Argus
CI: passingAI governance compliance-as-code engine. Classifies AI systems under the EU AI Act, crosswalks controls across NIST AI RMF and ISO/IEC 42001, and gates deployment in CI on critical findings.
I build the systems auditors check. Then I'm the auditor who checks them.
I build compliance the way modern teams build infrastructure: as code, tested in CI, with cryptographically signed evidence instead of screenshots, backed by four years in governance, risk, and compliance and three ISO/IEC Lead Auditor credentials across AI, privacy, and information security management.
I started in traditional compliance — auditing evidence, writing policy, coordinating assessments across regulatory frameworks. What I kept running into was the same gap everywhere: controls that were true on paper and unverifiable in practice. So I moved toward the part of the stack where that gap actually closes — Terraform, policy-as-code, and CI pipelines that sign their own evidence.
Today that means building AI governance systems that gate deployment on real EU AI Act findings, hardening HIPAA-regulated infrastructure until a policy engine can prove the controls hold, and leading the Augusta chapter of a national community built around exactly this shift — from GRC as paperwork to GRC as engineering.
Nothing here is a screenshot. Click through to the actual repo behind each card — real code, a real README, and for the ones that ship through CI, a cryptographically signed evidence trail you're welcome to verify yourself.
AI governance compliance-as-code engine. Classifies AI systems under the EU AI Act, crosswalks controls across NIST AI RMF and ISO/IEC 42001, and gates deployment in CI on critical findings.
Agentic retrieval agent that answers NIST SP 800-53 questions from a grounded, indexed source instead of guessing — extended into a standalone MCP server callable from Claude Desktop, Cursor, or Claude Code.
HIPAA-controlled patient intake API: Terraform baseline, 6 OPA/Rego policies with tests, a signed CI/CD evidence pipeline, and OSCAL control-to-code mapping. Includes a real remediated credential-exposure incident.
Compliant-by-default Terraform modules, keyless OIDC/Workload Identity Federation authentication, and OSCAL documentation across AWS and GCP.
Classify → extract → structure → score pipeline for SOC 2 reports and vendor questionnaires, with page-level evidence citations feeding a risk register.
Mapping all 110 CMMC L2 practices to Terraform/OPA enforcement, extending the same compliance-as-code pattern into the DoD supply chain.
Not every compliance workflow needs Terraform. These two show the other end of the spectrum.
A no-code Zapier pipeline: AI Incident Database RSS → severity classification → Slack alerts + a live risk register.
A beginner-friendly AI governance base: linked inventory, risk register, and controls with a compliance dashboard.
GRC Engineering Club — Augusta Chapter. Co-founded the Augusta to build a regional community for engineers, auditors, and compliance professionals across the CSRA.
Global Council for Responsible AI. Championing public awareness and education on responsible AI, activating local and digital communities.
Open to GRC Engineer, AI Governance Engineer, and Cloud Security/Compliance roles.