Senior GRC Analyst · New York

LaMeisha DuBose
Building at the
intersection of
cybersecurity.

GRC professional engineering the bridge between compliance frameworks, cloud infrastructure, and AI governance. Turning policy into practice.

Scroll to explore

About

Where compliance meets code.

I am a Senior GRC professional building toward a future where compliance isn't a checklist. It's infrastructure.

My background is in enterprise risk management, SOX ITGC, ISO 27001, HIPAA, and audit readiness. I've spent my career learning how governance programs actually work inside fast-moving technology organizations and, more importantly, where they break down.

What I'm working toward is the engineering side of that problem. I want to translate policy into infrastructure, generate evidence artifacts automatically, and build continuous monitoring systems that catch drift in real time. Not during the next annual audit. The goal isn't point-in-time compliance. It's compliance that runs.

I believe the next generation of GRC needs people who can sit at the intersection of policy, engineering, and AI governance. I'm building toward being one of them. One lab, one script, one framework at a time.


What I've built.

Personal builds are independent projects. Professional work highlights selected initiatives from my career.

Personal · Complete

GRC Engineering Challenge

A 6-week public build of an end-to-end GRC engineering pipeline. Compliant AWS infrastructure as code, Rego policy library, CI gate that blocks non-compliant PRs, cryptographically signed evidence, native cloud monitoring controls, and an OSCAL control mapping an auditor can traverse without scheduling a meeting.

Week 1   Compliant S3 with Terraform. SC-28, AC-3, CM-6, AU-3.
Week 2   Rego policy library. 6/6 tests passing.
Week 3   CI gate. Green PR passes, red PR blocked.
Week 4   Cosign keyless signing. Chain of custody verified.
Week 5   CloudTrail + Security Hub. 238KB of findings captured.
Week 6   OSCAL component definition. trestle validate returns VALID.
Terraform AWS OPA Rego NIST 800-53 Cosign OSCAL GRC Engineering
View on GitHub →
Personal · Live

CPGE Labs — Cloud Infrastructure

Hands-on AWS and Terraform lab work covering infrastructure provisioning, IAM policy design, and cloud security controls. Built to demonstrate how GRC professionals can engage directly with the infrastructure they're meant to govern — not just audit it.

AWS Terraform IAM Cloud Security
View on GitHub →
Professional

Okta Access Certification Automation

Led the transition from manual, spreadsheet-based access reviews to Okta's native certification workflows — cutting completion time by 70–80% (from 1–2 weeks to 2–3 days), improving audit evidence quality, and strengthening access governance across SOX and ISO audits.

Okta Access Governance SOX ISO 27001 Jira
Professional

Enterprise Risk Register & Executive Reporting

Owned and maintained the enterprise risk register, establishing clear risk ownership, escalation paths, and documented mitigation plans. Translated technical control gaps into business-level decision points — giving leadership the visibility needed to act.

Drata AuditBoard SmartSheets Risk Management Jira
Professional

SOX & ISO Control Remediation Strategy

Led remediation strategy for SOX and ISO control gaps — evaluating control design weaknesses, risk impact, and operational feasibility before recommending corrective actions. Redesigned ineffective, audit-driven controls into governance-first designs that actually reduced audit friction.

AuditBoard Drata SOX ITGC ISO 27001 Control Design

Skills

What I work with.

Frameworks

NIST CSF NIST AI RMF ISO 27001 SOC 2 ISO 42001 SOX ITGC HIPAA

Engineering

Terraform AWS IAM Cloud Security

GRC Practice

Risk Assessment Control Design Vendor Risk Audit Evidence Policy Writing AI Governance

Let's connect.