Senior GRC Analyst · New York
GRC professional engineering the bridge between compliance frameworks, cloud infrastructure, and AI governance. Turning policy into practice.
About
I am a Senior GRC professional building toward a future where compliance isn't a checklist. It's infrastructure.
My background is in enterprise risk management, SOX ITGC, ISO 27001, HIPAA, and audit readiness. I've spent my career learning how governance programs actually work inside fast-moving technology organizations and, more importantly, where they break down.
What I'm working toward is the engineering side of that problem. I want to translate policy into infrastructure, generate evidence artifacts automatically, and build continuous monitoring systems that catch drift in real time. Not during the next annual audit. The goal isn't point-in-time compliance. It's compliance that runs.
I believe the next generation of GRC needs people who can sit at the intersection of policy, engineering, and AI governance. I'm building toward being one of them. One lab, one script, one framework at a time.
Projects
Personal builds are independent projects. Professional work highlights selected initiatives from my career.
A 6-week public build where each week adds one layer to the same compliance system. By week 6 I'll have compliant infrastructure as code, a policy library, a CI gate, signed evidence, native cloud controls, and a full OSCAL control mapping.
Hands-on AWS and Terraform lab work covering infrastructure provisioning, IAM policy design, and cloud security controls. Built to demonstrate how GRC professionals can engage directly with the infrastructure they're meant to govern — not just audit it.
View on GitHub →Led the transition from manual, spreadsheet-based access reviews to Okta's native certification workflows — cutting completion time by 70–80% (from 1–2 weeks to 2–3 days), improving audit evidence quality, and strengthening access governance across SOX and ISO audits.
Built and currently in use for our quarterly Okta access certification cycle. A local read only MCP server pulls outstanding reviews and evidence from Okta Identity Governance, while a connected pipeline drafts reviewer nudges, excluding anyone currently out of office (unreviewed items reassign automatically if a campaign closes before they return), and posts closure evidence to Jira, surfacing hidden ticket dependencies along the way.
No public repo, built for a live work environmentOwned and maintained the enterprise risk register, establishing clear risk ownership, escalation paths, and documented mitigation plans. Translated technical control gaps into business-level decision points — giving leadership the visibility needed to act.
Led remediation strategy for SOX and ISO control gaps — evaluating control design weaknesses, risk impact, and operational feasibility before recommending corrective actions. Redesigned ineffective, audit-driven controls into governance-first designs that actually reduced audit friction.
Skills
Frameworks
Engineering
GRC Practice