Melbourne, Australia · CISSP

Cybersecurity
governance, risk
& assurance.

I help organisations turn complex cyber findings into clear risk decisions, accountable action and evidence-backed assurance.

12+Years in ICT & cybersecurity
CISSPSecurity leadership credential
3–4 / moVendor assurance assessments
900–1kLocal-government users supported
Gov / InfraVictorian public-sector context
Portrait of Ricky Anand
Professional profile

Risk is only useful when it leads to a decision.

I am a cybersecurity governance, risk and assurance professional based in Melbourne. My career began in secure web development before moving into dedicated cybersecurity roles across private-sector, local-government and Victorian Government environments.

I work where cybersecurity needs translation: what risk exists, who owns it, what evidence supports it, what treatment is realistic and what needs escalation. My value is turning cyber findings into accountable action, measurable trends and clear management decisions.

01 / GOVERNCyber governance & risk
02 / ASSUREThird-party security assurance
03 / IMPROVEEssential Eight maturity
04 / REPORTExecutive cyber reporting
Career path

Experience built across delivery and governance.

A progression from secure engineering foundations to security assurance and decision support in complex operating environments.

Dec 2024 — PresentVictorian Government

Cyber Security Analyst

Suburban Rail Loop Authority

Major Victorian Government infrastructure environment involving complex technology, supplier and governance dependencies.

  • Support cyber governance, risk and assurance activities across a major Victorian Government infrastructure environment.
  • Prepare executive-ready reporting covering exposure trends, remediation ownership, ageing risk and operational blockers.
  • Support third-party cybersecurity assurance through supplier risk review, control assessment and evidence validation.
  • Contribute to AI security governance and practical awareness material for secure technology use.
Sep 2023 — Dec 2024Local Government

Cyber Security Analyst

Yarra Ranges Council

Primary dedicated cybersecurity analyst for a local-government environment supporting approximately 900–1,000 users.

  • Supported governance, risk, assurance, vulnerability management, incident response and awareness activities.
  • Coordinated Essential Eight maturity uplift through gap assessment, evidence collection and remediation tracking.
  • Conducted regular vendor security assessments, reviewing supplier controls, questionnaire responses and supporting evidence.
  • Provided cybersecurity input into digital-transformation and technology-governance discussions.
May 2018 — Aug 2023Private Sector

IT Security Analyst

Momentum Systems

Five-year role spanning IAM, security monitoring, governance, control improvement and compliance support.

  • Supported identity and access management, access reviews and least-privilege improvement.
  • Used Splunk for log analysis, security monitoring and investigation of suspicious activity.
  • Contributed to risk assessments, control reviews, audit evidence and remediation tracking.
Jan 2015 — Apr 2018Secure Engineering

Security-Focused Web Developer

Digital Thing

Secure web-development foundation before transition into dedicated cybersecurity roles.

  • Developed web applications with a focus on secure design, reliability and data protection.
  • Applied OWASP-aligned practices across authentication, validation, sessions and access control.
Contribution areas

Work that makes security easier to govern.

The focus is practical security contribution: evidence, ownership, risk treatment and better decisions.

01

Executive cyber reporting

Translate technical findings into decision-ready risk messages, measurable exposure trends, accountable ownership and clear escalation points.

RISK TRENDSREPORTING
02

Third-party security assurance

Review supplier controls and evidence to advise stakeholders on residual risk, onboarding decisions and remediation requirements.

SUPPLIER RISKEVIDENCE
03

Essential Eight maturity

Support control uplift by identifying gaps, gathering evidence, tracking remediation and making implementation practical.

CONTROL UPLIFTMATURITY
04

Vulnerability governance

Turn technical findings into prioritised remediation actions, ageing analysis, ownership segmentation and management reporting.

REMEDIATIONACCOUNTABILITY
05

AI security governance

Support secure and responsible generative AI adoption across data protection, supplier assurance, access and acceptable use.

AI RISKDATA PROTECTION
06

Security awareness & culture

Develop practical guidance for real users on phishing, QR-code threats, supplier risk and safer technology use.

CYBER CULTUREAWARENESS
Selected work

From risk to action.

A selection of work across vulnerability governance, supplier assurance and Essential Eight maturity.

Credentials

Grounded in practice and formal learning.

Recognised security certification, public-sector assurance experience and a secure engineering background.

CISSPCertified Information Systems Security Professional
Security+CompTIA security certification
Essential EightCertified assessor, TAFECyber
MBADeakin University
BITRMIT University

CYBER GOVERNANCE · THIRD-PARTY RISK · ESSENTIAL EIGHT · VULNERABILITY MANAGEMENT · AI GOVERNANCE · EXECUTIVE REPORTING · ISO 27001 · NIST CSF · IAM · SPLUNK · SECURE WEB DEVELOPMENT

Start a conversation

Let’s make cyber risk clearer and more actionable.

Melbourne, Australia. Available to connect on cybersecurity governance, assurance, supplier risk and security architecture.