Professional Summary
Overview
Work History
Education
Skills
Certification
Personal Information
Languages
Timeline

MUSTAFA AGGOUR

Socotra Coffee House
Ann Arbor
2
Languages
1
Certification
4
years of professional experience

Cybersecurity professional with expertise in security assessments, risk management, and policy development. Applies NIST SP 800-53, NIST SP 800-30, NIST CSF, and ISO 27001 to identify control gaps and create business-aligned remediation plans. Experienced in cloud security, identity governance, and AI-driven security tools.

Work History

IT & Security Support

3 Years 2 Months
Socotra Coffee House | 08.2023 - Current
  • Conducted IT and security audits evaluating systems, access practices, and network security; supported PCI DSS compliance reviews and documented risk findings and corrective actions.
  • Developed security policies covering access control, acceptable use, and data protection; built and secured the organization's Wi-Fi network and supporting infrastructure.
  • Worked effectively in fast-paced environments.
  • Self-motivated, with a strong sense of personal responsibility.
  • Proven ability to learn quickly and adapt to new situations.

Cybersecurity & IT Intern

1 Year 10 Months
Muslim Community Association | 03.2023 - 01.2025
  • Evaluated systems against NIST SP 800-53 controls through audits, interviews, and document reviews, identifying 15+ security gaps and delivering risk-prioritized remediation recommendations.
  • Performed cybersecurity risk assessments using NIST SP 800-30 methodology, evaluating threats, vulnerabilities, and control weaknesses to prioritize remediation efforts.
  • Collected and organized audit evidence and compliance records across 20+ systems and applications, improving audit readiness and documentation accuracy for internal governance reviews.
  • Developed information security policies and compliance documentation supporting governance objectives; monitored authentication and system logs to identify anomalies, escalating findings per incident response procedures.
  • Delivered security awareness training that improved employee understanding of data handling and security best practices.
  • Supported help desk requests, resolving hardware, software, and connectivity issues for staff and volunteers.
  • Maintained user accounts, passwords, and access permissions across organizational systems.

Education

B.S. - Cybersecurity & Information Assurance

Western Governors University | 02-2025

B.S. - Psychology

Eastern Michigan University | 08-2022

Skills

Compliance Oversight
Risk Assessments
Control Testing
Control assessments
Remediation Tracking
Evidence Collection
Incident Response
Audit evidence
Policy management
NIST CSF
NIST CSF
PCI DSS
ISO 27001
CIS Controls
MITRE ATT&CK
MITRE ATT&CK

Certification

CompTIA Security+ | CompTIA CySA+ | CompTIA PenTest+ | CompTIA Network+ | CompTIA Project+ | ITIL 4 Foundation | Linux Essentials

Personal Information

Title: GOVERNANCE, RISK & COMPLIANCE (GRC) ANALYST — CYBERSECURITY

Languages

Arabic
Native or Bilingual
English
Native or Bilingual

Timeline

IT & Security Support

Socotra Coffee House
08.2023 - CurrentRead More

Cybersecurity & IT Intern

Muslim Community Association
03.2023 - 01.2025Read More

Eastern Michigan University

B.S. from Psychology
Read More

Western Governors University

B.S. from Cybersecurity & Information Assurance
Read More
MUSTAFA AGGOUR