Toyeeb Atanda
Toyeeb Atanda

Toyeeb Atanda

Governance, Risk & Compliance

I help organizations assess risk, strengthen security and compliance programs, navigate regulatory frameworks, and turn requirements into practical, measurable controls.

Hands-on experience in third-party risk, SOC 2 audits, information security risk management, GRC platforms, and compliance automation — bridging governance requirements and technical implementation.

Security Compliance Risk Management Audit & Assurance Third-Party Risk AI Governance GRC Engineering

At a Glance

4+ Years GRC & compliance experience
9 Audit engagements coordinated
6+ Organizations assessed
50+ Control gaps identified
20+ Security & regulatory requests per quarter
5+ Organizations supported in AI governance
70+ Endpoints coordinated for remediation
50+ Personnel reached through security awareness

About

I am a GRC and compliance professional with 4+ years of experience spanning third-party risk management, security questionnaires, SOC 2 audits, information security risk management, security assessments, governance, and compliance operations.

That work has included SOC 2, ISO/IEC 27001, NIST CSF, NIST SP 800-53, CMMC, HIPAA, privacy, and AI governance — coordinating audits end to end, collecting evidence, mapping controls, assessing gaps, and tracking remediation.

I work at the intersection of governance and technology: translating security requirements into practical controls, preparing teams for audit, identifying and managing risk, and using automation where it makes GRC programs more efficient and measurable.

I build systems that help organizations collect evidence, map controls, monitor compliance, and enforce governance requirements.

Experience

HISPI — Project Cerebellum Adoption & Partnership Co-Lead
  • Conducted AI governance and risk-framework gap assessments for 5+ client organizations against NIST AI RMF and ISO/IEC 42001, coordinating stakeholder interviews and delivering prioritized remediation recommendations.
  • Led a 5-person working group driving Trusted AI Model adoption to a 50–70% rate, measured by monthly TAIMScore downloads and assessor workshop registration.
  • Drafted and presented governance risk briefings and framework proposals to executive stakeholders across 5+ organizations.
RapidPaw Cyber Defense Cybersecurity GRC Consultant (Consulting Engagement)
  • Administered GRC and compliance automation platforms (Eramba, CSET) for evidence collection, control mapping, and audit readiness tracking, improving operational efficiency by 35%.
  • Led a 5-person team performing ISO/IEC 27001 and CMMC gap assessments for 3 SME clients, improving compliance readiness 70% and delivering remediation plans to client leadership.
  • Developed GRC playbooks, procedures, and runbooks that standardized governance and assessment workflows, reducing issue resolution time 20%.
  • Implemented 15+ custom compliance monitoring rules across EDR, SIEM, and IAM to monitor control effectiveness, improving detection accuracy 40%.
Cyber Defense and Intelligence Center GRC Specialist (Contract)
  • Developed and maintained security documentation, policies, standards, procedures, and runbooks, establishing the GRC operating charter for an 8-person team.
  • Conducted third-party security and framework gap assessments (CMMC, ISO/IEC 27001, NIST CSF) across 6+ organizations, documenting 50+ control gaps and advising owners on remediation.
  • Led a CMMC Level 1 gap assessment for a startup client, identifying control gaps and producing a prioritized remediation roadmap.
  • Identified and prioritized vulnerabilities using Action1, coordinating remediation across 70+ endpoints and helping reduce outstanding critical/high-risk findings by 30%+.
  • Designed and delivered cybersecurity awareness training to 50+ personnel, achieving 95%+ completion.

How I Work

GRC as an operating function — not a list of frameworks.

IdentifyRisks, regulatory requirements, control needs, vendor exposure
AssessGap assessments, questionnaires, risk assessments, audits
MapFrameworks → controls → evidence → owners
RemediatePrioritize gaps, assign owners, track closure
ValidateEvidence review, control testing, audit readiness
MonitorControl effectiveness, compliance status, risk change
ReportExecutive briefings, audit reporting, risk visibility

GRC Expertise

Governance & Compliance

  • Security policies, standards, and procedures
  • Compliance program design
  • Control mapping and governance documentation
  • Audit readiness and regulatory requirements

Risk Management

  • Information security risk management
  • Risk identification, assessment, and ownership
  • Risk registers and acceptance decisions
  • Remediation tracking and executive risk reporting

Audit & Assurance

  • Internal and external audit coordination
  • Evidence collection and auditor communication
  • Control testing and audit readiness
  • Finding remediation management

Third-Party Risk

  • Vendor security assessments
  • Security questionnaires and evidence review
  • Third-party control assessments
  • Risk-based remediation

Security Assessments

  • ISO/IEC 27001, 27701, and 42001
  • NIST CSF, SP 800-53, and SP 800-171
  • CMMC, HIPAA, PCI DSS, and SOC 2
  • GDPR, EU AI Act, and NIST AI RMF

GRC Technology & Automation

  • GRC platforms: ServiceNow, Eramba, CSET, OneTrust
  • Evidence automation and control monitoring
  • Policy-as-code, OSCAL, and cloud security
  • Terraform and OPA/Rego where enforcement belongs in the pipeline

Frameworks & Standards

Security & Compliance

SOC 2 ISO/IEC 27001 NIST CSF NIST SP 800-53 NIST SP 800-171 CMMC HIPAA PCI DSS

Privacy

ISO/IEC 27701 GDPR

AI Governance

ISO/IEC 42001 NIST AI RMF EU AI Act

Projects

How I apply technical skills to GRC problems — evidence automation, control enforcement, and governance knowledge.

GRC + Cloud Security + Compliance Automation

HIPAA-Compliant Healthcare API Governance Pipeline

CI: gated

Hardened a patient-intake API to HIPAA Security Rule standards: customer-managed KMS, multi-region CloudTrail, and an S3 Object Lock evidence vault — then enforced the controls in CI.

Controls
Terraform baseline, 6 OPA/Rego policies with tests, OSCAL control-to-code mapping.
Assurance
Conftest fail-closed gate. Cosign keyless signing into the evidence vault, including on failing runs.
Lesson
Identified and remediated a live credential-exposure finding, including key rotation and repository hardening.
HIPAAOPA/RegoOSCALCosign
AI Governance + Regulatory Compliance + Automation

ARGUS — AI Governance Compliance Engine

CI: passing

Compliance-as-code for AI system inventories: classify risk, evaluate governance controls, and produce evidence before deployment.

Governance
EU AI Act classification with a control catalog crosswalked to NIST AI RMF and ISO/IEC 42001.
Enforcement
CI gate blocks merge on critical governance findings.
Evidence
Assessment report, findings register, Statement of Applicability, and SHA-256 integrity manifest.
EU AI ActNIST AI RMFISO 42001
GRC Knowledge Automation

NISTBOT — AI-Assisted Compliance Retrieval

RAG workflow

A retrieval assistant for NIST SP 800-53 — grounded answers from source text instead of model guesses. Not a deployment gate.

Built
n8n workflow: Google Drive ingestion → embeddings → Pinecone → retrieval-backed answers.
Evidence
Documented workflow with verified example queries against NIST SP 800-53 Rev. 5.
NIST 800-53RAGn8n
Cloud Compliance Lab

Multi-Cloud Compliance Lab

CI: passing

Compliant-by-default Terraform modules and keyless OIDC / Workload Identity Federation across AWS and GCP, with OSCAL documentation.

AWSGCPOIDCOSCAL
View on GitHub →
Roadmap

Planned — not shipped.

TPRM

Vendor Compliance Document Intelligence

Planned

Classify → extract → structure → score pipeline for SOC 2 reports and vendor questionnaires, with page-level evidence citations.

TPRMSOC 2
DoD Supply Chain

CMMC Level 2 as Code

Planned

Map CMMC L2 practices to Terraform/OPA enforcement. Distinct from the CMMC Level 1 gap assessment under Experience.

CMMCNIST 800-171
Cloud Compliance

FedRAMP Evidence-as-Code

Planned

Planned exploration of FedRAMP Rev. 5, OSCAL-based control implementation, automated cloud evidence collection, and policy-as-code validation. Not professional FedRAMP experience.

FedRAMPOSCAL

Writing

No-code and low-code GRC automation — the other end of the same operating model.

Technical Skills

GRC Platforms
ServiceNowErambaCSETn8n
Cloud Security
AWS (S3, KMS, CloudTrail, Security Hub, IAM) GCP (Workload Identity Federation, Org Policy) Azure (Entra ID, Policy, Key Vault)
Compliance Automation
TerraformOPA/RegoConftest tfsecGitHub ActionsCosign S3 Object Lock
Machine-Readable Compliance
OSCALcompliance-trestle
Programming / Scripting
PythonHCLBash

Certifications

GRC / Audit

CGE-PCertified GRC Engineer — Practitioner
CGE-AUDCertified GRC Engineer — Auditor Specialty

ISO Lead Auditor

ISO/IEC 27001:2022Lead Auditor — Information Security Management
ISO/IEC 27701:2025Lead Auditor — Privacy Information Management
ISO/IEC 42001:2023Lead Auditor — AI Management Systems

Security / Technology

CompTIA Security+ ceSecurity
ServiceNow CSACertified System Administrator
Securiti AI Security & GovernanceSecuriti
Security, Compliance & IdentityMicrosoft
Azure FundamentalsMicrosoft
Azure AI FundamentalsMicrosoft
Azure Data FundamentalsMicrosoft

Leadership

Vice President

GRC Engineering Club — Augusta Chapter. Co-founded a regional community for GRC, audit, and compliance professionals across the CSRA, connecting practitioners around Fort Gordon’s Army Cyber Command, the Signal Corps, and the Georgia Cyber Innovation & Training Center.

Global Ambassador, USA

Global Council for Responsible AI. Public education and community engagement on responsible AI, AI risk awareness, and governance — not product engineering.

Let’s talk about GRC that holds up under audit.

Open to: GRC Analyst · Security Compliance · TPRM · Risk · GRC Consultant · GRC Engineering roles