Senior GRC Analyst · New York
GRC professional engineering the bridge between compliance frameworks, cloud infrastructure, and AI governance. Turning policy into practice.
About
I am a Senior GRC professional building toward a future where compliance isn't a checklist. It's infrastructure.
My background is in enterprise risk management, SOX ITGC, ISO 27001, HIPAA, and audit readiness. I've spent my career learning how governance programs actually work inside fast-moving technology organizations and, more importantly, where they break down.
What I'm working toward is the engineering side of that problem. I want to translate policy into infrastructure, generate evidence artifacts automatically, and build continuous monitoring systems that catch drift in real time. Not during the next annual audit. The goal isn't point-in-time compliance. It's compliance that runs.
I believe the next generation of GRC needs people who can sit at the intersection of policy, engineering, and AI governance. I'm building toward being one of them. One lab, one script, one framework at a time.
Projects
Personal builds are independent projects. Professional work highlights selected initiatives from my career.
A 6-week public build of an end-to-end GRC engineering pipeline. Compliant AWS infrastructure as code, Rego policy library, CI gate that blocks non-compliant PRs, cryptographically signed evidence, native cloud monitoring controls, and an OSCAL control mapping an auditor can traverse without scheduling a meeting.
Hands-on AWS and Terraform lab work covering infrastructure provisioning, IAM policy design, and cloud security controls. Built to demonstrate how GRC professionals can engage directly with the infrastructure they're meant to govern — not just audit it.
View on GitHub →Led the transition from manual, spreadsheet-based access reviews to Okta's native certification workflows — cutting completion time by 70–80% (from 1–2 weeks to 2–3 days), improving audit evidence quality, and strengthening access governance across SOX and ISO audits.
Owned and maintained the enterprise risk register, establishing clear risk ownership, escalation paths, and documented mitigation plans. Translated technical control gaps into business-level decision points — giving leadership the visibility needed to act.
Led remediation strategy for SOX and ISO control gaps — evaluating control design weaknesses, risk impact, and operational feasibility before recommending corrective actions. Redesigned ineffective, audit-driven controls into governance-first designs that actually reduced audit friction.
Skills
Frameworks
Engineering
GRC Practice