I turn security and compliance requirements into controls, evidence, and systems that work.
I’m a GRC professional and engineer bridging risk, compliance, audit, security, and technology. I translate frameworks and regulatory requirements into practical controls, automate evidence and compliance workflows, and build governance systems that teams can actually operate and auditors can verify.
I am a GRC engineer and auditor with 4+ years spanning third-party risk management, security questionnaires, SOC 2 audits, information security risk management, security assessments, governance, and compliance operations.
That work has included SOC 2, ISO/IEC 27001, NIST CSF, NIST SP 800-53, CMMC, HIPAA, privacy, and AI governance: coordinating audits end to end, collecting evidence, mapping controls, assessing gaps, and tracking remediation. Automation is used where it makes those programs more efficient and measurable.
Projects
Proof that the model works: requirements become controls, evidence, and systems, including GRC engineering that automates the loop.
GRC + Cloud Security + Compliance Automation
HIPAA-Compliant Healthcare API Governance Pipeline
CI: gated
Hardened a patient-intake API to HIPAA Security Rule standards: customer-managed KMS, multi-region CloudTrail, and an S3 Object Lock evidence vault, then enforced the controls in CI.
Controls
Terraform baseline, 6 OPA/Rego policies with tests, OSCAL control-to-code mapping.
Assurance
Conftest fail-closed gate. Cosign keyless signing into the evidence vault, including on failing runs.
Lesson
Identified and remediated a live credential-exposure finding, including key rotation and repository hardening.
First-pass risk assessment for AI agents: score, control gaps, evidence requests, and a remediation plan, with the language model barred from deciding anything that has to be defended.
Built
Self-hosted n8n workflow. Deterministic engine scores Impact × Likelihood × Exposure; the model writes analysis and summaries only.
Governance
13-control catalog, evidence gaps with named owners, TPRM branch for third-party systems. Framework mappings are illustrative, not a certified crosswalk.
Decision
Does not approve the system. Human governance review stays required.
Turns security questionnaire answers into a ledger of customer promises, flags where those promises contradict each other, and checks whether vendor SOC reports still support them.
Built
Layout-agnostic extraction from questionnaires. Rule-based classification (commitment vs roadmap vs attestation). Cross-customer contradiction detection. Human approval before anything is tracked.
Evidence
CUECs from vendor SOC 2 / SOC 3 PDFs, mapped to promises with reviewer sign-off, then a per-customer ledger: SUPPORTED / AT RISK / UNPROVEN.
Limit
Sample questionnaires and observed evidence are synthetic. Live checks (GitHub 2FA, CloudTrail retention, Okta deprovisioning) are still on the roadmap.
GRC Engineering Club, Augusta Chapter. Co-founded a regional community for GRC, audit, and compliance professionals across the CSRA, connecting practitioners around Fort Gordon’s Army Cyber Command, the Signal Corps, and the Georgia Cyber Innovation & Training Center.
Global Ambassador, USA
Global Council for Responsible AI. Public education and community engagement on responsible AI, AI risk awareness, and governance.