Technology GRC
GRC & ComplianceRisk, controls, evidence, ownership and remediation workflows.
Evidence · 10-system portfolio
Technology GRC & AI Governance Analyst specializing in NIST AI RMF, ISO 27001, and SOC 2 alignment. Building audit-ready evidence packages, automated control mapping, and vendor risk frameworks.
10
governance systems built
15
AI use cases mapped
25
buyer questions standardized
24h
trust snapshot scope
01 / Flagship proof-of-work
The flagship combines customer assurance, third-party risk and AI governance so a buyer can move from public claim → evidence → residual risk → action without changing tools or vocabulary.
Integrated modules
Module 01 · Customer assurance
A buyer-facing control model that converts broad trust claims into owners, evidence, framework mappings and reviewable remediation decisions.
15
Evidence domains
SOC 2 + ISO
Primary lenses
Traceable
Evidence state
| Domain | Buyer question | Evidence | Priority |
|---|---|---|---|
| Access | How is privileged access controlled? | RBAC · MFA · access review | High |
| Encryption | Is customer data encrypted? | TLS · storage · KMS evidence | High |
| Incident | How are incidents escalated? | IR plan · exercise · notice flow | High |
| Assurance | What audit evidence exists? | SOC scope · ISO certificate | High |
02 / 10 production-grade systems
Every project answers a real GRC question: what is the risk, what control addresses it, what evidence proves it, who owns it, and what decision comes next?
03 / Capability matrix
Capability is shown through implementation context and a concrete artifact—not a fabricated proficiency percentage.
Risk, controls, evidence, ownership and remediation workflows.
Evidence · 10-system portfolio
Trust Services Criteria mapped to operational controls and audit evidence.
Evidence · 15-domain control inventory
ISMS control architecture, risk treatment and evidence mapping.
Evidence · Control-to-evidence system
Canonical buyer answers with evidence links, owners and review dates.
Evidence · 25-question knowledge base
Population/sample thinking, expected result, exception and retest workflow.
Evidence · Audit operations system
Govern, Map, Measure and Manage applied to operational AI use cases.
Evidence · 15-system AI register
Provider/deployer transparency analysis for interactive and synthetic content.
Evidence · 15-use-case register
AI management-system governance integrated with risk/evidence workflows.
Evidence · AI Governance OS
Use-case, stakeholder, oversight, testing and residual-risk mapping.
Evidence · AI Governance OS
Prompt DLP, approved channels, redaction and unsanctioned-use controls.
Evidence · 12-control DLP standard
Criticality tiering, evidence review, findings and treatment decisions.
Evidence · 10-vendor TPRM register
Processor contracts, subprocessors, assistance, deletion and audit rights.
Evidence · 12-clause control set
Evidence requests spanning assurance, IAM, crypto, privacy and AI providers.
Evidence · 20-question vendor assessment
Likelihood, impact, residual risk, appetite, treatment, KRI and escalation.
Evidence · 15-risk executive register
Typed component systems and interactive frontend architecture.
Evidence · This portfolio
Static-first App Router site with SEO metadata and accessible interactions.
Evidence · This portfolio
Version control, repository documentation and CI workflow.
Evidence · Portfolio repository
Data transformation and artifact-generation workflows.
Evidence · GRC evidence workbooks
Computer Science foundations supporting technical risk analysis.
Evidence · BSc Computer Science
Data modeling and query fundamentals for control/evidence systems.
Evidence · BSc Computer Science
04 / Trajectory
The positioning is deliberately analyst-level: technical enough to be useful immediately, conservative enough to withstand an experienced GRC manager's questions.
2026 · Now
Built ten operational governance systems spanning customer assurance, AI governance, TPRM, SOC 2/ISO evidence, executive risk, Article 50 transparency, shadow AI, Article 28 and audit operations.
Aug 2026
Mapped interactive and generative AI use cases to the European Commission's Article 50 transparency guidance while keeping legal applicability distinct from generic framework alignment.
2026
Produced source-backed public trust assessments that separate observed evidence, public evidence not identified and matters requiring internal verification instead of making unsupported compliance conclusions.
Current
Building the technical foundation behind technology risk work: software engineering, algorithms, databases, systems and disciplined problem solving.
03 / Framework Coverage Matrix
Every compliance framework is backed by concrete control mapping, evidence registers, and risk treatment plans—not theoretical compliance claims.
Information Security Management System (ISMS) control mapping and evidence collection alignment.
Key Mapped Safeguards
Governance, Mapping, Measuring, and Managing risk functions across LLM and machine learning deployments.
Key Mapped Safeguards
Security, Availability, and Confidentiality trust service criteria mapping for SaaS vendor evaluations.
Key Mapped Safeguards
Data protection impact assessments (DPIA), processing records, and AI high-risk categorization.
Key Mapped Safeguards
Artificial Intelligence Management System (AIMS) structure and algorithmic risk treatment.
Key Mapped Safeguards
Prioritized safeguards for defensive posture, asset inventory, and vulnerability management.
Key Mapped Safeguards
05 / Hire · Contract · Collaborate
Open to Technology GRC, Security Compliance, TPRM, Technology Risk and AI Governance roles—and tightly scoped B2B trust-readiness work.
Micro-offer
15-point evidence review · buyer-question register · third-party/AI risk observations · five prioritized documentation actions.