Sign in to view Munya’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Munya’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Melbourne, Victoria, Australia
Sign in to view Munya’s full profile
Munya can introduce you to 10+ people at Origin Energy
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
2K followers
500+ connections
Sign in to view Munya’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Munya
Munya can introduce you to 10+ people at Origin Energy
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Munya
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Munya’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Activity
2K followers
-
Munya Mufambisi shared thisWe're hiring in the Appsec team! The role is great, the team is great, and I need to fill it before my boss asks me about it in our next 1:1. Help. Share.
-
Munya Mufambisi shared thisReposting, because the right person for this hasn't seen it yet and I refuse to accept otherwise. Hit me up!
-
Munya Mufambisi reposted thisWe’re hiring 🌱 Protect critical infrastructure while making a meaningful impact. 💻 Join a collaborative, experienced team 🛠 Modern tools and varied, engaging work 📍 Brisbane or Melbourne Link below:
-
Munya Mufambisi shared thisIf you know anyone interested - Dilshan's hiring.Munya Mufambisi shared thisHiring again for x3 gun full stack developers to work in the digital service stream.
-
Munya Mufambisi shared thisMy teams hiring! Hit me up if you or anyone you know is interested.
-
Munya Mufambisi shared thisAI doesn't introduce new security problems. It inherits old ones. Every "new" AI security threat has an appsec ancestor. Prompt injection? That's SQL injection with a conversational front end. Insecure tool invocation? Command injection dressed up in natural language. The underlying logic exactly the same. Whats changing is the attack surface with natural language as an input vector. The vulnerability classes themselves are not new. So the path forward isn't to build a new security discipline from scratch. It's proven basics such as least privilege, input validation, trust boundary enforcement, defence in depth. These principles hold. They jmust be re-expressed for the AI world `agents.lock` is a great example of this thinking in action. It takes a concept every engineer already understands, dependency locking (package-lock.json, Gemfile.lock), and applies it to agent capability manifests. What tools can this agent actually invoke? Has that surface been explicitly reviewed and pinned? Simple question. Proven pattern. Applied to a new context. The instinct to treat AI security as a foreign domain risks reinventing the wheel while ignoring wheels that already roll. Disciplined analogy beats novelty-seeking. Find the appsec ancestor. Apply what works. Adapt.Munya Mufambisi shared thisI've been staring at this problem for few weeks and I want to see if it lands with anyone else. We solved dependency pinning years ago. We solved build reproducibility. We solved artifact signing. But right now, two engineers on the same team can use completely different AI agent setups, different models, different skills, different tool connections, commit to the same repo, and there is nothing anywhere that records or enforces the difference. The agent session ends and so does the context. The commit just says who pushed it. As we move toward agents reviewing other agents' code, this feels like it matters a lot more than people realize. I've been thinking about what maybe an "agent.lock" could solve and would need to look like for possible review reasoning and build reproducibility. Not sure I have the full answer yet, but writing up what I've got so far. Would love to hear if this problem resonates with anyone else. Blog - https://lnkd.in/gKTXjsX4
-
Munya Mufambisi shared thisModels work towards objectives, creatively subverting roadblocks which are sometimes guardrails you’d want assurance on 😬
-
Munya Mufambisi shared thisMy team’s hiring. If you’re interested, hit me up. If you know someone interested, hit me up. If someone you know knows someone interested… you know what to do. while (true) { refer(); }
-
Munya Mufambisi shared thisOf AI code reviews: https://lnkd.in/ghdWjmQS
-
Munya Mufambisi liked thisMunya Mufambisi liked thisWas not having the best day - lost my earbud case, almost missed the ferry, tech didn't work, got stuck in a project, yadda yadda yadda. Then I got back to my car and found this note taped to my drivers side door, with my earbud case stuck to it. Big thanks to folks who do the kind gesture. And may this good Samaritan have the best year - they sure made my whole week!
-
Munya Mufambisi liked thisMunya Mufambisi liked thisEvery day's a learning day! 🤓 Last week I had the opportunity to hear from James Ng and take part in the Melbourne ISACA Breach Ready workshop, where we explored micro segmentation in a practical, hands-on environment. A big thank you to James, Natalie Hingco Perez, Wayne Rodrigues, and Chathura Abeydeera GAICD for giving up your time and putting together such an eye-opening session. It was great to see how organisations can use tools like ColourTokens to strengthen cyber resilience, reduce attack paths, and help prevent lateral movement. Always appreciate the opportunity to learn something new and to connect with the cyber community. Cheers ISACA Melbourne Chapter 🫶🤩🫶
-
Munya Mufambisi liked thisI'm looking forward to speaking at Nexthink Experience and connecting with digital workplace and IT leaders from around the world. If you'll be there, let me know, or if you're still considering attending, get in touch for a discounted registration code.
-
Munya Mufambisi liked thisMunya Mufambisi liked thisToday Origin reported its FY26 results. Strong cash generation and a healthy balance sheet enabled us to keep investing and deliver consistent returns to shareholders. There were highlights right across the business, including growing our customer base, outstanding delivery of our large-scale battery projects, and safe and reliable operation of our electricity and gas assets which underpinned reliable energy supply. These outcomes reflect the hard work of our people who are relentlessly focused on delivering for our customers, communities, and the planet. Thank you to everyone at Origin who contributed to this result. Find out more: https://lnkd.in/dr9gH-3T
-
Munya Mufambisi liked thisMunya Mufambisi liked thisCongratulations to Chirag D Joshi and the ISACA Sydney Chapter team on running a fantastic conference! I had the chance to speak about autonomous AI SOC operations, hang out with all the cool kids, and be the unofficial official photographer. What a great event! Nivedita Newar Gergana Winzer Roma S Natasha Passley Suhaas Madhyastha
-
Munya Mufambisi liked thisMunya Mufambisi liked thisLate in sharing this incredible news and milestone with you all, so consider this a “Flash Back Friday” post… I made Forrester’s 2025 Winner’s Circle and here’s my award to prove it. It actually just came in the mail this week 😍💚🏁 #MillionCashRace #BornHustler #WomenInSales #Forrester
-
Munya Mufambisi liked thisMunya Mufambisi liked thisI’m hiring a full stack dev (with a lean towards backend) for my team that looks after Identity and Authentication (plus a few other things). If you are interested in the role, please apply below. If you know someone who you think might be interested, please forward to them. Thanks.
Experience & Education
-
Origin Energy
**** ** *********** * ******* ********
-
*** ******
***** ******** ******* * ***** ********** ************ ***********
-
***
******* **** * ********* ******* * ********** * *********** ********
View Munya’s full experience
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Licenses & Certifications
Publications
Recommendations received
9 people have recommended Munya
Join now to viewView Munya’s full profile
-
See who you know in common
-
Get introduced
-
Contact Munya directly
Other similar profiles
-
Richard L.
Richard L.
With over 14 years of experience in cyber security and technology risk management in various industries, I am a seasoned leader who can design, implement, and manage secure and resilient solutions for complex business challenges. I have a proven track record of achieving security certifications, such as ISO27001 and SOC2, and delivering security operations and identity solutions for global and local products and services.<br><br>My mission is to create a world where people can trust and benefit from the power of data, while protecting their privacy and security. I have extensive experience in leading security, DevOps and IT teams, communicating with senior stakeholders, and mentoring others. I am currently open to opportunities where I can leverage my skills and knowledge to help businesses achieve their goals and vision.
2K followersSydney, NSW
Explore more posts
-
Risk Management
28K followers
#RiskManagement "Critical infrastructure (CI) continues to be a target for state-sponsored cyber actors, cybercriminals and hacktivists. This is due to the sensitive data CI organisations hold and its role in providing services that support Australia’s national resilience, sovereignty and prosperity. " #security #securityriskmanagement #securitymanagement #securityrisks #enterprisesecurity #cybersecurity #physicalsecurity #informationsecurity #digitalsecurity #securityoperations #enterprisesecurityriskmanagement #securityassessment #intelligence #threatlintelligence #risk #riskmanagement #safety #safetyfirst #safetymanagement #safetyassessment #safetyrisks #safetyculture #safetyanalysis #personalsafety #workplacesafety #healthandsafety #hazard #danger #peril #threat #PPE #protectivesafety #workplacesafety #risk #risks #enterpriserisk #enterprisesecurityriskmanagement #intelligence #threatlintelligence #riskmanagement #riskanalysis #riskassessment #riskmanagementframework #operationalriskmanagement #projectriskmanagement #projectrisk #operationalresilience #resilience #operationalrisk #riskintelligence #governance #crisis #crisismanagement #complexity #chaos #crisisleadership #crisisplan #crisismanagementplan #stress #governance #decisionmaking #riskmanagement #riskinformed #securitymanagement #securityriskmanagement #resilience #humanfactors #emergency #disaster #emergencyresponse #travelsecurity #travelsafety #travel #businesstravel #tourism #travelrisks #travelriskmanagement
3
1 Comment -
Synergy Point Group
71 followers
Some key highlights from Australian Signals Directorate (ASD)'s Cyber Threat Report 2024–2025: 1. There is a significant rise in cyber incidents and reports: The Australian Cyber Security Centre (ACSC) reported that in during 2024-2025 they have responded to over 1,200 major cybersecurity incidents which is a 11% increase from the previous year. 2. There is a steep rise in the financial impact due to cybercrimes: For businesses, the average loss due to cybercrimes is on the rise, Small businesses lost up to $56,571 a 14% increase from last year, Medium business lost up to $97,166 a 55% increase, and Large businesses lost up to $202,691 a 221% increase. It was also reported that an individual average self reported loss was $36,633 3. Critical infrastructure under increasing threat: Critical infrastructures have received notifications of 190 potential malicious cyber activity impacting their network which is a 111$ increase from last year. The Top 3 most common types of activity which led to infrastructure related incidents were: Scanning or Reconnaissance making up 41% DoS/DDoS making up 31% Phishing making up 20% 4. Credential compromise, email attacks and phishing remain the main methods of attack: It was reported that email compromise with no direct financial loss accounted for ~19% of business reports, Business email compromise with financial loss ~15%, identity fraud ~ 11% and phishing emails remains one of the most common attack methods. 5. New technologies are amplifying the risk like AI The report also warns the rise in the use of Generative AI by cybercriminals as they use these tools to automate the analysis of extensive datasets which allows them to find vulnerabilities, they also use generative AI to create content like videos, text, fake voices, websites etc. to help them trick their target easier. 💡 The big moves organisations must take: a. Implement Effective event logging - You can't defend what you can't see b. Manage legacy IT risks - Legacy technology lets threats thrive c. Effective Third-Party Risk Management (TPRM) - Shut the back door, choose sercure and verifable technologies d. Start preparing for Post Quantum Cryptography (PQC) more details: https://lnkd.in/gCVf9fSq
7
-
Jim Tora
Datacom • 5K followers
For someone who has worked in the financial services sector across the Pacific including NZ, the managing of technology and cybersecurity risk exist on enterprise platforms. These platforms are not available for the small to medium businesses and even to government agencies due to the high cost. Excel has been the go to tool for risk registers and management of risk. Whilst other platforms targeting SMEs exist I felt a more tailored one for the Pacific was needed. So for the last few months maybe a year I've been putting together this light weight GRC tool called /thatsit risk with the help of Ai tools. It is now LIVE and ready. Feedback welcome. app.thatsitconsultants.com
15
1 Comment -
Harris Security Management
1K followers
Statement by the Director-General New Zealand Security Intelligence Service This statement relates to security issues in the New Zealand context. It reinforces the concerns raised by partner agencies in Australia and strategic security risk management consultancies such as Harris Security Management. One important issue typically missed by executives relates to the risk of threats and dynamics of the broader security environment reaching into and gaining hold within organisations across the spectrums of government, commercial, education, arts and not-for-profit workplaces. Social cohesion as an empowering factor in developing and sustaining positive corporate culture is seriously challenged when political activism occurs in the workplace and in some instances, this includes intimidation of colleagues. This is not a theory; it is for many organisations ‘the elephant in the room’. We know this from our work with clients. When political activism in the workplace occurs, there are consequences for example: · loss of good personnel escaping to ‘safer’ organisations · diminished attractiveness to potential employees (the ‘word’ gets around) · difficult relationship management with external stakeholders · loss of trust, innovation, collaboration, commitment and performance · loss of investment in personnel development · reduction of safety and security standards · loss of corporate resilience · increase in sick leave · elevation of the risk of psychosocial claims. Organisations need to be strategic, transparent and honest to identify and effectively manage intimidation to conform with the agenda of internal political activists and not let it become engrained. Failure to do so will result in a toxic work environment. Delay in facing this unhealthy situation is not an option. Determined leadership at the top is absolutely required for corporate hygiene. If you have concerns regarding these issues for your organisation, supply chain or 3rd party management services and want strategic clarity and solutions, please contact us. Read the statement: https://lnkd.in/g3n2KXpx Please follow us on LinkedIn - https://lnkd.in/etGU_9pC Harris Security Management – Trusted, expert and independent security risk management consultants since 1983. www.harris.com.au Declaration: We appreciate and benefit from AI. However, we do not use AI to generate our blogs, posts, reports or specifications. We believe in professional curiosity and integrity, human creativity and the protection of intellectual property. Proud Corporate Partner with the Protective Security Network. © Harris Security Management, March 2026. #humanresourcemanagement #workplacerelations #psychosocialhazard #enterpriseriskmanagement #companydirector
-
Patrick Gleadhill CPEng (Elec, ITEE, Cyber) RPEQ/V
SAFEgroup Automation (SGA) • 2K followers
📢 The Australian Signals Directorate has released CI Fortify. A new framework providing practical, high-level cybersecurity guidance to help critical infrastructure (CI) operators strengthen their operational technology (OT) resilience during crisis or disruption. 🧩 What it is CI Fortify sets out clear actions to ensure essential services can continue even under sustained cyberattack or system isolation. 🎯 Why it exists Australia’s Critical Infrastructure remains a prime target for both state-sponsored and criminal actors. These systems were never designed to endure today’s cyber threats, making proactive resilience a national priority. ⚙️ What it requires CI Fortify challenges operators to: 🔹 Isolate vital OT systems for up to 3 months while maintaining operations. 🔹 Rapidly rebuild those systems from trusted backups. Preparation steps include: 1. Maintaining a current OT asset inventory 2. Identifying vital systems critical to service continuity 3. Defining isolation points and manual contingency workflows Don't wait for a cyber incident to be the first time in verifying operational resilience. In my recent presentation 'Safeguarding water utilities: From Reliability to Resilience' 👉 "Confidence in resilience comes from experience. Test and verify your controls — assumptions are never assurance." 💪 Who's up for the CI Fortify Challenge?? For more information on CI Fortify can be found here: https://lnkd.in/gQ9Z9iQs https://lnkd.in/gknZfqCX #CyberSecurity #OperationalTechnology #CriticalInfrastructure #Resilience #ASD #CIFortify #Australia #EA #CyberEngineer
32
-
McGovern Consulting Group, LLC
416 followers
The cheapest time to fix MIP security is before it becomes an audit question. Many teams inherit security settings that were built one request at a time. It works until it does not. Then it turns into access confusion, role creep, and an audit trail that takes too long to explain. MCG Lunch and Learn (60 minutes) Topic: MIP Security Checkup, Users, Groups, Advanced, Audit Trails February 25, 2026, 1:00 PM to 2:00 PM EST $39 per session $299 for 12 sessions with membership, save over 35% For nonprofit and mission-driven organizations using MIP Accounting. Not for teams that are not on MIP. Register: https://lnkd.in/enCdZUhz #mipaccounting #nonprofitfinance #internalcontrols #auditreadiness
1
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More