Senior GRC Analyst · New York

LaMeisha DuBose
Building at the
intersection of
cybersecurity.

GRC professional engineering the bridge between compliance frameworks, cloud infrastructure, and AI governance. Turning policy into practice.

Scroll to explore

About

Where compliance meets code.

I am a Senior GRC professional building toward a future where compliance isn't a checklist. It's infrastructure.

My background is in enterprise risk management, SOX ITGC, ISO 27001, HIPAA, and audit readiness. I've spent my career learning how governance programs actually work inside fast-moving technology organizations and, more importantly, where they break down.

What I'm working toward is the engineering side of that problem. I want to translate policy into infrastructure, generate evidence artifacts automatically, and build continuous monitoring systems that catch drift in real time. Not during the next annual audit. The goal isn't point-in-time compliance. It's compliance that runs.

I believe the next generation of GRC needs people who can sit at the intersection of policy, engineering, and AI governance. I'm building toward being one of them. One lab, one script, one framework at a time.


What I've built.

Personal builds are independent projects. Professional work highlights selected initiatives from my career.

Personal · Live · In Progress

GRC Engineering Challenge

A 6-week public build where each week adds one layer to the same compliance system. By week 6 I'll have compliant infrastructure as code, a policy library, a CI gate, signed evidence, native cloud controls, and a full OSCAL control mapping.

Week 1 Compliant AWS S3 infrastructure with Terraform. Controls: SC-28, CM-6, AC-3, AU-3. Evidence captured as machine-readable JSON.
Week 2 Policy as code with OPA and Rego. Three policies, six unit tests, 6/6 passing. Executable rules that prove controls automatically.
Week 3 CI gate with GitHub Actions and Conftest. Green PR passes, red PR blocked. Evidence artifact on every run. Branch protection enabled.
Week 4 Signed evidence with Cosign keyless signing. SHA-256 integrity + Sigstore authenticity. One changed byte breaks the chain.
Week 5 Native cloud controls — coming soon
Week 6 OSCAL mapping and portfolio case study — coming soon
Terraform AWS OPA Rego NIST 800-53 GRC Engineering
View on GitHub →
Personal · Live

CPGE Labs — Cloud Infrastructure

Hands-on AWS and Terraform lab work covering infrastructure provisioning, IAM policy design, and cloud security controls. Built to demonstrate how GRC professionals can engage directly with the infrastructure they're meant to govern — not just audit it.

AWS Terraform IAM Cloud Security
View on GitHub →
Professional

Okta Access Certification Automation

Led the transition from manual, spreadsheet-based access reviews to Okta's native certification workflows — cutting completion time by 70–80% (from 1–2 weeks to 2–3 days), improving audit evidence quality, and strengthening access governance across SOX and ISO audits.

Okta Access Governance SOX ISO 27001 Jira
Professional

Okta User Access Review MCP

Built and currently in use for our quarterly Okta access certification cycle. A local read only MCP server pulls outstanding reviews and evidence from Okta Identity Governance, while a connected pipeline drafts reviewer nudges, excluding anyone currently out of office (unreviewed items reassign automatically if a campaign closes before they return), and posts closure evidence to Jira, surfacing hidden ticket dependencies along the way.

Python MCP Okta Identity Governance Jira
No public repo, built for a live work environment
Professional

Enterprise Risk Register & Executive Reporting

Owned and maintained the enterprise risk register, establishing clear risk ownership, escalation paths, and documented mitigation plans. Translated technical control gaps into business-level decision points — giving leadership the visibility needed to act.

Drata AuditBoard SmartSheets Risk Management Jira
Professional

SOX & ISO Control Remediation Strategy

Led remediation strategy for SOX and ISO control gaps — evaluating control design weaknesses, risk impact, and operational feasibility before recommending corrective actions. Redesigned ineffective, audit-driven controls into governance-first designs that actually reduced audit friction.

AuditBoard Drata SOX ITGC ISO 27001 Control Design

Skills

What I work with.

Frameworks

NIST CSF NIST AI RMF ISO 27001 SOC 2 ISO 42001 SOX ITGC HIPAA

Engineering

Terraform AWS IAM Cloud Security

GRC Practice

Risk Assessment Control Design Vendor Risk Audit Evidence Policy Writing AI Governance

Let's connect.