Shabbir Kamal.
Portfolio · Sydney, AU

Shabbir
Kamal.

AI & cybersecurity consultant, engineer, and builder.

I help organisations adopt AI where it actually pays back, build the AI and software to do it, and put the governance and security in place so it holds up, from ISO 42001 and 27001 to production-grade systems.

Shabbir Kamal
MSc · Univ. of Sydney
 ISO/IEC 27001ISO/IEC 42001ISO/IEC 27701ISO 22301NIST CSFSOC 2GDPRRAG & LLMsPenetration Testing
What I do

Three ways
I can help.

Pick one to see how I actually work it: the method, the moves, and what you walk away with.
Service 01

The full AI lifecycle, under one roof.

Find where AI pays back, build it to a production standard, and govern it so it holds up. Three connected pillars, one accountable person.

Find where AI earns its place.
1DiscoverAudit workflows and data to find high-ROI use cases.
2PrioritiseScore each on value, effort, risk and data readiness.
3RoadmapSequence initiatives, decide build vs buy, design the target.
4EnableUpskill teams and set guardrails so adoption sticks.
DeliverablesOpportunity map & roadmap · RAG, agents & LLM apps · AIMS (ISO 42001) · Team enablement
Selected work

Things I built,
and how I got
there.

Nine shipped products across AI, governance and security. Open any project to walk through the approach, the mindset, the changes I made, and what I learnt.
Shabbir Kamal at work
How I work

Technical enough to build it. Grounded enough to make it stick.

I sit between three worlds most people keep separate: the engineering that ships AI and software, the governance that keeps it safe and compliant, and the offensive security that proves it holds. That mix is the whole point, it means what I recommend, I can also build, secure, and defend.
01

Outcome first, hype never

Every engagement starts from the business result, not the technology. If AI is not the right answer, I will say so.

02

Build it like it has to run

Prototypes are cheap; production is the test. I design for evaluation, monitoring, security, and cost from day one.

03

Governance is not paperwork

ISO 42001 and 27001 only matter if they change what teams actually do. I operationalise them, then train people to own them.

04

Leave you self-sufficient

The best outcome is that you do not need me forever. I hand over documented systems and trained teams.

Background

The receipts.

Three years moving from offensive security into GRC, management-system implementation, and AI governance, alongside a research-track master's in Sydney.
Jun 2025 – Feb 2026

Consultant, Information Security & AI

Cybersecurity Consulting Firm - Global

Led ISO 42001 AI Management System implementations, built an ISO 42001 documentation toolkit, delivered executive and technical training, managed client engagements, and mentored a team of consultants to certification readiness.

Jan 2024 – Jun 2025

Consultant, Information Security

Cybersecurity Consulting Firm - Global

Implemented ISMS (ISO 27001) and PIMS (ISO 27701) across enterprise clients through certification and surveillance audits. 15+ risk assessments, 60+ governance documents, and governance workshops for 100+ stakeholders.

Feb 2023 – Jan 2024

Junior Penetration Tester

Cybersecurity Consulting Firm - Global

20+ web, mobile, and network penetration tests under black and gray box methodologies. Found and validated 100+ vulnerabilities with exploit chaining and privilege escalation, achieving 85%+ closure within agreed timelines.

Certifications
ISO/IEC 27001 Implementer
PECB
ISO/IEC 42001 Implementer
PECB
Education
MSc Computer Science
University of Sydney
Cybersecurity
BSc Computer Science
Lahore University of Management Sciences
Leadership
Lead, ReCypher (EU project)
LUMS Chapter · cybersecurity education
VP, AIESEC in LUMS
Youth leadership & global exchange
Get in touch

Building something,
or hiring for it?

I take on select consulting engagements and full-time roles in AI, cybersecurity and governance. Tell me the problem and I will give you a straight answer on whether I am the right fit.