Skip to content
View Toyeeb29's full-sized avatar

Block or report Toyeeb29

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Toyeeb29/README.md

Hey, I'm Toyeeb πŸ‘‹

Engineering governance into systems from day one. Focused on AI risk, compliance automation, and cloud-native security β€” moving GRC from spreadsheets to code.

About Me

I build pipelines that turn compliance from a quarterly spreadsheet exercise into a merge-blocking check: Terraform baselines that are compliant by default, policy-as-code gates that fail closed, signed evidence chains, and machine-readable control mappings an assessor can traverse without a meeting.

I'm certified on both sides of the audit: I build audit-defensible pipelines, and I assess someone else's.

Certifications

  • Certified GRC Engineer – Auditor Specialty (CGE-AUD)
  • Certified GRC Engineer – Practitioner (CGE-P)
  • ISO/IEC 42001:2023 Lead Auditor β€” AI Management Systems
  • ISO/IEC 27701:2025 Lead Auditor β€” Privacy Information Management
  • ISO/IEC 27001:2022 Lead Auditor β€” Information Security Management
  • CompTIA Security+ ce
  • ServiceNow Certified System Administrator
  • Microsoft Certified: Azure AI Fundamentals Β· Azure Fundamentals Β· Security, Compliance & Identity Fundamentals Β· Azure Data Fundamentals

Open to: GRC Engineer Β· AI Governance Engineer Β· Cloud Security / Compliance Engineer

What I'm Building

Each repo is a stage of the same pipeline: compliant infrastructure β†’ policy gates β†’ signed evidence β†’ continuous monitoring β†’ machine-readable mapping.

Compliant IaC β†’ Policy-as-Code Gate β†’ Signed Evidence β†’ Monitoring β†’ OSCAL Mapping

Flagship Projects

  • argus-ai-grc β€” AI Governance Compliance-as-Code engine. EU AI Act risk tiering, NIST AI RMF / ISO 42001 crosswalk, CI gate that blocks merges on critical findings. Live dashboard
  • cgep-app-starter β€” CGE-P capstone: HIPAA-controlled Patient Intake API. Terraform baseline, 6 OPA policies with tests, signed CI evidence pipeline, OSCAL component mapping. Passed 81.7%.
  • cgep-labs β€” Full lab portfolio: compliant modules, policy libraries, keyless OIDC/WIF pipelines, OSCAL authoring, across AWS and GCP.

GRC Automation Tools

  • circleci-aws-opa-lab β€” CI/CD pipeline (CircleCI β†’ AWS): keyless OIDC auth, Terraform deploy/destroy, OPA gates blocking non-compliant infra before it ships.
  • cloud-encryption-evidence β€” Scans an AWS account and produces timestamped, audit-ready evidence that every S3 bucket, EBS volume, and KMS key is encrypted β€” mapped to SOC 2 / NIST 800-53 / ISO 27001 / PCI DSS / HIPAA.
  • cloudtrail-logging-monitoring β€” Validates CloudTrail configuration against SOC 2 CC7.2 and NIST 800-53 AU-2/3/6/12, classifying trails by risk with remediation commands.
  • aws_automated_access_review β€” Serverless IAM access review: Lambda + IAM Access Analyzer + Security Hub, summarized by Amazon Bedrock (Claude) and emailed on a schedule.
  • AWS-IAM-Inactive-Key-Lifecycle-Manager β€” Detects inactive IAM access keys and automates their rotation/deactivation lifecycle.
  • password-policy-automation β€” Automates enforcement and drift detection of IAM password policy against a compliance baseline.
  • No-s3-Public-Buckets β€” OPA/Rego policy library denying any S3 bucket lacking full public-access blocking.
  • apis-to-audit-ready-excel β€” Serverless pipeline extracting Security Hub findings into audit-ready Excel reports.

Writing

  • Real-Time AI Incident Logging β€” a no-code Zapier pipeline that turns the public AI Incident Database into a live, severity-classified risk register with instant Slack alerts.
  • Building an AI Readiness Tracker with Airtable β€” a beginner-friendly AI governance base: linked AI inventory, risk register, and controls tables with a compliance dashboard and automated alerts.

More on Medium.

Technical Stack

Category Technologies
Cloud AWS (S3, KMS, CloudTrail, Security Hub, IAM), Azure (AD, Policy, Defender for Cloud), GCP (WIF, Org Policy, Audit Logs)
Languages Python (boto3), HCL, Bash
IaC Terraform
Policy-as-Code OPA/Rego, Conftest
CI/CD GitHub Actions, CircleCI
Evidence & Signing Cosign (keyless/Sigstore), S3 Object Lock
Machine-Readable Compliance OSCAL, compliance-trestle
AI in the Loop Amazon Bedrock (Claude) for automated findings summarization
Frameworks NIST 800-53, HIPAA Security Rule, SOC 2, PCI DSS, EU AI Act, NIST AI RMF, ISO/IEC 42001/27001/27701

Currently Learning

Claude Code Β· Cursor Β· n8n Β· OPA/Gatekeeper admission control Β· AI agent governance

Where to Find Me

LinkedIn Β· Medium

Pinned Loading

  1. argus-ai-grc argus-ai-grc Public

    Python

  2. cgep-app-starter cgep-app-starter Public

    CGE-P Capstone: HIPAA-controlled Patient Intake API (derivative of GRCEngClub/cgep-app-starter)

    HCL

  3. cgep-labs cgep-labs Public

    HCL

  4. cloud-encryption-evidence cloud-encryption-evidence Public

    Python

  5. cloudtrail-logging-monitoring cloudtrail-logging-monitoring Public

    Python

  6. Toyeeb29 Toyeeb29 Public

    GitHub profile README