Skip to content
View garynair's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report garynair

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
garynair/README.md

Hi, I'm Girish Nair

Senior Manager leading Cyber GRC, TPRM, and AI Governance programs across regulated financial services, insurance, healthcare, and SaaS environments.

  • 🔐 Focus areas: Cybersecurity GRC · AI Governance (NIST AI RMF, ISO 42001, EU AI Act) · Third-Party Risk Management · IAM
  • 🧩 What's in this account: hands-on AI agent and automation builds (RAG, multi-agent, workflow orchestration) that support GRC and audit work, including evidence collection, tailoring, and research tasks that are usually manual — plus curated, deduplicated reference lists for the compliance frameworks behind that work
  • 📜 Credentials: 40+ training and certification badges (NIST, ISO 27001/42001, SOX/ITGC, HIPAA, PCI-DSS) on my Credly wallet — see the curated framework lists below for the same standards
  • 💼 More about me: LinkedIn

Curated framework lists

  • ai-governance: regulation, standards, and runtime controls for AI and autonomous agents (NIST AI RMF, EU AI Act, ISO 42001, and more)
  • security-frameworks: NIST CSF, ISO/IEC 27001, PCI-DSS, CIS Controls, DISA STIG, and the CRI Profile
  • risk-management: gap analysis, qualitative/quantitative risk analysis (FAIR), heat maps, RACI, the risk register, and compensating controls — with starting templates
  • vapt: vulnerability assessment and penetration testing methodology, free tools (Nmap, Nessus Essentials, Burp, Metasploit), MITRE ATT&CK, and building a legal practice lab
  • privacy: GDPR, CCPA/CPRA, the US state privacy patchwork, DPIAs, and data subject request handling
  • cloud-security: the shared responsibility model, AWS/Azure/GCP-specific security, Zero Trust, CSPM, and SOC 2
  • ir-bc-dr: incident response planning, ransomware/scenario playbooks, tabletop exercises, and BIA-driven disaster recovery (RTO/RPO)
  • it-audit-controls: COBIT, COSO, and ITGC/ITAC for IT and SOX audits
  • healthcare-compliance: HIPAA, HITECH, and HITRUST CSF
  • finserv-compliance: GLBA/FFIEC, NYDFS 500, SEC/FINRA, BSA/AML/OFAC, and model risk management (SR 26-2) for US financial services
  • federal-compliance: FedRAMP, CMMC, NIST SP 800-53/171, FISMA, and writing an SSP/POA&M
  • insurance-compliance: NAIC Insurance Data Security Model Law, ORSA, and market conduct examinations

Featured work

  • grc-case-studies: open, team-based GRC case studies with task sheets, capstones and answer keys. First case: a five-week simulation of the 2014 JPMorgan Chase breach covering asset inventory, MFA exception management, and NIST CSF/FFIEC mapping
  • ai-governance: AI regulation, standards, and runtime controls for autonomous agents
  • risk-management: the risk-management method end to end, from gap analysis and FAIR to the risk register, with starting templates
  • it-audit-controls: COBIT, COSO, and ITGC/ITAC guidance for IT and SOX audits
  • finserv-compliance: the US financial-services regulatory perimeter: banking, securities, and financial crimes
  • security-frameworks: NIST CSF, ISO/IEC 27001, PCI-DSS, and CIS Controls implementation guidance
  • Legal-Agent-RAG: RAG-based contract clause lookup supporting vendor contract review for third-party risk.

More automation work (n8n-based GRC and AI governance pipelines) is being cleaned up and will be published here as it's ready.

Pinned Loading

  1. ai-governance ai-governance Public

    A curated, deduplicated list of AI governance resources — regulation, standards, and runtime controls for autonomous agents

    HTML

  2. Legal-Agent-RAG Legal-Agent-RAG Public

    RAG-based legal contract knowledge base - indexes contracts for fast, cost-efficient clause lookup instead of feeding full documents to an LLM.

  3. security-frameworks security-frameworks Public

    A curated list of NIST CSF, ISO/IEC 27001, and PCI-DSS — standards, implementation guidance, and tooling

    HTML

  4. finserv-compliance finserv-compliance Public

    A curated list of standards, implementation guidance, and tooling for financial-services compliance: GLBA, FFIEC, NYDFS 500, SEC/FINRA, BSA/AML/OFAC, and more.

    HTML

  5. risk-management risk-management Public

    A curated, practitioner-oriented guide to enterprise and operational risk management — gap analysis, qualitative/quantitative risk analysis (FAIR), heat maps, RACI, the risk register, and compensat…

    HTML

  6. grc-case-studies grc-case-studies Public

    Open, team-based GRC case studies with task sheets, capstones and answer keys. Starting with the 2014 JPMorgan Chase breach.