
M Kamruzzaman
Advisor at IqraX. A cybersecurity, risk and compliance leader with 20+ years securing banks and financial institutions, and a certified lead auditor across ISO 27001, 42001, 22301 and 9001.
About M Kamruzzaman
M Kamruzzaman advises IqraX on cybersecurity, governance, risk, and compliance, bringing more than two decades of experience building and leading enterprise security and assurance programs across the banking and financial sector. He currently serves as FAVP and Head of GRC & Data Security at United Commercial Bank PLC, where he runs enterprise-wide cybersecurity, audit, and risk management aligned with ISO 27001, ISO 22301, HIPAA, and the NIST Cybersecurity Framework.
Before UCB, he led information security and IT governance at Meghna Bank and spent nearly seven years at BRAC Bank, first as a principal officer in information security, then as unit head for governance, risk, compliance, and data security, where he drove policy governance and security-awareness programs reaching over 7,000 employees. In parallel, as an independent lead consultant and assessor, he delivered 800+ man-days of audits across ISO 9001 (QMS), ISO 27001 (ISMS), and ISO 22301 (BCMS), and earlier implemented ISO and ITSM frameworks for clients across Saudi Arabia.
A Certified Information Systems Auditor (CISA) and an accredited lead auditor across ISO 27001, ISO 42001 (AI Management Systems), ISO 22301, and ISO 9001, he holds an MSc and BSc in Computer Science (MIS) from Universiti Teknologi Malaysia. At IqraX, he guides the team on building security, privacy, and regulatory compliance into an AI platform for healthcare from the ground up.
Focus areas
Experience
Advisor
Dec 2025 – PresentGovernance, risk, compliance, and security advisory for the AI operating system for healthcare.
FAVP & Head of GRC & Data Security
Feb 2023 – PresentLeads enterprise-wide GRC and cybersecurity programs aligned with ISO 27001, ISO 22301, HIPAA and NIST CSF; owns IT governance frameworks, risk assessments and internal audits, and PCI-DSS, ISO 27001/22301 and SWIFT CSP compliance, acting as liaison between auditors, regulators and executive leadership.
Head of Information Security & IT Governance
Aug 2022 – Feb 2023Ran GRC operations ensuring ISO 27001, PCI-DSS and SWIFT CSP compliance; built IT risk and compliance roadmaps aligned with NIST and GDPR, and supervised VAPT, vulnerability scans and configuration reviews.
Unit Head, Governance, Risk, Compliance & Data Security
Oct 2019 – Aug 2022Built and led GRC programs (ISO 27001, PCI-DSS, SWIFT CSP) and policy governance and security-awareness initiatives for 7,000+ employees; advised senior leadership on compliance strategy and audit readiness.
Associate Manager (Principal Officer), Information Security
Nov 2015 – Sep 2019Authored IT security policies, standards and baselines; led threat modeling, VAPT and gap assessments, ran the Security Operations Centre (SOC), and reported IT-risk KPIs, KRIs and Business Impact Analyses.
Lead Consultant / Assessor
Jan 2013 – Dec 2022Conducted 800+ man-day audits across QMS (ISO 9001), ISMS (ISO 27001) and BCMS (ISO 22301), implementing frameworks incorporating COBIT, ISO 27002 and PCI-DSS, and developing IT-governance and audit-readiness training.
Consultant, Information Security & Management Systems
Dec 2007 – Dec 2012Managed ISO certification projects (ISO 9001, 27001, 20000) and IT governance / ITSM frameworks across Saudi clients including SIMAH and Saudi Electricity, with security assessments for Alfanar and Saudi Hollandi Bank.