Cyber Forensics Investigations & Incident Response
100%He has led high-profile digital forensics investigations and cyber breach assessments, assisting organizations in identifying, containing, and remediating security incidents. His expertise includes forensic analysis of compromised systems, investigation of insider threats, fraud detection, and identification of data exfiltration attempts. He has also developed and executed incident response plans to ensure effective threat mitigation and regulatory compliance.
Breach Assessments & Red/Blue Teaming
100%Razi has performed assumption-based breach assessments and Red/Blue Teaming exercises using the MITRE ATT&CK Framework to simulate real-world attack scenarios. His experience includes physical security bypass assessments, ATM compromise simulations, network penetration testing, and adversarial attack simulations aimed at enhancing organizational detection, response, and mitigation capabilities.
Cybersecurity Operations & SOC Maturity Assessments
100%He has conducted Security Operations Center (SOC) reviews and maturity assessments to evaluate and enhance threat monitoring, incident response, and SIEM capabilities. He has developed SOC enhancement programs focusing on threat intelligence, security orchestration, automated incident response, and operational effectiveness. His work has significantly improved clients’ cybersecurity monitoring and response capabilities.
Operational Risk Management & Compliance Reviews
100%Razi has led operational risk assessments across banking, insurance, and financial institutions, evaluating resilience against cyber threats, regulatory changes, and third-party risks. He has assisted organizations in identifying, assessing, and mitigating operational risks while ensuring compliance with ISO 27001, NIST, PCI-DSS, SOC 2, GDPR, and other regulatory requirements.
Business Continuity & Disaster Recovery (BCP/DR)
100%He has designed and implemented enterprise-wide Business Continuity Plans (BCP) and Disaster Recovery (DR) programs aligned with ISO 22301 and SBP’s ETGRM framework. His experience includes conducting simulation exercises, tabletop drills, failover testing, and resilience assessments to ensure business continuity during cyber incidents, natural disasters, and operational disruptions.
Cybersecurity Awareness & Training Programs
100%Razi has developed and delivered cybersecurity awareness and training programs designed to educate employees on phishing attacks, social engineering techniques, and security best practices. He has also designed and executed phishing simulation campaigns to assess human risk factors and strengthen cybersecurity culture across organizations.
Biography
Syed Muhammad Razi is a seasoned cybersecurity and risk advisory professional with over 14 years of extensive experience in technology risk management, cybersecurity, business continuity, and regulatory compliance. Having been associated with leading Big 4 firms, he has successfully led high-impact engagements across banking, financial services, multinational corporations, and regulated industries.
Currently serving as Director – Cyber Security & Risk Advisory at Infinitrs Private Limited, he spearheads enterprise-wide security and risk consulting initiatives, ensuring organizations achieve resilience, compliance, and enhanced cyber maturity. He specializes in ISO 27001, SOC 2, NIST, COBIT, PCI-DSS, and regulatory frameworks, advising clients on cyber risk governance, information security strategy, and business continuity planning.
Throughout his career, he has led security transformation programs, IT audits, regulatory reviews, third-party risk management initiatives, and enterprise resilience strategies. With a strong leadership background, he has mentored and managed cross-functional teams, driving excellence in cybersecurity implementation, risk mitigation, and strategic advisory services for clients across the Middle East, Pakistan, and international markets.
Professional skills
Vulnerability Assessment & Penetration Testing (VAPT)
100%Razi has conducted multiple Vulnerability Assessment and Penetration Testing (VAPT) engagements for web and mobile applications, network devices, operating systems, cloud environments, databases, SCADA systems, and embedded software. His expertise enables organizations to identify security weaknesses and implement effective remediation measures to strengthen their security posture.
Security Assessments
100%He has performed comprehensive Security Configuration Reviews for operating systems, databases, and web servers in accordance with industry standards such as NIST and CIS. Additionally, he has conducted security assessments aligned with various data governance, privacy, and protection regulations to ensure organizational compliance and resilience.
Business Continuity Planning (BCP)
100%Razi possesses extensive experience in implementing and managing Business Continuity Plans (BCP) in compliance with ISO 22301 standards. He has developed, tested, and maintained business continuity strategies to ensure the resilience of critical business functions during disruptions. He has also coordinated with key stakeholders to align continuity planning with organizational risk management frameworks and recovery objectives.
Secure Code Reviews
100%He has executed Secure Source Code Reviews for web, mobile, and desktop applications, ensuring compliance with recognized methodologies and standards such as OWASP Top 10, CREST, and OSSTMM. His reviews have helped organizations identify and mitigate security vulnerabilities during the software development lifecycle.
CMMI Assessments & IT Governance
100%Razi has conducted CMMI maturity assessments and process improvement initiatives for organizations seeking to enhance IT service delivery and operational excellence. He has assisted clients in achieving CMMI Level 3 and Level 5 certifications while ensuring adherence to structured process improvement frameworks. He has also provided strategic IT governance advisory services aligned with regulatory requirements and industry best practices.
IT Audits & Security Configuration Reviews
100%He has conducted IT audits and security configuration reviews for organizations seeking compliance with international standards and local regulatory requirements. His audit engagements have included detailed gap assessments, remediation planning, and secure configuration reviews for network devices, databases, and cloud platforms to reduce cyber risk exposure.
Cloud Security & Compliance Assessments
100%Razi has assessed cloud security architectures and controls across AWS, Microsoft Azure, and Google Cloud environments. His expertise includes evaluating identity and access management (IAM), encryption controls, cloud-native security configurations, and compliance requirements aligned with CSA STAR, NIST, ISO 27017, and industry-specific standards.
Third-Party & Vendor Risk Management
100%Razi has developed and implemented Third-Party Risk Management (TPRM) frameworks to ensure due diligence, security compliance, and effective risk mitigation across vendor ecosystems. He has assessed outsourcing arrangements, cloud service providers, and supply chain risks to strengthen third-party governance and organizational resilience.
IT & Information Security Risk Assessments
100%He has performed enterprise-wide IT and Information Security risk assessments, identifying vulnerabilities across cloud environments, IT infrastructure, and business-critical applications. His work includes risk quantification exercises, development of Risk Control Matrices (RCMs), Key Risk Indicators (KRIs), and Business Impact Analysis (BIA) frameworks to enhance risk oversight and decision-making.
Policy Development & Regulatory Compliance
100%Razi has developed, reviewed, and implemented Information Security and IT policies aligned with ISO 27001, PCI-DSS, GDPR, SOC 2, and NIST requirements. He has provided compliance advisory services and led policy standardization initiatives to ensure regulatory alignment, governance effectiveness, and risk mitigation across organizations.
Cybersecurity Strategy & Program Development
100%He has advised organizations on developing, implementing, and optimizing cybersecurity strategies aligned with business objectives, risk tolerance, and regulatory requirements. His expertise includes establishing long-term security roadmaps, strengthening cyber risk governance frameworks, and enhancing organizational resilience and cyber maturity through strategic security initiatives.
Request a quote for work
Feel free to contact us through Twitter or Facebook if you prefer!