Professional profile

Cybersecurity leadership, built across the whole system.

I am Taher Amine ELHOUARI—an independent vCISO, senior advisor, accredited auditor, and certified trainer. My work connects governance, risk, assurance, security operations, resilience, and technical reality so leaders can make defensible decisions.

15+Years across IT and cybersecurity
4Continents of professional engagement
300+Certifications and professional credentials
50+Authorized professional training programs

Security is not one function. It is a system of decisions.

My career has moved through technology support, software and web delivery, offensive security, enterprise security operations, consulting, executive leadership, assurance, audit, and training. That range shapes how I see cybersecurity today.

A control can be well written and still fail in operation. A SOC can generate excellent telemetry and still fail to influence risk decisions. A strategy can look convincing and still collapse when ownership, evidence, escalation, and accountability are unclear.

I work across those boundaries—connecting executive intent to operating reality, and technical evidence to the decisions that boards, CISOs, auditors, and delivery teams must own.

Executive altitude. Operational depth.

A multidisciplinary perspective developed through leadership, delivery, assurance, and hands-on security work.

01

Executive leadership & advisory

CISO and vCISO leadership, cyber strategy, operating models, enterprise risk, board reporting, transformation, and accountable roadmaps.

  • CISO / vCISO
  • Strategy
  • Governance
  • Board advisory
02

Audit, GRC & assurance

Risk, control, compliance, ISMS, BCMS, PIMS, audit readiness, and evidence-led assurance across regulated and operationally sensitive environments.

  • ISO 27001
  • ISO 22301
  • ISO 27701
  • Independent assurance
03

Security operations & resilience

SOC, MSOC, CSIRT, incident response, crisis management, detection, vulnerability management, architecture, and operational resilience.

  • SOC / CSIRT
  • Incident response
  • DFIR
  • Resilience
04

Capability & ecosystem building

Executive education, professional training, mentoring, certification programs, knowledge platforms, community leadership, and international capacity building.

  • Training
  • Mentoring
  • Speaking
  • Knowledge platforms

Certification auditing and advisory are distinct mandates.

Through engagements with accredited certification bodies, I can perform official third-party certification audits within my approved scope—particularly across ISMS, BCMS, and PIMS, as well as other applicable management-system standards.

Those certification activities are kept clearly separate from independent advisory, implementation support, gap assessment, and certification-readiness work. The distinction protects impartiality, professional integrity, and client confidence.

Built from the technical foundation upward.

The detailed role history belongs in the resume. This is the progression that explains the perspective.

Explore the full experience
  1. 2010–2012

    Technology foundations

    Began in practical IT support, systems, networking, and client-facing technical problem solving.

  2. 2013–2017

    Independent delivery & offensive security

    Delivered international web, secure-development, VAPT, ethical-hacking, source-code review, and training engagements.

  3. 2018–2023

    Security operations & program leadership

    Progressed through penetration testing, security project management, consulting, SOC, incident response, DFIR, and enterprise information security.

  4. 2024–Present

    Executive, advisory, assurance & capacity building

    Expanded into CISO leadership, vCISO mandates, business-unit direction, certification audits, global advisory roles, professional training, and public knowledge programs.

Leadership, assurance, learning, and contribution.

Current work spans independent mandates, recognized professional programs, international expert contribution, and public knowledge platforms.

Independent practice

Independent vCISO, Senior Advisor, Auditor & Trainer

Executive and project-based mandates across cybersecurity strategy, governance, assurance, operations, resilience, and technical security.

Professional training

PECB Certified GOLD Trainer

Authorized across more than 50 professional programs spanning cybersecurity leadership, management systems, risk, GRC, incident management, and resilience.

International contribution

AfricaCERT SME & EC-Council Advisory Boards

Contributing to security frameworks, maturity models, assessment resources, executive curricula, technical review, and cyber capacity building.

Public platforms

Cyber Master Series & The InfoSec Control Room

Building accessible practitioner resources and conversations about governance, security operations, resilience, and consequential cyber decisions.

Bring clarity to the mandate before adding more complexity.

I am available for independent advisory, vCISO, audit, training, speaking, partnership, contract, and selected international leadership opportunities.

Start a conversation