from both an operational perspective and from a management perspective- Created a Slack-driven workflow for the audit to manage the relationship with auditors and evidence analysis- Built a relationship with the program manager of the TISAX certification body- Delivered the project on time, on budget and kept every business stakeholders informed with the adequate level of depth on a need-to-know basis
  • Immersive Labs
    Information Security Risk & Compliance Analyst
    Immersive Labs Oct 2020 - Sep 2021
    Bristol, England, Gb
    - Managed incoming requests from Sales team, including answering security questionnaires and engaging with customer supplier assurance audits- Led the Security Awareness Program, delivering sessions and writing internal and external security communications- Uplifted the ISMS program and successfully underwent the full ISO 27001 audit- Handled our IT risk management process and conduct regular risk interviews with internal stakeholders- Maintained Cyber Essentials and achieving the Cyber Essentials Plus certifications- Leveraged internal security expertise to improve our own security posture and processes- Participated in the Security Vulnerability Management process with Application Security Lead, Penetration Testers and Software Engineers using CVSS- Led a monthly Security Governance meeting for Engineering, Infrastructure, QA, IT Support, Product Managers and Development
  • Ey
    Information Security Consultant
    Ey Sep 2019 - Oct 2020
    London, Gb
    ๐’๐ญ๐š๐ญ๐ž-๐จ๐ฐ๐ง๐ž๐ ๐‚๐จ๐ฆ๐ฉ๐š๐ง๐ฒ:- Built Security Dashboards for the CISO of a 60,000-employee company with 20 KPIs and assessed its security posture- Crafted 4 detailed risk scenarios based on Qualys vulnerability extracts using ISO 27005's risk assessment framework- Designed an information security roadmap for 2020 based on the dashboard KPIs with 6 axes- Produced a strategy for NIS Regulations compliance in 2021 spanning over 23 domains and 137 key controls๐€๐Ÿ๐ซ๐ข๐œ๐š๐ง ๐Ž๐ข๐ฅ & ๐†๐š๐ฌ ๐‚๐จ๐ฆ๐ฉ๐š๐ง๐ฒ:- Drafted a Data Classification Policy for a 20,000-employee company accounting for its risk appetite and GDPR compliance- Built a Cloud Eligibility tool prompting Product Owners to perform a CIA and data privacy impact assessment and outputting Public Cloud storage eligibility๐…๐ซ๐ž๐ง๐œ๐ก ๐†๐ฅ๐จ๐›๐š๐ฅ ๐‘๐ž๐ญ๐š๐ข๐ฅ ๐†๐ซ๐จ๐ฎ๐ฉ:- Performed a GDPR maturity assessment for a 220,000-employee retail company; analyzed over 30 documents and conducted 4 workshops๐„๐˜:- Managed 2 interns when building the Cyber Threat Intelligence capability, proofread and reviewed their work- Released 20 weekly threat reports sent to the CISOs of 3 companies in the Oil & Gas, Construction, and FMCG sectors
  • Devoteam
    Information Security Consultant
    Devoteam Oct 2018 - Sep 2019
    Levallois-Perret, Fr
    - Auditing the Information Security Systems Policies using the ISO 27002's 114 controls.- Completed the first translation of their information security policies in English- Worked on an internal awareness cybersecurity questionnaire directed to fellow consultants in other service lines

Ayoub Fandi Skills

Anglais Professionnel Leadership Organisationnel Amazon Web Services Gestion Des Risques Cybersecurity It Risk Management Microsoft Powerpoint Parler En Public Communication Agile Methodologies Cyber Risk Management Cyber Security Risk Google Cloud Platform Microsoft Office Microsoft Word It Security Assessments It Operations Microsoft Excel Security Awareness Information Security Management Security Audits Iso 27001 Gestion Des Talents Strategic Consulting Rgpd Cloud Computing Anglais

Ayoub Fandi Education Details

  • Ecole De Guerre Economique โ€“ Ege
    Ecole De Guerre Economique โ€“ Ege
    International Safety And Cybersecurity
  • Universitรฉ Paris Nanterre
    Universitรฉ Paris Nanterre
    Linguistics
  • Universitรฉ Paris Nanterre
    Universitรฉ Paris Nanterre
    Economics/Management

Frequently Asked Questions about Ayoub Fandi

What company does Ayoub Fandi work for?

Ayoub Fandi works for Gitlab

What is Ayoub Fandi's role at the current company?

Ayoub Fandi's current role is Security Assurance Automation Team Lead.

What is Ayoub Fandi's email address?

Ayoub Fandi's email address is ay****@****ail.com

What schools did Ayoub Fandi attend?

Ayoub Fandi attended Ecole De Guerre Economique โ€“ Ege, Universitรฉ Paris Nanterre, Universitรฉ Paris Nanterre.

What skills is Ayoub Fandi known for?

Ayoub Fandi has skills like Anglais Professionnel, Leadership Organisationnel, Amazon Web Services, Gestion Des Risques, Cybersecurity, It Risk Management, Microsoft Powerpoint, Parler En Public, Communication, Agile Methodologies, Cyber Risk Management, Cyber Security Risk.

Who are Ayoub Fandi's colleagues?

Ayoub Fandi's colleagues are Jessica Smith, Lanbo Ma, Bryce Weatherford, Rushik Subba, Tyler Smith, Stan Brower, Erick Bajao.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.