Tim N | Security & Compliance Specialist
Specialising in governance, risk, and compliance — ensuring security frameworks such as ISO 27001 and PCI DSS are implemented, monitored, and continuously improved.
Delivering robust security solutions with expertise in hybrid cloud environments, security monitoring and incident response.
Professional Experience
RUSH | Security Compliance & Tech Ops Specialist
Contributing extensively to ISO 27001 and PCI DSS audits, providing 24/7 security monitoring, and enhancing cloud security posture across multi-cloud environments.
Guardian Cyber Security | Director
Curating and sharing real-time threat intelligence through regular LinkedIn content, helping professionals stay ahead of emerging cyber threats.
HF Holidays | Cyber Security Consultant
Conducted penetration testing, vulnerability assessments, and provided tailored remediation strategies to strengthen security defences.
Previous Career | Media Leadership
Extensive background in strategic planning at NZ advertising organisations, developing robust business strategies and team management.
Core Expertise
GRC & Audit Readiness
ISO 27001 and PCI DSS compliance and audit preparation
Cloud & Endpoint Security
Multi-cloud environment protection and device monitoring
Security Monitoring & Incident Response
24/7 threat detection and mitigation
Security Culture & Training
Training and awareness programmes
Tim specialises in building practical, resilient security strategies by combining technical expertise with strategic business insight, ensuring comprehensive protection of digital assets while enabling business growth.
Professional Certifications
Validated expertise across leading industry certifications:
CompTIA Certifications
  • Currently pursuing CompTIA CySA+
  • CompTIA PenTest+ certified
  • CompTIA Security+ certified
  • CompTIA ITF+ certified
ISC2 Certifications
  • Currently pursuing ISC2 CGRC
  • ISC2 CC (Certified in Cybersecurity) certified
  • ISC2 Member
Microsoft Certifications
  • Microsoft SC-900 certified
  • Microsoft AZ-900 certified
ISACA Certifications
  • ISACA CCOA certified
  • ISACA Member & ISACA Auckland Chapter
Google Certifications
  • Google Cloud Cybersecurity Certificate
  • Google Cybersecurity Certificate
Other Certificates
  • TryHackMe Security Engineer
  • Microsoft Cybersecurity Analyst
Key Responsibilities at RUSH
GRC Management
Successfully supported RUSH’s ISO 27001 external surveillance audit and PCI DSS Level 1 recertification, ensuring continuous compliance and control evidence management
Security Monitoring
24/7 threat detection using advanced SIEM and EDR solutions
Cloud Security
Enhancing security posture across multicloud environments
Security Training
Leading security awareness initiatives and staff onboarding
Tim provides comprehensive security oversight while maintaining operational efficiency, balancing robust protection with business enablement across all technology platforms.
Guardian Cyber Security Initiative
Monitor
Track breaking cyber threats, vulnerabilities, and regulatory changes
Analyse
Evaluate impact, technical details, and business implications
Translate
Convert complex technical concepts into accessible insights
Share
Distribute timely updates via LinkedIn to security professionals
This personal initiative helps close the awareness gap between emerging threats and security responses, providing actionable intelligence for security teams, compliance professionals, and business leaders.
Educational Background
AUT & Institute of Data
Cyber Security Program graduate, acquiring practical skills in security operations, risk management, and compliance through intensive training.
University of Southampton
BSc (Hons) in Environmental Science, providing strong analytical foundations and methodical research approaches.
Continuous Learning
Pursuing advanced certifications including BSI ISO 27001 Lead Auditor, CySA+, ISC2 CGRC and ISACA CRISC to further enhance professional expertise.
Connect With Tim
LinkedIn
Connect professionally at www.linkedin.com/in/tnorman
Collaboration
Open to discussing security strategies and sharing industry insights
Tim is passionate about advancing cyber security practices and welcomes connections with fellow professionals interested in building more secure digital environments.