Vendor Compliance Document Intelligence
PlannedClassify → extract → structure → score pipeline for SOC 2 reports and vendor questionnaires, with page-level evidence citations feeding a risk register.
EU AI Act · ISO/IEC 42001 · NIST 800-53 · HIPAA · SOC 2 · OPA/Rego
I build the systems auditors check. Then I audit them.
Nine audits at 90%+. A GRC charter from zero. Five orgs through HISPI’s Trusted AI Model. CGE-P · CGE-AUD · three ISO Lead Auditor credentials. Shipped as Terraform, OPA, and CI evidence you verify — not trust.
Genpact taught me what it looks like when controls pass review and fail reality — nine audits, fifty-plus evidence artifacts mapped to requirements, and the same gap every time: true on paper, unverifiable in production. CDIC taught me to stand up governance when there is no playbook. HISPI taught me AI adoption stalls when frameworks stay in slides. Same fix in every role: move the control into the pipeline.
That’s Argus gating deploys on EU AI Act findings, a HIPAA API where six OPA policies have tests and CI signs the evidence, NISTBOT answering from indexed source instead of guessing. Off the clock, I co-founded the Augusta GRC Engineering Club chapter — a regional bench for engineers and auditors in the CSRA, anchored around Fort Eisenhower’s Army Cyber Command and the people who rotate through both sides of the audit.
Open-source compliance-as-code work. Cards link out to GitHub; the README in each repo is the deep dive. For the ones that ship through CI, the evidence trail is cryptographically signed — you're welcome to verify yourself.
Shipped or in progress. Each card links to the GitHub repo.
AI governance compliance-as-code engine. Classifies AI systems under the EU AI Act, crosswalks controls across NIST AI RMF and ISO/IEC 42001, and gates deployment in CI on critical findings.
Agentic retrieval agent that answers NIST SP 800-53 questions from a grounded, indexed source instead of guessing — extended into a standalone MCP server callable from Claude Desktop, Cursor, or Claude Code.
HIPAA-controlled patient intake API: Terraform baseline, 6 OPA/Rego policies with tests, a signed CI/CD evidence pipeline, and OSCAL control-to-code mapping. Includes a real remediated credential-exposure incident.
Compliant-by-default Terraform modules, keyless OIDC/Workload Identity Federation authentication, and OSCAL documentation across AWS and GCP.
Planned next.
Classify → extract → structure → score pipeline for SOC 2 reports and vendor questionnaires, with page-level evidence citations feeding a risk register.
Mapping all 110 CMMC L2 practices to Terraform/OPA enforcement, extending the same compliance-as-code pattern into the DoD supply chain.
Not every compliance workflow needs Terraform. These two show the other end of the spectrum.
A no-code Zapier pipeline: AI Incident Database RSS → severity classification → Slack alerts + a live risk register.
A beginner-friendly AI governance base: linked inventory, risk register, and controls with a compliance dashboard.
GRC Engineering Club — Augusta Chapter. Co-founded the Augusta chapter to build a regional community for engineers, auditors, and compliance professionals across the CSRA.
Global Council for Responsible AI. Championing public awareness and education on responsible AI, activating local and digital communities.
Open to GRC Engineer, AI Governance Engineer, and Cloud Security/Compliance roles.