Security · GRC · Markets

Sanda Adedotun

Cybersecurity & GRC Analyst

I find security weaknesses and explain what they mean for the business. Trained in ethical hacking and VAPT, with a background on a trading floor.

  • VAPT Intern, Trios Cyber
  • GRC Certified
  • Cisco Ethical Hacking
  • Open to remote roles
drag or move to tilt · click to pulse

About

Security analyst with a risk manager's instincts

I started my career on a trading floor, building and back-testing strategies against years of market data. That habit of forming a hypothesis, testing it and measuring the result is exactly what security work rewards.

Today I focus on vulnerability assessment and penetration testing (VAPT) and governance, risk and compliance (GRC): finding the gaps, ranking them by business impact, and writing them up so non-technical people can act on them.

Based inIbadan, Nigeria · open to remote
Looking forGRC, security analyst and risk roles
StudyingB.Sc. Economics, University of Ibadan

Experience

Where I've worked

VAPT Intern

Trios Cyber, with Ernith · Sep 2026 to present
  • Hands-on web application testing: recon, SQL injection, XSS and access control
  • Labs across PortSwigger, TryHackMe and DVWA, with Burp Suite
  • Completed a mini web VAPT assessment written up as a full report

Product & Security Analyst (Intern)

MetroHub, Ibadan · 2023 to 2024
  • Ran security audits and pen testing cycles across the company's products
  • Turned findings into prioritised, business-impact-ranked backlogs
  • Wrote security documentation and post-incident reports

Senior Trader

Acorn Capital, Abuja · 2019 to 2021
  • Analysed macroeconomic signals and market trends
  • Designed and back-tested trading strategies on multi-year data
  • Worked within strict regulatory compliance requirements

B.Sc. Economics

University of Ibadan · expected Feb 2027
  • Econometrics, statistics, quantitative methods, market theory

Work

Selected projects

Risk & compliance

Security audit & risk assessment

Risk assessments for simulated company environments on TryHackMe and Forage, with risk matrices, threat models and NIST-aligned fixes.

Incident response

Mastercard cybersecurity simulation

Investigated a phishing scenario, traced the root cause and wrote an executive-style briefing. Forage, 2025.

Applied security

20+ TryHackMe CTFs

Capture the Flag challenges that sharpened recon, exploitation and problem-solving under pressure.

Certifications

Credentials

Governance, Risk & Compliance
Ernith
Sep 2026
Ethical Hacking
Cisco Networking Academy
Jul 2026
Networking Basics
Cisco Networking Academy
Oct 2025
Cybersecurity Job Simulation
Mastercard / Forage
Mar 2025
Cybersecurity Certification
TryHackMe
Dec 2024
Cybersecurity Certification
MetroHub, Ibadan
Nov 2024

Skills

What I work with

Security

  • VAPT
  • Web app testing
  • SQL injection, XSS, IDOR
  • Threat modelling
  • Log analysis & SIEM basics

GRC

  • Risk assessment
  • NIST
  • ISO 27001
  • Policy & compliance
  • Rules of engagement

Tools

  • Burp Suite
  • Kali Linux
  • Nessus
  • Wireshark
  • Linux CLI
  • Python

Threat Desk

Test yourself

Quick quiz

Daily lesson

For businesses

Website Security Check

A fixed-price check of your website's security with a plain-English report and the exact fixes. I only test sites you own, and only with your written permission.

Ask about a check

Contact

Let's talk

Hiring for a GRC, security analyst or risk role, or want your website checked? Send me a message.

Sanda.adedotun@yahoo.comLinkedIn