Toyeeb Atanda

GRC Engineer & AI Governance

I build compliance the way modern teams build infrastructure: as code, tested in CI, with cryptographically signed evidence instead of screenshots. Dual-certified across both sides of the audit — I build the pipelines, and I assess them — backed by four years in governance, risk, and compliance and three ISO/IEC Lead Auditor credentials across AI, privacy, and information security management.

CGE-P CGE-AUD ISO/IEC 42001 Lead Auditor ISO/IEC 27701 Lead Auditor ISO/IEC 27001 Lead Auditor
About

From reviewing controls to engineering them

I started in traditional compliance — auditing evidence, writing policy, coordinating assessments across regulatory frameworks. What I kept running into was the same gap everywhere: controls that were true on paper and unverifiable in practice. So I moved toward the part of the stack where that gap actually closes — Terraform, policy-as-code, and CI pipelines that sign their own evidence.

Today that means building AI governance systems that gate deployment on real EU AI Act findings, hardening HIPAA-regulated infrastructure until a policy engine can prove the controls hold, and leading the Augusta chapter of a national community built around exactly this shift — from GRC as paperwork to GRC as engineering.

Genpact → CDIC → HISPI Compliance analyst roots: 9 audits at 90%+ compliance, then built a GRC operating charter for an 8-person team from scratch.
HISPI — Project Cerebellum Adoption & Partnership Co-Lead. Guided 5+ organizations through AI governance integration under the Trusted AI Model.
VP, GRC Engineering Club — Augusta Co-founded the chapter serving the CSRA's dense cyber community around Fort Eisenhower's Army Cyber Command.
Projects

Compliance you can verify, not just read about

Nothing here is a screenshot. Click through to the actual repo behind each card — real code, a real README, and for the ones that ship through CI, a cryptographically signed evidence trail you're welcome to verify yourself.

Built

Argus

CI: passing

AI governance compliance-as-code engine. Classifies AI systems under the EU AI Act, crosswalks controls across NIST AI RMF and ISO/IEC 42001, and gates deployment in CI on critical findings.

EU AI ActNIST AI RMFISO 42001
View on GitHub →

NISTBOT

Evidence: signed

Agentic retrieval agent that answers NIST SP 800-53 questions from a grounded, indexed source instead of guessing — extended into a standalone MCP server callable from Claude Desktop, Cursor, or Claude Code.

NIST 800-53MCPRAG
View on GitHub →

CGE-P Capstone

Score: 81.7%

HIPAA-controlled patient intake API: Terraform baseline, 6 OPA/Rego policies with tests, a signed CI/CD evidence pipeline, and OSCAL control-to-code mapping. Includes a real remediated credential-exposure incident.

HIPAAOPA/RegoOSCAL
View on GitHub →

Multi-Cloud Compliance Lab

CI: passing

Compliant-by-default Terraform modules, keyless OIDC/Workload Identity Federation authentication, and OSCAL documentation across AWS and GCP.

AWSGCPOIDC
View on GitHub →
Roadmap

Vendor Compliance Document Intelligence

Planned

Classify → extract → structure → score pipeline for SOC 2 reports and vendor questionnaires, with page-level evidence citations feeding a risk register.

TPRMMCP

CMMC Level 2 as Code

Planned

Mapping all 110 CMMC L2 practices to Terraform/OPA enforcement, extending the same compliance-as-code pattern into the DoD supply chain.

CMMCNIST 800-171
Writing

No-code & low-code GRC automation

Not every compliance workflow needs Terraform. These two show the other end of the spectrum.

Skills

The stack behind the repos

Cloud
AWS (S3, KMS, CloudTrail, Security Hub, IAM) GCP (Workload Identity Federation, Org Policy) Azure (Entra ID, Policy, Key Vault)
IaC & Policy as Code
TerraformOPA/Rego Conftesttfsec
CI/CD & Evidence
GitHub ActionsCircleCI Cosign keyless signingS3 Object Lock
Machine-Readable Compliance
OSCALcompliance-trestle
Frameworks
NIST 800-53HIPAASOC 2 PCI DSSEU AI ActNIST AI RMF ISO/IEC 42001 · 27001 · 27701
Languages & AI Tooling
Python (boto3)HCLBash Claude CodeCursorMCP
Certifications

Both sides of the audit

CGE-PCertified GRC Engineer — Practitioner
CGE-AUDCertified GRC Engineer — Auditor Specialty
ISO/IEC 42001:2023Lead Auditor — AI Management Systems
ISO/IEC 27701:2025Lead Auditor — Privacy Information Mgmt
ISO/IEC 27001:2022Lead Auditor — Information Security Mgmt
CompTIA Security+ ceSecurity
ServiceNow CSACertified System Administrator
Azure AI FundamentalsMicrosoft
Azure FundamentalsMicrosoft
Azure Security, Compliance & IdentityMicrosoft
Azure Data FundamentalsMicrosoft
Securiti AI Security & GovernanceSecuriti
Leadership

Building the community, not just the repos

Vice President

GRC Engineering Club — Augusta Chapter. Co-founded the Augusta to build a regional community for engineers, auditors, and compliance professionals across the CSRA.

Global Ambassador, USA

Global Council for Responsible AI. Championing public awareness and education on responsible AI, activating local and digital communities.

Connect

Let's talk about governance that executes

Open to GRC Engineer, AI Governance Engineer, and Cloud Security/Compliance roles.