Engineering governance into systems from day one. Focused on AI risk, compliance automation, and cloud-native security β moving GRC from spreadsheets to code.
I build pipelines that turn compliance from a quarterly spreadsheet exercise into a merge-blocking check: Terraform baselines that are compliant by default, policy-as-code gates that fail closed, signed evidence chains, and machine-readable control mappings an assessor can traverse without a meeting.
I'm certified on both sides of the audit: I build audit-defensible pipelines, and I assess someone else's.
Certifications
- Certified GRC Engineer β Auditor Specialty (CGE-AUD)
- Certified GRC Engineer β Practitioner (CGE-P)
- ISO/IEC 42001:2023 Lead Auditor β AI Management Systems
- ISO/IEC 27701:2025 Lead Auditor β Privacy Information Management
- ISO/IEC 27001:2022 Lead Auditor β Information Security Management
- CompTIA Security+ ce
- ServiceNow Certified System Administrator
- Microsoft Certified: Azure AI Fundamentals Β· Azure Fundamentals Β· Security, Compliance & Identity Fundamentals Β· Azure Data Fundamentals
Open to: GRC Engineer Β· AI Governance Engineer Β· Cloud Security / Compliance Engineer
Each repo is a stage of the same pipeline: compliant infrastructure β policy gates β signed evidence β continuous monitoring β machine-readable mapping.
Compliant IaC β Policy-as-Code Gate β Signed Evidence β Monitoring β OSCAL Mapping
- argus-ai-grc β AI Governance Compliance-as-Code engine. EU AI Act risk tiering, NIST AI RMF / ISO 42001 crosswalk, CI gate that blocks merges on critical findings. Live dashboard
- cgep-app-starter β CGE-P capstone: HIPAA-controlled Patient Intake API. Terraform baseline, 6 OPA policies with tests, signed CI evidence pipeline, OSCAL component mapping. Passed 81.7%.
- cgep-labs β Full lab portfolio: compliant modules, policy libraries, keyless OIDC/WIF pipelines, OSCAL authoring, across AWS and GCP.
- circleci-aws-opa-lab β CI/CD pipeline (CircleCI β AWS): keyless OIDC auth, Terraform deploy/destroy, OPA gates blocking non-compliant infra before it ships.
- cloud-encryption-evidence β Scans an AWS account and produces timestamped, audit-ready evidence that every S3 bucket, EBS volume, and KMS key is encrypted β mapped to SOC 2 / NIST 800-53 / ISO 27001 / PCI DSS / HIPAA.
- cloudtrail-logging-monitoring β Validates CloudTrail configuration against SOC 2 CC7.2 and NIST 800-53 AU-2/3/6/12, classifying trails by risk with remediation commands.
- aws_automated_access_review β Serverless IAM access review: Lambda + IAM Access Analyzer + Security Hub, summarized by Amazon Bedrock (Claude) and emailed on a schedule.
- AWS-IAM-Inactive-Key-Lifecycle-Manager β Detects inactive IAM access keys and automates their rotation/deactivation lifecycle.
- password-policy-automation β Automates enforcement and drift detection of IAM password policy against a compliance baseline.
- No-s3-Public-Buckets β OPA/Rego policy library denying any S3 bucket lacking full public-access blocking.
- apis-to-audit-ready-excel β Serverless pipeline extracting Security Hub findings into audit-ready Excel reports.
- Real-Time AI Incident Logging β a no-code Zapier pipeline that turns the public AI Incident Database into a live, severity-classified risk register with instant Slack alerts.
- Building an AI Readiness Tracker with Airtable β a beginner-friendly AI governance base: linked AI inventory, risk register, and controls tables with a compliance dashboard and automated alerts.
More on Medium.
| Category | Technologies |
|---|---|
| Cloud | AWS (S3, KMS, CloudTrail, Security Hub, IAM), Azure (AD, Policy, Defender for Cloud), GCP (WIF, Org Policy, Audit Logs) |
| Languages | Python (boto3), HCL, Bash |
| IaC | Terraform |
| Policy-as-Code | OPA/Rego, Conftest |
| CI/CD | GitHub Actions, CircleCI |
| Evidence & Signing | Cosign (keyless/Sigstore), S3 Object Lock |
| Machine-Readable Compliance | OSCAL, compliance-trestle |
| AI in the Loop | Amazon Bedrock (Claude) for automated findings summarization |
| Frameworks | NIST 800-53, HIPAA Security Rule, SOC 2, PCI DSS, EU AI Act, NIST AI RMF, ISO/IEC 42001/27001/27701 |
Claude Code Β· Cursor Β· n8n Β· OPA/Gatekeeper admission control Β· AI agent governance

