M Kamruzzaman, IqraX
Advisor

M Kamruzzaman

Cybersecurity, Risk & Compliance Leader · Ex-CISO

Advisor at IqraX. A cybersecurity, risk and compliance leader with 20+ years securing banks and financial institutions, and a certified lead auditor across ISO 27001, 42001, 22301 and 9001.

20+
Years in governance, risk & compliance
800+
Man-day ISO audits: ISMS, QMS & BCMS
7,000+
Employees reached via security-awareness programs
CISA
Certified Information Systems Auditor (ISACA)
About

About M Kamruzzaman

M Kamruzzaman advises IqraX on cybersecurity, governance, risk, and compliance, bringing more than two decades of experience building and leading enterprise security and assurance programs across the banking and financial sector. He currently serves as FAVP and Head of GRC & Data Security at United Commercial Bank PLC, where he runs enterprise-wide cybersecurity, audit, and risk management aligned with ISO 27001, ISO 22301, HIPAA, and the NIST Cybersecurity Framework.

Before UCB, he led information security and IT governance at Meghna Bank and spent nearly seven years at BRAC Bank, first as a principal officer in information security, then as unit head for governance, risk, compliance, and data security, where he drove policy governance and security-awareness programs reaching over 7,000 employees. In parallel, as an independent lead consultant and assessor, he delivered 800+ man-days of audits across ISO 9001 (QMS), ISO 27001 (ISMS), and ISO 22301 (BCMS), and earlier implemented ISO and ITSM frameworks for clients across Saudi Arabia.

A Certified Information Systems Auditor (CISA) and an accredited lead auditor across ISO 27001, ISO 42001 (AI Management Systems), ISO 22301, and ISO 9001, he holds an MSc and BSc in Computer Science (MIS) from Universiti Teknologi Malaysia. At IqraX, he guides the team on building security, privacy, and regulatory compliance into an AI platform for healthcare from the ground up.

Focus

Focus areas

Governance, Risk & Compliance (GRC)Information Security Management (ISO 27001)ISO 42001 (AI Management Systems)Business Continuity (ISO 22301)Quality Management (ISO 9001)IT Audit & AssuranceRisk Assessment & MitigationPCI-DSS & SWIFT CSPRegulatory Compliance (BB, GDPR, HIPAA)NIST CSFCloud & Data Privacy (ISO 27017/27018)Vendor & Third-Party Risk
Experience

Experience

Advisor

Dec 2025 – Present
IqraX

Governance, risk, compliance, and security advisory for the AI operating system for healthcare.

FAVP & Head of GRC & Data Security

Feb 2023 – Present
United Commercial Bank PLC · Dhaka, Bangladesh

Leads enterprise-wide GRC and cybersecurity programs aligned with ISO 27001, ISO 22301, HIPAA and NIST CSF; owns IT governance frameworks, risk assessments and internal audits, and PCI-DSS, ISO 27001/22301 and SWIFT CSP compliance, acting as liaison between auditors, regulators and executive leadership.

Head of Information Security & IT Governance

Aug 2022 – Feb 2023
Meghna Bank Limited · Dhaka, Bangladesh

Ran GRC operations ensuring ISO 27001, PCI-DSS and SWIFT CSP compliance; built IT risk and compliance roadmaps aligned with NIST and GDPR, and supervised VAPT, vulnerability scans and configuration reviews.

Unit Head, Governance, Risk, Compliance & Data Security

Oct 2019 – Aug 2022
BRAC Bank Limited · Dhaka, Bangladesh

Built and led GRC programs (ISO 27001, PCI-DSS, SWIFT CSP) and policy governance and security-awareness initiatives for 7,000+ employees; advised senior leadership on compliance strategy and audit readiness.

Associate Manager (Principal Officer), Information Security

Nov 2015 – Sep 2019
BRAC Bank Limited · Dhaka, Bangladesh

Authored IT security policies, standards and baselines; led threat modeling, VAPT and gap assessments, ran the Security Operations Centre (SOC), and reported IT-risk KPIs, KRIs and Business Impact Analyses.

Lead Consultant / Assessor

Jan 2013 – Dec 2022
Management Information System Consultancy · Remote

Conducted 800+ man-day audits across QMS (ISO 9001), ISMS (ISO 27001) and BCMS (ISO 22301), implementing frameworks incorporating COBIT, ISO 27002 and PCI-DSS, and developing IT-governance and audit-readiness training.

Consultant, Information Security & Management Systems

Dec 2007 – Dec 2012
NEXCONS · Riyadh, Saudi Arabia

Managed ISO certification projects (ISO 9001, 27001, 20000) and IT governance / ITSM frameworks across Saudi clients including SIMAH and Saudi Electricity, with security assessments for Alfanar and Saudi Hollandi Bank.

Education

Education

MSc in Computer Science (MIS)

2007
Universiti Teknologi Malaysia

BSc in Computer Science (MIS)

2003
Universiti Teknologi Malaysia