Kwaku Ampem Affram
Updated September 2026. Phone number on request.
Accra, Ghana · affram.dev@gmail.com · linkedin.com/in/kwaku-ampem-affram
Summary
CISA Associate and security-focused technology professional with experience in identity and access management (IAM), Active Directory, role-based access control, secure application development and IT operations within regulated financial institutions. Combines hands-on experience building enterprise IAM and performance management applications with knowledge of information systems auditing, internal controls, COBIT, security monitoring and business-process improvement. Holds degrees in computer science and psychology, providing technical and human-centred perspectives on technology risk, governance and organisational change.
Professional experience
- Built the administration interface for the CSD's enterprise IAM platform, covering user provisioning, application registration, role definition and permission assignment in an AD and SSO environment.
- Translated access-management requirements into standardised workflows, improving the consistency and traceability of access changes.
- Built the front end of a performance management system replacing an Excel-based balanced scorecard, reducing version-control and uncontrolled-edit risks.
- Assisted the infrastructure team with Hyper-V virtual machine setup and configuration, and gained exposure to Microsoft Sentinel security monitoring in an enterprise environment.
- Administered AD accounts and group policies for 50+ staff (joiners, movers and leavers; password policy) in line with internal access policy, under the supervision of the IT team.
- Logged and resolved around 15 incidents a day, and followed ITIL change-control procedures by raising and documenting changes for approval by the IT team.
Projects
- Translated Ghana's OTCMS licensing rules into system-enforced controls, including server-side blocking of Class A and B medicine sales on every transaction path, not just in the user interface.
- Designed role-based access with five roles and fourteen permissions (owner, licensed practitioner, sales clerk, inventory clerk and a read-only auditor), supporting segregation of duties in a small-shop setting.
- Implemented a database-enforced, append-only audit trail recording who performed each action, on what, and why, from first login.
- Built batch- and expiry-level stock traceability with first-expiry-first-out sales, quarantine of expiring stock, and disposal records carrying the FDA application reference and certificate of destruction.
- Delivered daily closing reports to shop owners by SMS and e-mail, covering takings, voids, payment methods, margin and sales by staff member.
- Designed for offline operation on a single shop PC, with automated nightly database backups, 30-day retention, an off-machine copy and a documented restore procedure.
- Implemented production-readiness features including structured logging, health checks, rate limiting, Dockerisation and automated test coverage.
- Applied secure-by-design practices including authorisation checks, auditability, input validation and OWASP-aligned API design.
- Modernised the legacy student information system, improving UI/UX, security and accessibility for 3,000+ stakeholders.
- Implemented multi-layered authentication (JWT, 2FA) with granular role-based access control.
- Designed secure API endpoints following OWASP guidelines and established comprehensive audit logging.
Education
Focus: digital forensics, cybercrime and risk management, IT audit, cryptography and security mechanisms, Python programming.
CGPA 3.15/4.0. Relevant coursework: computer forensics, system and network administration, network security, systems programming.
Relevant coursework: organisational psychology, industrial psychology.
Certifications
- February 2026
- CISA Associate, ISACA
Examination passed; the Associate designation is held while completing the experience requirement for full certification.
- February 2025
- Microsoft SC-900, Microsoft, Security, Compliance and Identity Fundamentals
- January 2020
- GSE Securities Certification, levels 1 to 4, Ghana Stock Exchange
Technical and risk competencies
Governance, risk and audit
Identity and access management
Application and API security
Security monitoring and operations
Systems development
Data and tooling
References available on request.