
Daniel Kabagema
Verified Expert in Engineering
Cybersecurity Architect and Developer
Montreal, QC, Canada
Toptal member since June 23, 2026
Daniel is a senior cybersecurity architect with 15+ years of experience delivering cloud security, AI security, IAM, application security, and enterprise risk management solutions. He has advised CISOs, CIOs, and executive teams on security strategy, Zero Trust, compliance, and digital transformation initiatives, helping organizations build secure, scalable, and resilient technology platforms.
Portfolio
Experience
- Enterprise Security Architecture - 15 years
- Multi-cloud Security - 10 years
- Identity & Access Management (IAM) - 10 years
- Application Security - 10 years
- Enterprise Risk Management (ERM) - 10 years
- Cybersecurity - 10 years
- AI Risk Management Framework - 5 years
- AI Security - 5 years
Preferred Environment
Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI)
The most amazing...
...solution I've built is an enterprise framework unifying cybersecurity, cloud, and AI governance while helping organizations adopt AI securely and responsibly.
Work Experience
Staff Security Analyst
Twilio
- Architected and led the adoption of the One Twilio Risk Management Framework, standardizing enterprise, cybersecurity, cloud, and AI risk governance across global business functions.
- Developed enterprise security architectures, standards, and roadmaps for Fortune 500, healthcare, public sector, and technology organizations.
- Designed and assessed security controls across AWS, Azure, and hybrid cloud environments, reducing risk exposure and improving security posture.
- Implemented Zero Trust, IAM, PAM, MFA, and conditional access (CA) strategies to strengthen identity security and enforce least-privilege access.
- Advised CISOs, CIOs, and executive committees on cybersecurity strategy, risk management, governance, and cloud transformation initiatives.
- Guided application security reviews, threat modeling, and penetration testing for web, API, cloud, and enterprise platforms.
- Integrated security into Agile and DevSecOps pipelines through SAST, DAST, secure code reviews, and developer enablement programs.
- Performed AI and LLM security assessments, addressing prompt injection, model governance, data security, and AI supply chain risks.
- Delivered security and compliance assessments aligned with ISO 27001, NIST, PCI DSS, SOC 2, HIPAA, and PHIPA requirements.
Senior Cybersecurity Architect
Deloitte
- Developed enterprise security architectures, standards, and multiyear transformation roadmaps for Fortune 500, healthcare, financial services, and public sector organizations.
- Advised CISOs, CIOs, and executive steering committees on cybersecurity strategy, Zero Trust adoption, cloud security, and enterprise risk management initiatives.
- Designed and assessed cloud security architectures across AWS, Azure, VMware, and hybrid environments, improving governance, resilience, and security posture.
- Drove IAM modernization initiatives involving Entra ID, Keycloak, OAuth 2.0, OpenID Connect, SAML federation, MFA, PAM, and Zero Trust architectures.
- Evaluated and optimized Microsoft Defender, Sentinel, Defender for Endpoint, and Defender for Identity deployments to strengthen threat detection and response.
- Performed penetration testing and adversarial assessments across web applications, APIs, Active Directory, cloud platforms, and AI/ML environments.
- Directed AI security assessments and governance reviews aligned with NIST AI RMF, ISO 42001, OWASP LLM Top 10, and MITRE ATLAS frameworks.
- Delivered security assessments and remediation roadmaps aligned with ISO 27001, NIST, PCI DSS, SOC 2, HIPAA, and PHIPA requirements.
- Implemented Zero Trust security models and identity governance controls, reducing access risks while supporting large-scale cloud transformations.
- Produced executive-level security assessments, risk analyses, and remediation strategies, enabling informed technology and security investment decisions.
Senior Application Security Analyst
Computer-talk.com
- Led application security assessments and secure design reviews for enterprise contact center platforms, identifying vulnerabilities and reducing security risk.
- Conducted threat modeling using STRIDE and OWASP methodologies to identify attack paths and strengthen security controls during application design.
- Performed web application and API penetration testing using Burp Suite, OWASP ZAP, Postman, Nmap, and SQLMap to validate security weaknesses.
- Integrated security into Agile and DevSecOps workflows through SAST, DAST, secure code reviews, and vulnerability remediation programs.
- Embedded as the security subject-matter expert (SME) within Agile teams, enabling developers to address security risks early without impacting delivery timelines.
- Defined and implemented secure coding standards, authentication controls, input validation requirements, and API security best practices.
- Established vulnerability management processes that improved remediation prioritization, risk visibility, and overall application security posture.
- Integrated security requirements into the SDLC, strengthening security governance across design, development, testing, and deployment phases.
- Validated application security controls through manual testing, attack simulation, and proof-of-concept exploitation of identified vulnerabilities.
- Partnered with engineering teams to improve security awareness, reduce recurring vulnerabilities, and accelerate secure software delivery.
Network Security and IT Administrator
Facturation Medicale Rive Sud
- Managed IT and security operations for a healthcare organization, protecting sensitive patient information and supporting regulatory compliance requirements.
- Administered VMware virtualized infrastructure, implementing workload security, network segmentation, and access controls for critical business systems.
- Configured and maintained firewalls, IDS/IPS, and network security controls to strengthen perimeter defenses and reduce operational risk.
- Implemented RBAC and access control policies across servers, applications, and network devices to enforce least-privilege principles.
- Performed vulnerability assessments, patch management, and system hardening activities to improve infrastructure security and resilience.
- Monitored network traffic and security events using analysis tools, enabling proactive detection and response to operational threats.
- Implemented data protection controls and security configurations to reduce the risk of unauthorized access to healthcare information.
- Secured VMware vSphere and ESXi environments through hardening, access management, and infrastructure security best practices.
- Maintained highly available infrastructure supporting healthcare billing operations while ensuring security, performance, and reliability.
- Managed Windows servers, virtualization platforms, network infrastructure, and security technologies across a regulated environment.
System and Network Administrator
Gexel Telecom
- Managed enterprise network and server infrastructure supporting multi-site telecommunications operations and business-critical services.
- Administered firewalls, network devices, and access controls to strengthen infrastructure security and reduce operational risk.
- Maintained Windows and Linux server environments, ensuring system availability, performance, and security across distributed locations.
- Implemented system hardening, patch management, and security configurations to improve the organization's security posture.
- Monitored and troubleshot network performance issues, improving service reliability and minimizing operational downtime.
- Managed user accounts, permissions, and authentication controls across enterprise systems and network infrastructure.
- Supported telecommunications infrastructure and network services, ensuring secure and reliable connectivity across business locations.
- Investigated and resolved infrastructure, network, and security incidents, reducing service disruptions and improving operational stability.
- Contributed to infrastructure upgrades and technology refresh initiatives that improved scalability, reliability, and security.
- Provided technical leadership for server, network, and infrastructure operations while maintaining service continuity and security controls.
Experience
One Twilio Risk Management Framework
Identity and Secure API Modernization for Enterprise Applications
Education
Master's Degree in Information Systems Security
Concordia University - Montreal, QC, Canada
Bachelor's Degree in Electrical Engineering | Telecommunication
University Concordia - Montreal, QC, Canada
Certifications
Certified Information Security Manager
ISACA
Certified Information Systems Security Professional
ISC2
Skills
Tools
Claude, Microsoft Copilot, OWASP Zed Attack Proxy (ZAP), Postman, Checkmarx, IBM Security AppScan, SonarQube, Hyper-V, VMware vSphere, System Center Configuration Manager (SCCM), VMware, Wireshark, VPN
Languages
SAML, Python, C++, Java
Frameworks
AI Risk Management Framework, OAuth 2, Windows PowerShell
Paradigms
DevSecOps, Penetration Testing, Security Software Development, Role-based Access Control (RBAC), HIPAA Compliance, Security Orchestration, Automation, and Response (SOAR)
Platforms
Amazon Web Services (AWS), Azure, Burp Suite, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI)
Industry Expertise
Cybersecurity
Storage
Storage Area Networks (SAN)
Other
Secure Software Development Lifecycle (SSDLC), Incident Response, CI/CD Pipelines, Infrastructure as Code (IaC), Microsoft Sentinel, Multi-cloud Security, MITRE ATT&CK, Cloud Workload Protection (CWP), Cloud Security Posture Management (CSPM), Zero Trust, Identity & Access Management (IAM), IT Security Assessment, Governance, Vulnerability Management, Network Security, Application Security, AI Trust, Risk and Security Management (AI TRiSM), IT Security, Enterprise Security Architecture, AWS Identity and Access Management, Security Operations Centers (SOC), Information Security Governance, Information Security Program Development and Management, Information Security Incident Management, Risk Management Framework (RMF), AWS Cloud Security, Azure Cloud Security, MITRE ATLAS, Incident Management, Cybersecurity Program Design, Enterprise Risk Management (ERM), AI Security, NIST AI RMF, ISO 31000, Risk Governance, Security Architecture, PCI DSS, SOC 2, ISO 27001, CIS Benchmarks, GRC, OpenAI ChatGPT, Google Gemini, AI Risk Assessment, Threat Modeling, Table Top Exercise, Risk Assessment, TCP/IP, OSI Model, Routing and Switching Protocols, Multiprotocol Label Switching (MPLS), Network Design, VoIP, Wireless Networks, LTE/Cellular Networks, Protocol Engineering, Telecommunications Infrastructure, Real-time Embedded Systems, Lunix/Unix, Signal Processing, Digital Signal Processing, Network Performance Analysis, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), OWASP Top 10, Nikto, SQLMap, PASTA, STRIDE, Semgrep, Trivy, Gitleaks, Software Composition Analysis (SCA), Aqua Security, Supply Chain Security, Snyk, SBOM, IDS/IPS, Data Loss Prevention (DLP), Patch Management, vCenter, Network Segmentation, Firewalls, ASA Firewalls, Dell PowerEdge Servers, Cisco Switches, Cisco Routers, Access Points, Dynamic Host Configuration Protocol (DHCP), Risk & Compliance, Vulnerability Assessment, Web Applications, OpenID Connect (OIDC), Identity Federation, Microsoft Conditional Access, Data Security, Endpoint Detection and Response (EDR), Security, Threat Analytics, Offensive Security, Tactics, Techniques, and Procedures (TTP), Network Access Control, Network Engineering, Wireless Networking, Network Monitoring, Network Security Monitoring, Cloud Security, SecOps, Risk Management, NIST, ISO 9001, Cryptography, PHI, HIPAA
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring