I help organizations assess risk, strengthen security and compliance programs, navigate regulatory frameworks, and turn requirements into practical, measurable controls.
Hands-on experience in third-party risk, SOC 2 audits, information security risk management, GRC platforms, and compliance automation — bridging governance requirements and technical implementation.
I am a GRC and compliance professional with 4+ years of experience spanning third-party risk management, security questionnaires, SOC 2 audits, information security risk management, security assessments, governance, and compliance operations.
That work has included SOC 2, ISO/IEC 27001, NIST CSF, NIST SP 800-53, CMMC, HIPAA, privacy, and AI governance — coordinating audits end to end, collecting evidence, mapping controls, assessing gaps, and tracking remediation.
I work at the intersection of governance and technology: translating security requirements into practical controls, preparing teams for audit, identifying and managing risk, and using automation where it makes GRC programs more efficient and measurable.
I build systems that help organizations collect evidence, map controls, monitor compliance, and enforce governance requirements.
How I Work
GRC as an operating function — not a list of frameworks.
IdentifyRisks, regulatory requirements, control needs, vendor exposure
How I apply technical skills to GRC problems — evidence automation, control enforcement, and governance knowledge.
GRC + Cloud Security + Compliance Automation
HIPAA-Compliant Healthcare API Governance Pipeline
CI: gated
Hardened a patient-intake API to HIPAA Security Rule standards: customer-managed KMS, multi-region CloudTrail, and an S3 Object Lock evidence vault — then enforced the controls in CI.
Controls
Terraform baseline, 6 OPA/Rego policies with tests, OSCAL control-to-code mapping.
Assurance
Conftest fail-closed gate. Cosign keyless signing into the evidence vault, including on failing runs.
Lesson
Identified and remediated a live credential-exposure finding, including key rotation and repository hardening.
Classify → extract → structure → score pipeline for SOC 2 reports and vendor questionnaires, with page-level evidence citations.
TPRMSOC 2
DoD Supply Chain
CMMC Level 2 as Code
Planned
Map CMMC L2 practices to Terraform/OPA enforcement. Distinct from the CMMC Level 1 gap assessment under Experience.
CMMCNIST 800-171
Cloud Compliance
FedRAMP Evidence-as-Code
Planned
Planned exploration of FedRAMP Rev. 5, OSCAL-based control implementation, automated cloud evidence collection, and policy-as-code validation. Not professional FedRAMP experience.
FedRAMPOSCAL
Writing
No-code and low-code GRC automation — the other end of the same operating model.
GRC Engineering Club — Augusta Chapter. Co-founded a regional community for GRC, audit, and compliance professionals across the CSRA, connecting practitioners around Fort Gordon’s Army Cyber Command, the Signal Corps, and the Georgia Cyber Innovation & Training Center.
Global Ambassador, USA
Global Council for Responsible AI. Public education and community engagement on responsible AI, AI risk awareness, and governance — not product engineering.