Profile

JESUFEMI E. DADA

Cybersecurity professional | ISC2 Certified in Cybersecurity | Cybersecurity Audit & Assurance | Incident Response |Risk & Controls Assessment | Cloud Security | Member, Chartered Institute of Information Security (CIISec.)

PROFESSIONAL PROFILE

About

A results-oriented Cybersecurity graduate, Committed to reducing the human and organisational factors that drive cyber risk, and to applying security best practice in real-world environments.Brings a strong foundation across risk and controls assessment, defence-in-depth, and secure systems design, with a track record of analytical problem-solving, rigorous research, and clear communication to both technical and non-technical stakeholders.Independently built a rules-based cybersecurity audit engine for SMEs, mapped to ISO 27001, NCSC Cyber Essentials, GDPR, NIST CSF, and CIS Controls v8, producing board-ready audit reports with a Red/Amber/Green scoring model and escalation logic for live threats.Led an independent phishing behaviour study, conducted under strict ethical governance in line with GDPR and the BPS Code of Human Research Ethics, exploring the psychological and behavioural patterns behind user susceptibility to social engineering, and translating findings into a five-module security awareness training programme designed to reduce real-world vulnerability.Combines this behavioural insight with hands-on technical expertise in secure IoT system simulation, TLS-encrypted communications, JWT authentication, and real-time intrusion detection, with a proven ability to analyse complex security challenges, identify root causes, and act decisively under a structured, research-driven approach.

Professional Experience

Cybersecurity Audit & Assurance Placement | Lasota Group Ltd, t/a Aisy | England, UK | 29 Jun 2026 – 21 Aug 2026

• Researched NCSC and ICO breach data to identify the five root causes of UK SME cyber incidents, phishing, weak credentials, misconfiguration, supply chain risk, and poor access control, and used them to design a rules-based audit engine from scratch.• Designed and built a rules-based cybersecurity audit engine for SMEs from scratch, developing ten evidence-based diagnostic questions across six risk domains, each mapped to ISO 27001, NCSC Cyber Essentials, GDPR/ICO guidance, NIST CSF, and CIS Controls v8.• Engineered a version-controlled JSON rules engine implementing a fixed Red/Amber/Green scoring model, producing board-ready, client-facing audit reports with a prioritised 30-day remediation plan and escalation layer to route live threats to mandatory human review before any client-facing output was released.• Supported stakeholder communication throughout the engagement, translating technical risk findings into clear, business-relevant language

Student Ambassador | Keele University | England, UK | Nov 2025 – Jun 2026

• Applied strong verbal communication and audience analysis skills to guide prospective students and parents through campus tours and open days, tailoring explanations of courses, accommodation, and student life to each visitor's level of familiarity with the university.• Investigated and resolved visitor queries on the spot, drawing on research into course structures, admissions criteria, and campus logistics to give accurate, confident answers under time pressure.• Built adaptability and structured thinking by managing unpredictable, high-volume enquiries across simultaneous events, prioritising which issues needed immediate escalation versus independent resolution.

Onboarding & Incident Response | Investornomy Inc. | Ontario, Canada | Jun 2022 – May 2025

• Reduced average incident resolution time by 35% as primary escalation point for live security events, applying structured triage, root cause analysis, and end-to-end tracking aligned to NIST CSF Respond and Recover functions.• Designed and delivered a behavioural security awareness programme that cut escalated incidents by 30%, grounded in real incident data with measurable behaviour change, not just awareness scores.• Managed identity and access control across all staff transitions, enforcing least-privilege policies, and ensuring zero residual access for departing employees.• Conducted application and system-level risk and controls assessments during onboarding reviews, identifying access and configuration risks before new staff touched production systems.• Prepared and maintained governance documentation, audit logs, and compliance records, creating an auditable trail of every significant security decision and incident.

Projects

Rules-Based Cybersecurity Audit Engine for SMEs: Automated Risk Scoring Mapped to ISO 27001 and NIST CSF and CIS Controls

| Industry Placement Project | Jun–Aug 2026

An Ethical Simulated Phishing Study: Assessing Behavioral Susceptibility in an SME Context and the Implementation of a Targeted

Overview

A rules-based cybersecurity audit engine built for small and medium businesses (SMEs), designed to identify real-world breach risk and deliver a plain-language, prioritised action plan without requiring any technical knowledge from the business owner.The engine takes a business through ten evidence-based diagnostic questions, mapped to ISO 27001, NCSC Cyber Essentials, GDPR, NIST CSF, and CIS Controls v8, scoring exposure against a fixed Red/Amber/Green model. Live, active threats are pulled out of normal scoring and routed to mandatory human review, with built-in safety rules preventing the engine from ever instructing a client to remove access or alter a system directly. Full rule logic and system configuration are intentionally withheld from this document to protect the engine's integrity.

Executive Summary

The engine was tested against five simulated businesses, each run twice on separate days, to confirm the model produced consistent, repeatable ratings rather than one-off judgement calls. Every inconsistency found was closed, at which point testing confirmed identical outputs on every run.The final deliverable is a client-facing report containing an overall risk rating, a findings table across all ten domains with written justification for each score, an escalation section with an immediate first-hour response plan for active threats, and a prioritised 30-day action plan pairing each finding with a fix and an ongoing check.This addresses a real gap in UK SME security: 46% of small businesses and 65% of medium-sized businesses identified a breach or attack in the last 12 months, and 38% experienced phishing attacks specifically, yet only 19% carried out any staff security training in that period, a figure that has stayed flat year on year (Cyber Security Breaches Survey 2025–2026, DSIT and Home Office).Built during an 8-week cybersecurity placement, the project moved from independent research into SME breach causes, through question design and rules engine development, to a full cybersecurity audit product.

An Ethical Simulated Phishing Study in SMEs Assessing Non-Technical Employee Susceptibility and Delivering Targeted Awareness

|Personal Project | May 2026

An Ethical Simulated Phishing Study: Assessing Behavioral Susceptibility in an SME Context and the Implementation of a Targeted

Overview

An ethical, consent-based simulated phishing study conducted with 17 SME-employed participants. The study investigated behavioural and cognitive factors contributing to phishing susceptibility, and implemented a custom just-in-time awareness training programme for participants who clicked.
A cloud-hosted phishing simulation lab environment was designed to ensure accessibility on any network from any location, no shared physical network required between researcher and participants.
The environment was built to support a web application, email delivery, DNS configuration, and a hosted lab server for campaign-style testing in a closed setting. Full configuration details, API credentials, SMTP credentials, and operational reproduction steps are intentionally withheld from this document to ensure responsible disclosure and prevent unethical reproduction.

Executive Summary

A simulated phishing email was deployed via GoPhish hosted on a DigitalOcean VPS, delivered through Brevo authenticated SMTP. Participants who clicked were directed to an ethical disclosure page, an anonymous behavioural survey, and a custom five-module phishing awareness training programme hosted on Google Classroom.12 of 17 participants clicked the simulation link, a 70.6% click rate, 2.9 times the KnowBe4 2025 SME industry baseline of 24.6%. Analysis of the behavioural survey revealed that curiosity was the dominant click motivator (54.5%), followed by genuine belief in the email's legitimacy (45.5%).Time-to-click analysis showed that 75% of participants clicked more than 30 minutes after delivery, confirming that susceptibility was driven by the quality of the social engineering rather than momentary inattention.The most significant finding was the Overconfidence Paradox: 54.5% of respondents rated themselves as highly confident in their ability to detect phishing before the study and every one of them clicked. This directly reflects the Dunning-Kruger effect (Kruger and Dunning, 1999) and demonstrates that security awareness training must target confident employees, not just those who self-identify as uncertain.The study concludes that SME phishing susceptibility is more of a behavioural and cognitive challenge, not just a technical one. Effective mitigation requires recurring simulation, just-in-time embedded training, and confidence calibration exercises designed to close the metacognitive gap that leaves the most self-assured employees the most exposed.

Secure Smart Hotel IoT Security System Simulation: Implementing Defence in Depth Through Device-Level JWT Authentication and Real-Time Intrusion Detection

|Personal Project | February 2026

Video

A Python-based IoT security simulation demonstrating defence in depth across door access control, camera command channels, and HVAC systems,using MQTT with TLS encryption and JWT authentication at device controller level.Three security-critical components, door access control, cameras, and HVAC are each simulated as Python scripts communicating over a real MQTT broker. Rather than trusting the MQTT broker as the main security boundary, every controller (ACU) enforces JWT authentication at device level, blocking unauthorised commands even from attackers with valid broker credentials.A lightweight IoT IDS monitors all channels simultaneously, publishing real-time alerts to a Node-RED dashboard, providing live visual visibility of every device status, access event, and security alert in one place. This ensures attacks are not just blocked but detected, alerted, and visible in real time. Together, these layers address a gap most commercial IoT deployments leave entirely unguarded.

Cloud-Native Medical Imaging Platform on AWS with Secure Scalable Architecture.

|Module Project | March 2026

Video

Designed and presented a cloud-native medical imaging web service application as part of my MSc Cybersecurity module in Data Management and Cloud Technologies. The project involved full architectural design, AWS service selection with justified trade-off analysis, and delivery through a structured slide deck and video presentation.It explored IaaS, PaaS, and SaaS models using real-world cloud provider examples and applied them to a medical imaging context. The system architecture was designed across five layers, covering network security, application, data storage, big data analytics, and security management.The design used AWS VPC, CloudFront, and Shield at the network layer; API Gateway, Application Load Balancer, and Auto Scaling EC2 at the application layer; and S3, RDS PostgreSQL, and DynamoDB for storage and metadata management. It also integrated AWS Glue, Redshift, and Lambda for analytics and stream processing, alongside IAM, KMS, and CloudTrail for secure access, encryption, and audit logging. I also completed five AWS Academy Cloud Foundations modules, achieving 100% in all of them.

Professional
Certifications


01

Certified in Cybersecurity (CC) | ISC2

Issued: March 2026

Credential ID: 3578317


02

Chartered Institute of Information Security (CIISec)

Issued: October 2025

Membership Number:218404

Professional
Engagements


Cyber Security Expo 2026 | Manchester Central, England, UK

Manchester Central | 9th July 2026

I had the incredible opportunity to attend the Cyber Security EXPO at Manchester Central, one of the UK's dedicated recruitment events connecting cyber security professionals, hiring managers, and recruiters under one roof. And what an experience it was!Being in a room with exhibitors, industry professionals, and recruiters gave me the chance to have real, honest, face to face conversations that added so much value to my professional journey. I had the chance to speak directly with recruiters and employers about what is tangible and actionable to become more employable in cyber security todayWhat I truly value about attending events like this is how they help me stay relevant in the field of cybersecurity. The industry moves fast and the Cyber Security EXPO keeps me connected to where the field is heading, what skills matter, and how I need to keep positioning myself to grow as a professional.A big thank you to SATOS Media for organising this event, and to Sponsors Amentum, CGI and Counter Terrorism Policing for making this possible.


National Cyber Security Show | NEC Birmingham, England, UK

Cyber Solution Theatre | 28th-30th April, 2026

Attended the Cyber Solutions Theatre at the National Cyber Security Show 2026, and it was a highly valuable experience. As someone who enjoys attending cybersecurity conferences and events to listen to employers, business owners, and professionals discuss current trends and challenges in cybersecurity, this was a great opportunity to gain practical insight. The sessions covered a range of key topics, including compliance across frameworks, deepfake-enabled threats, browser and workspace security, proactive application security, MDR, and supply chain risk. What stood out most was how these challenges are being addressed in real-world environments.As someone building a career in cybersecurity, I found the discussions around security foundations, AI-driven threats, continuous validation in AppSec, and shared supply chain risk particularly relevant. They reinforced the idea that effective security goes beyond tools, requiring clear thinking, practical controls, and adaptability.I also really valued the opportunity to network with experienced professionals. Those conversations provided useful insight into industry expectations, key skills, and the direction I want to keep pursuing in cybersecurity.


NDC Manchester 2025 – AI & Security | Manchester, England, UK

Crew Member & Volunteer | December, 2025

Volunteered as a Crew Member at NDC Manchester 2025 – an AI & Cybersecurity conference featuring deep-dive, multi-track sessions on secure coding, AI red-teaming, supply chain security, data-streaming security, and building secure infrastructure for AI agents.
Supported smooth day-to-day operations by assisting with speaker and attendee check-in, room setup and turnaround, session timing, crowd flow, and on-site guidance. This helped ensure sessions ran on schedule and participants had a positive and seamless conference experience.
As someone who actively attends cybersecurity events to learn from employers, business owners, and industry professionals about current trends and real-world challenges, this was a valuable opportunity to both contribute and gain insight into the field.

Contact

I am currently open to new opportunities and would love to discuss how my skills can help your team. If you’re looking for a dedicated professional to bring your next project to life, please reach out below

Thank you

Thank you for visiting!I appreciate you taking the time to review my work. If you've sent a message, I will get back to you within 24–48 hours. I look forward to the possibility of working together.