Senior Manager leading Cyber GRC, TPRM, and AI Governance programs across regulated financial services, insurance, healthcare, and SaaS environments.
- 🔐 Focus areas: Cybersecurity GRC · AI Governance (NIST AI RMF, ISO 42001, EU AI Act) · Third-Party Risk Management · IAM
- 🧩 What's in this account: hands-on AI agent and automation builds (RAG, multi-agent, workflow orchestration) that support GRC and audit work, including evidence collection, tailoring, and research tasks that are usually manual — plus curated, deduplicated reference lists for the compliance frameworks behind that work
- 📜 Credentials: 40+ training and certification badges (NIST, ISO 27001/42001, SOX/ITGC, HIPAA, PCI-DSS) on my Credly wallet — see the curated framework lists below for the same standards
- 💼 More about me: LinkedIn
- ai-governance: regulation, standards, and runtime controls for AI and autonomous agents (NIST AI RMF, EU AI Act, ISO 42001, and more)
- security-frameworks: NIST CSF, ISO/IEC 27001, PCI-DSS, CIS Controls, DISA STIG, and the CRI Profile
- risk-management: gap analysis, qualitative/quantitative risk analysis (FAIR), heat maps, RACI, the risk register, and compensating controls — with starting templates
- vapt: vulnerability assessment and penetration testing methodology, free tools (Nmap, Nessus Essentials, Burp, Metasploit), MITRE ATT&CK, and building a legal practice lab
- privacy: GDPR, CCPA/CPRA, the US state privacy patchwork, DPIAs, and data subject request handling
- cloud-security: the shared responsibility model, AWS/Azure/GCP-specific security, Zero Trust, CSPM, and SOC 2
- ir-bc-dr: incident response planning, ransomware/scenario playbooks, tabletop exercises, and BIA-driven disaster recovery (RTO/RPO)
- it-audit-controls: COBIT, COSO, and ITGC/ITAC for IT and SOX audits
- healthcare-compliance: HIPAA, HITECH, and HITRUST CSF
- finserv-compliance: GLBA/FFIEC, NYDFS 500, SEC/FINRA, BSA/AML/OFAC, and model risk management (SR 26-2) for US financial services
- federal-compliance: FedRAMP, CMMC, NIST SP 800-53/171, FISMA, and writing an SSP/POA&M
- insurance-compliance: NAIC Insurance Data Security Model Law, ORSA, and market conduct examinations
- grc-case-studies: open, team-based GRC case studies with task sheets, capstones and answer keys. First case: a five-week simulation of the 2014 JPMorgan Chase breach covering asset inventory, MFA exception management, and NIST CSF/FFIEC mapping
- ai-governance: AI regulation, standards, and runtime controls for autonomous agents
- risk-management: the risk-management method end to end, from gap analysis and FAIR to the risk register, with starting templates
- it-audit-controls: COBIT, COSO, and ITGC/ITAC guidance for IT and SOX audits
- finserv-compliance: the US financial-services regulatory perimeter: banking, securities, and financial crimes
- security-frameworks: NIST CSF, ISO/IEC 27001, PCI-DSS, and CIS Controls implementation guidance
- Legal-Agent-RAG: RAG-based contract clause lookup supporting vendor contract review for third-party risk.
More automation work (n8n-based GRC and AI governance pipelines) is being cleaned up and will be published here as it's ready.