I build security and compliance controls that execute in the pipeline—not just in policy documents.
Four years across audit, GRC, risk, and AI governance—now engineering those practices into automated controls with Terraform, OPA/Rego, CI/CD, and OSCAL, and evidence auditors can verify.
I build the systems auditors check. Then I audit them.
Controls Machine-readable control catalogs & OSCAL
Policy OPA/Rego with automated tests
Infrastructure Terraform baselines & cloud config
Validation CI/CD gates & Conftest policy checks
Evidence Signed artifacts &
Audit Controls you demonstrate—not merely claim
TerraformOPA/RegoGitHub ActionsOSCALCosignAWSGCP
About
Traditional GRC
Four years across governance, risk, compliance, and audit—from Genpact audit rooms in Kraków through cyber defense GRC at CDIC to AI governance adoption at HISPI. Assessments, gap analyses, control mapping, evidence review, and remediation against NIST, ISO, SOC 2, HIPAA, CMMC, and AI governance frameworks.
Security & Cloud
Controls can pass an audit and still fail in production. At CDIC, gap assessments and vulnerability remediation showed me compliance has to live in technical environments—identity, encryption, logging, and infrastructure—not policy binders alone.
GRC Engineering & AI Governance
I now turn those requirements into automated, testable, continuously verifiable controls—policy-as-code, CI/CD gates, signed evidence, and AI governance engines like ARGUS. Professional GRC experience first; engineering is how I make it hold.
What I Bring
Professional GRC depth and engineering execution—not one without the other.
GRC & Risk
Translate regulatory and framework requirements into actionable controls, assessments, gap analyses, and remediation plans.
Compliance Engineering
Turn controls into machine-readable policies, automated tests, CI/CD gates, and continuously generated evidence.
Cloud & Security
Apply compliance requirements across cloud infrastructure, identity, access, encryption, logging, and infrastructure-as-code.
AI Governance
Operationalize AI governance through risk classification, controls, assessments, oversight, and evidence.
Experience
HISPI — Project Cerebellum
Adoption & Partnership Co-Lead. Guided 5+ organizations through AI governance integration under the Trusted AI Model, aligned to NIST AI RMF and ISO/IEC 42001. Lead a team driving adoption through workshops, stakeholder engagement, and framework integration.
CDIC — GRC Specialist
Established the GRC operating charter for an 8-person team. Conducted risk and gap assessments against multiple frameworks and standards. Led a CMMC Level 1 gap assessment for a startup, evaluating security practices against applicable CMMC requirements, identifying control gaps, and developing remediation recommendations. Coordinated vulnerability remediation with technical teams.
Genpact — Regulatory & Content Compliance Analyst
Led 9 internal and external compliance audits at 90%+ compliance. Evaluated 50+ evidence artifacts and mapped technical controls to audit requirements. Supported development of a risk management and regulatory oversight program aligned to the NIST framework.
Frameworks & Standards
Frameworks I’ve worked with professionally. Engineering demonstrations are in Projects; planned work is in Roadmap.
Professional experience NIST 800-53 · CMMC · SOC 2 · HIPAA · ISO 27001/27701/42001
Engineering NIST AI RMF · EU AI Act · OSCAL · HIPAA (capstone)
Roadmap FedRAMP · CMMC L2
Projects
Open-source compliance-as-code I engineered and can demonstrate in code. Professional assessments and audit work are under Experience.
Shipped
Completed and demonstrable. Click through to verify.
Flagship · AI Governance
ARGUS — AI Governance Compliance Engine
CI: passing
Problem
AI governance lives in spreadsheets that go stale; requirements are hard to enforce before deployment.
Built
Python compliance-as-code engine: classifies AI systems under EU AI Act tiers, evaluates a machine-testable control catalog crosswalked across NIST AI RMF and ISO/IEC 42001.
Planned—not shipped. Strategic direction, not vaporware presented as done.
TPRM
Vendor Compliance Document Intelligence
Planned
Classify → extract → structure → score pipeline for SOC 2 reports and vendor questionnaires, with page-level evidence citations.
TPRMSOC 2
DoD Supply Chain
CMMC Level 2 as Code
Planned
Map CMMC L2 practices to Terraform/OPA enforcement, extending the compliance-as-code pattern into the DoD supply chain.
CMMCNIST 800-171
Cloud Compliance
FedRAMP Evidence-as-Code
Planned
Planned exploration of FedRAMP Rev. 5, OSCAL-based control implementation, automated cloud evidence collection, and policy-as-code validation.
FedRAMPOSCAL
AI Governance
ARGUS — Extended Governance Pipeline
Planned
AI Inventory → Risk Classification → Impact Assessment → Controls → Evidence → Monitoring. Future capabilities not yet implemented in the current codebase.
NIST AI RMFEU AI Act
Writing
Not every compliance workflow needs Terraform. These show the other end of the automation spectrum.
Credentials support the work—the repos carry the proof.
GRC Engineering
CGE-PCertified GRC Engineer — Practitioner
CGE-AUDCertified GRC Engineer — Auditor Specialty
Management Systems
ISO/IEC 42001:2023Lead Auditor — AI Management Systems
ISO/IEC 27701:2025Lead Auditor — Privacy Information Mgmt
ISO/IEC 27001:2022Lead Auditor — Information Security Mgmt
Security / Technology
CompTIA Security+ ceSecurity
ServiceNow CSACertified System Administrator
Azure AI FundamentalsMicrosoft
Azure FundamentalsMicrosoft
Azure Security, Compliance & IdentityMicrosoft
Azure Data FundamentalsMicrosoft
Securiti AI Security & GovernanceSecuriti
Leadership
Vice President
GRC Engineering Club — Augusta Chapter. Co-founded the chapter for engineers, auditors, and compliance professionals across the CSRA, anchored around Fort Eisenhower’s Army Cyber Command.
Global Ambassador, USA
Global Council for Responsible AI. Championing public awareness and education on responsible AI.
Let’s build compliance that can prove itself.
Open to: GRC Engineering · AI Governance · Cloud Security & Compliance