Hi, I am

Ricky Anand

Cybersecurity Governance, Risk & Assurance | CISSP

MY PROJECTS

PENETRATION TESTING

Performed Grey Box penetration testing on a virtual server using OSINT (Open-source intelligence) and identified vulnerabilities exploitable with Metasploit, Burp Suite, and Nessus.

Read more
PHISHING SIMULATION

Educated users on the ease of creating phishing emails and provided steps for mitigation using Kali Linux and industry-standard tools.

Read more
SIEM (LOG ANALYSIS)

Used SPLUNK tool to conduct analysis of a Brute Force Attack on Windows and Linux Server.

Read more
GRC - RISK ASSESSMENT (MATRIX)

Created a custom Risk Matrix for a Healthcare provider for Incident Response that categorised the incidents based on Severity and Likelihood of Occurrence.

Read more
CLOUD NETWORK

Designed a secure network using Microsoft Azure Cloud Services with Load Balancing capabilities.

Read more

Cybersecurity leadership and assurance

12+ years across Victorian Government, local government and private-sector environments.

Dec 2024 – Present

Cyber Security Analyst

Suburban Rail Loop Authority

  • Translate project, supplier and technology risks into clear business treatments.
  • Produce executive-ready vulnerability reporting with remediation ownership and trend analysis.
  • Support third-party assurance, Essential Eight uplift, security awareness and AI governance.

Sep 2023 – Dec 2024

Cyber Security Analyst

Yarra Ranges Council

  • Primary dedicated cyber analyst for a 900–1,000-user local-government environment.
  • Coordinated Essential Eight maturity uplift and evidence-based governance reporting.
  • Assessed supplier controls and residual risk while delivering practical security-awareness initiatives.

May 2018 – Aug 2023

IT Security Analyst

Momentum Systems

  • Strengthened IAM, monitoring, incident investigation and security-risk remediation.
  • Used Splunk SIEM to investigate suspicious activity and improve security visibility.
  • Supported ISO 27001, NIST CSF, GDPR and ASD Essential Eight-aligned control improvement.

Ricky Anand

Turning cybersecurity complexity into decision-ready action.

I am a CISSP-certified cybersecurity professional with 12+ years of experience across ICT, web security and cybersecurity. I help organisations prioritise risk, strengthen third-party assurance, improve vulnerability governance and turn technical findings into clear, decision-ready actions for senior stakeholders.

My work spans cyber governance, Essential Eight uplift, ISO/IEC 27001 and NIST CSF-aligned assurance, executive reporting, security awareness and AI risk. I bring a practical, business-focused approach: make the risk clear, assign ownership and move remediation forward.

portfolio_img