I build security and compliance programs that work in the real world.
I work at the intersection of GRC, TPRM, audit, security, and AI governance. I turn complex requirements into practical controls, repeatable workflows, and evidence that teams can actually use.
Compliance should not be a checklist. It should be evidence-backed, measurable, automated where possible, and built into how organizations operate.
GRC Engineering
Automation and workflows that cut repetitive compliance work, improve evidence collection, strengthen control monitoring, and make GRC faster to run.
Security, Audit & TPRM
SOC 2, ISO 27001, ISO 27701, NIST CSF, NIST 800-53, HIPAA, and CMMC translated into practical risk and control programs, including audits, gap assessments, and vendor reviews.
AI Governance
Risk assessment, control mapping, evidence requirements, human oversight, and responsible AI practice applied to the systems organizations actually deploy.
The goal: controls that don’t just exist on paper, but can demonstrate that they work.
I am a GRC engineer and auditor with 4+ years of experience spanning third-party risk management, security questionnaires, SOC 2 audits, information security risk management, security assessments, governance, and compliance operations.
That work has included SOC 2, ISO/IEC 27001, NIST CSF, NIST SP 800-53, CMMC, HIPAA, privacy, and AI governance: coordinating audits end to end, collecting evidence, mapping controls, assessing gaps, and tracking remediation.
I work at the intersection of governance and technology: translating security requirements into practical controls, preparing teams for audit, identifying and managing risk, and using automation where it makes GRC programs more efficient and measurable.
I build systems that help organizations collect evidence, map controls, monitor compliance, and enforce governance requirements, so the operating loop and the engineering loop produce the same audit trail.
Projects
How I apply technical skills to GRC problems: evidence automation, control enforcement, and governance knowledge.
GRC + Cloud Security + Compliance Automation
HIPAA-Compliant Healthcare API Governance Pipeline
CI: gated
Hardened a patient-intake API to HIPAA Security Rule standards: customer-managed KMS, multi-region CloudTrail, and an S3 Object Lock evidence vault, then enforced the controls in CI.
Controls
Terraform baseline, 6 OPA/Rego policies with tests, OSCAL control-to-code mapping.
Assurance
Conftest fail-closed gate. Cosign keyless signing into the evidence vault, including on failing runs.
Lesson
Identified and remediated a live credential-exposure finding, including key rotation and repository hardening.
First-pass risk assessment for AI agents: score, control gaps, evidence requests, and a remediation plan, with the language model barred from deciding anything that has to be defended.
Built
Self-hosted n8n workflow. Deterministic engine scores Impact × Likelihood × Exposure; the model writes analysis and summaries only.
Governance
13-control catalog, evidence gaps with named owners, TPRM branch for third-party systems. Framework mappings are illustrative, not a certified crosswalk.
Decision
Does not approve the system. Human governance review stays required.
Turns security questionnaire answers into a ledger of customer promises, flags where those promises contradict each other, and checks whether vendor SOC reports still support them.
Built
Layout-agnostic extraction from questionnaires. Rule-based classification (commitment vs roadmap vs attestation). Cross-customer contradiction detection. Human approval before anything is tracked.
Evidence
CUECs from vendor SOC 2 / SOC 3 PDFs, mapped to promises with reviewer sign-off, then a per-customer ledger: SUPPORTED / AT RISK / UNPROVEN.
Limit
Sample questionnaires and observed evidence are synthetic. Live checks (GitHub 2FA, CloudTrail retention, Okta deprovisioning) are still on the roadmap.
GRC Engineering Club, Augusta Chapter. Co-founded a regional community for GRC, audit, and compliance professionals across the CSRA, connecting practitioners around Fort Gordon’s Army Cyber Command, the Signal Corps, and the Georgia Cyber Innovation & Training Center.
Global Ambassador, USA
Global Council for Responsible AI. Public education and community engagement on responsible AI, AI risk awareness, and governance.