Toyeeb Atanda

Toyeeb Atanda

GRC Engineer & AI Governance

EU AI Act · ISO/IEC 42001 · NIST 800-53 · HIPAA · SOC 2 · OPA/Rego

I build the systems auditors check. Then I audit them.

Nine audits at 90%+. A GRC charter from zero. Five orgs through HISPI’s Trusted AI Model. CGE-P · CGE-AUD · three ISO Lead Auditor credentials. Shipped as Terraform, OPA, and CI evidence you verify — not trust.

About

Genpact taught me what it looks like when controls pass review and fail reality — nine audits, fifty-plus evidence artifacts mapped to requirements, and the same gap every time: true on paper, unverifiable in production. CDIC taught me to stand up governance when there is no playbook. HISPI taught me AI adoption stalls when frameworks stay in slides. Same fix in every role: move the control into the pipeline.

That’s Argus gating deploys on EU AI Act findings, a HIPAA API where six OPA policies have tests and CI signs the evidence, NISTBOT answering from indexed source instead of guessing. Off the clock, I co-founded the Augusta GRC Engineering Club chapter — a regional bench for engineers and auditors in the CSRA, anchored around Fort Eisenhower’s Army Cyber Command and the people who rotate through both sides of the audit.

Genpact → CDIC → HISPI Compliance analyst roots: 9 audits at 90%+ compliance, then built a GRC operating charter for an 8-person team from scratch.
HISPI — Project Cerebellum Adoption & Partnership Co-Lead. Guided 5+ organizations through AI governance integration under the Trusted AI Model.
VP, GRC Engineering Club — Augusta Co-founded the chapter serving the CSRA's dense cyber community around Fort Eisenhower's Army Cyber Command.

Projects

Open-source compliance-as-code work. Cards link out to GitHub; the README in each repo is the deep dive. For the ones that ship through CI, the evidence trail is cryptographically signed — you're welcome to verify yourself.

Roadmap

Planned next.

TPRM

Vendor Compliance Document Intelligence

Planned

Classify → extract → structure → score pipeline for SOC 2 reports and vendor questionnaires, with page-level evidence citations feeding a risk register.

TPRMMCP
DoD Supply Chain

CMMC Level 2 as Code

Planned

Mapping all 110 CMMC L2 practices to Terraform/OPA enforcement, extending the same compliance-as-code pattern into the DoD supply chain.

CMMCNIST 800-171

Writing

Not every compliance workflow needs Terraform. These two show the other end of the spectrum.

Skills

Cloud
AWS (S3, KMS, CloudTrail, Security Hub, IAM) GCP (Workload Identity Federation, Org Policy) Azure (Entra ID, Policy, Key Vault)
IaC & Policy as Code
TerraformOPA/Rego Conftesttfsec
CI/CD & Evidence
GitHub ActionsCircleCI Cosign keyless signingS3 Object Lock
Machine-Readable Compliance
OSCALcompliance-trestle
Frameworks
NIST 800-53HIPAASOC 2 PCI DSSEU AI ActNIST AI RMF ISO/IEC 42001 · 27001 · 27701
Languages & AI Tooling
Python (boto3)HCLBash Claude CodeCursorMCP

Certifications

CGE-PCertified GRC Engineer — Practitioner
CGE-AUDCertified GRC Engineer — Auditor Specialty
ISO/IEC 42001:2023Lead Auditor — AI Management Systems
ISO/IEC 27701:2025Lead Auditor — Privacy Information Mgmt
ISO/IEC 27001:2022Lead Auditor — Information Security Mgmt
CompTIA Security+ ceSecurity
ServiceNow CSACertified System Administrator
Azure AI FundamentalsMicrosoft
Azure FundamentalsMicrosoft
Azure Security, Compliance & IdentityMicrosoft
Azure Data FundamentalsMicrosoft
Securiti AI Security & GovernanceSecuriti

Leadership

Vice President

GRC Engineering Club — Augusta Chapter. Co-founded the Augusta chapter to build a regional community for engineers, auditors, and compliance professionals across the CSRA.

Global Ambassador, USA

Global Council for Responsible AI. Championing public awareness and education on responsible AI, activating local and digital communities.

Connect

Open to GRC Engineer, AI Governance Engineer, and Cloud Security/Compliance roles.