- Conducted AI governance and risk-framework gap assessments for 5+ client organizations against NIST AI RMF and ISO/IEC 42001, coordinating stakeholder interviews and delivering prioritized remediation recommendations.
- Led a 5-person working group driving Trusted AI Model adoption to a 50–70% rate, measured by monthly TAIMScore downloads and assessor workshop registration.
- Drafted and presented governance risk briefings and framework proposals to executive stakeholders across 5+ organizations.
Toyeeb Atanda
Governance, Risk & Compliance
I help organizations assess risk, strengthen security and compliance programs, navigate regulatory frameworks, and turn requirements into practical, measurable controls.
Hands-on experience in third-party risk, SOC 2 audits, information security risk management, GRC platforms, and compliance automation — bridging governance requirements and technical implementation.
At a Glance
About
I am a GRC and compliance professional with 4+ years of experience spanning third-party risk management, security questionnaires, SOC 2 audits, information security risk management, security assessments, governance, and compliance operations.
That work has included SOC 2, ISO/IEC 27001, NIST CSF, NIST SP 800-53, CMMC, HIPAA, privacy, and AI governance — coordinating audits end to end, collecting evidence, mapping controls, assessing gaps, and tracking remediation.
I work at the intersection of governance and technology: translating security requirements into practical controls, preparing teams for audit, identifying and managing risk, and using automation where it makes GRC programs more efficient and measurable.
I build systems that help organizations collect evidence, map controls, monitor compliance, and enforce governance requirements.
Experience
- Administered GRC and compliance automation platforms (Eramba, CSET) for evidence collection, control mapping, and audit readiness tracking, improving operational efficiency by 35%.
- Led a 5-person team performing ISO/IEC 27001 and CMMC gap assessments for 3 SME clients, improving compliance readiness 70% and delivering remediation plans to client leadership.
- Developed GRC playbooks, procedures, and runbooks that standardized governance and assessment workflows, reducing issue resolution time 20%.
- Implemented 15+ custom compliance monitoring rules across EDR, SIEM, and IAM to monitor control effectiveness, improving detection accuracy 40%.
- Developed and maintained security documentation, policies, standards, procedures, and runbooks, establishing the GRC operating charter for an 8-person team.
- Conducted third-party security and framework gap assessments (CMMC, ISO/IEC 27001, NIST CSF) across 6+ organizations, documenting 50+ control gaps and advising owners on remediation.
- Led a CMMC Level 1 gap assessment for a startup client, identifying control gaps and producing a prioritized remediation roadmap.
- Identified and prioritized vulnerabilities using Action1, coordinating remediation across 70+ endpoints and helping reduce outstanding critical/high-risk findings by 30%+.
- Designed and delivered cybersecurity awareness training to 50+ personnel, achieving 95%+ completion.
- Coordinated 9 internal and external audit engagements end to end — evidence requests, auditor communication, and remediation — sustaining a 90%+ compliance rate.
- Performed evidence collection and control mapping across 50+ audit artifacts, interviewing stakeholders across 8+ business and operational teams and helping reduce recurring findings by 20%.
- Supported an ISRM program aligned to NIST CSF: risk register, prioritization, risk acceptance, ownership, and remediation tracking, reducing risk exposure by 50%.
- Managed 20+ inbound client, regulatory, and security questionnaire requests per quarter, coordinating evidence from 6+ internal teams and delivering 95%+ of responses on or ahead of deadline.
How I Work
GRC as an operating function — not a list of frameworks.
GRC Expertise
Governance & Compliance
- Security policies, standards, and procedures
- Compliance program design
- Control mapping and governance documentation
- Audit readiness and regulatory requirements
Risk Management
- Information security risk management
- Risk identification, assessment, and ownership
- Risk registers and acceptance decisions
- Remediation tracking and executive risk reporting
Audit & Assurance
- Internal and external audit coordination
- Evidence collection and auditor communication
- Control testing and audit readiness
- Finding remediation management
Third-Party Risk
- Vendor security assessments
- Security questionnaires and evidence review
- Third-party control assessments
- Risk-based remediation
Security Assessments
- ISO/IEC 27001, 27701, and 42001
- NIST CSF, SP 800-53, and SP 800-171
- CMMC, HIPAA, PCI DSS, and SOC 2
- GDPR, EU AI Act, and NIST AI RMF
GRC Technology & Automation
- GRC platforms: ServiceNow, Eramba, CSET, OneTrust
- Evidence automation and control monitoring
- Policy-as-code, OSCAL, and cloud security
- Terraform and OPA/Rego where enforcement belongs in the pipeline
Frameworks & Standards
Security & Compliance
Privacy
AI Governance
Projects
How I apply technical skills to GRC problems — evidence automation, control enforcement, and governance knowledge.
HIPAA-Compliant Healthcare API Governance Pipeline
CI: gatedHardened a patient-intake API to HIPAA Security Rule standards: customer-managed KMS, multi-region CloudTrail, and an S3 Object Lock evidence vault — then enforced the controls in CI.
- Controls
- Terraform baseline, 6 OPA/Rego policies with tests, OSCAL control-to-code mapping.
- Assurance
- Conftest fail-closed gate. Cosign keyless signing into the evidence vault, including on failing runs.
- Lesson
- Identified and remediated a live credential-exposure finding, including key rotation and repository hardening.
ARGUS — AI Governance Compliance Engine
CI: passingCompliance-as-code for AI system inventories: classify risk, evaluate governance controls, and produce evidence before deployment.
- Governance
- EU AI Act classification with a control catalog crosswalked to NIST AI RMF and ISO/IEC 42001.
- Enforcement
- CI gate blocks merge on critical governance findings.
- Evidence
- Assessment report, findings register, Statement of Applicability, and SHA-256 integrity manifest.
NISTBOT — AI-Assisted Compliance Retrieval
RAG workflowA retrieval assistant for NIST SP 800-53 — grounded answers from source text instead of model guesses. Not a deployment gate.
- Built
- n8n workflow: Google Drive ingestion → embeddings → Pinecone → retrieval-backed answers.
- Evidence
- Documented workflow with verified example queries against NIST SP 800-53 Rev. 5.
Multi-Cloud Compliance Lab
CI: passingCompliant-by-default Terraform modules and keyless OIDC / Workload Identity Federation across AWS and GCP, with OSCAL documentation.
Planned Projects
Vendor Compliance Document Intelligence
PlannedClassify → extract → structure → score pipeline for SOC 2 reports and vendor questionnaires, with page-level evidence citations.
CMMC Level 2 as Code
PlannedMap CMMC L2 practices to Terraform/OPA enforcement. Distinct from the CMMC Level 1 gap assessment under Experience.
FedRAMP Evidence-as-Code
PlannedPlanned exploration of FedRAMP Rev. 5, OSCAL-based control implementation, automated cloud evidence collection, and policy-as-code validation. Not professional FedRAMP experience.
Writing
No-code and low-code GRC automation — the other end of the same operating model.
Technical Skills
Certifications
GRC / Audit
ISO Lead Auditor
Security / Technology
Leadership
Vice President
GRC Engineering Club — Augusta Chapter. Co-founded a regional community for GRC, audit, and compliance professionals across the CSRA, connecting practitioners around Fort Gordon’s Army Cyber Command, the Signal Corps, and the Georgia Cyber Innovation & Training Center.
Global Ambassador, USA
Global Council for Responsible AI. Public education and community engagement on responsible AI, AI risk awareness, and governance — not product engineering.
Let’s talk about GRC that holds up under audit.
Open to: GRC Analyst · Security Compliance · TPRM · Risk · GRC Consultant · GRC Engineering roles