
RiskCurity
GRC Compliance Automation Consultant
Habilidades

Revisa mis servicios


Experiencia laboral
GRC Analyst
Security First IT • Tiempo completo
May 2026 - Present • 2 mos
Led end-to-end compliance readiness programs across SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR, and NIST frameworks for clients ranging from early-stage startups to mid-market enterprises. Authored and maintained core governance documentation including Information Security Policies, Access Control Policies, Incident Response Plans, and Business Continuity/Disaster Recovery plans. Conducted risk assessments, built and maintained risk registers, and performed third-party/vendor risk reviews to identify and mitigate organizational exposure. Designed and executed internal audits and mock audit simulations to prepare stakeholders for external certification audits. Implemented and configured GRC automation platforms (Vanta, Drata, Secureframe, OneTrust) to streamline evidence collection, continuous control monitoring, and audit trail management — reducing manual compliance workload by up to 70%. Partnered with cross-functional teams (Engineering, Legal, HR) to embed compliance controls into daily operations without disrupting productivity.
Security consultant
cyberboost • Tiempo completo
Jan 2023 - Apr 2026 • 3 yrs 3 mos
Took companies from zero compliance maturity to full audit-readiness across SOC 2, ISO 27001, HIPAA, GDPR, and PCI-DSS — on tight, deadline-driven timelines. Built policies, risk registers, and control frameworks from the ground up, written for real auditors, not shelfware. Ran vendor risk assessments and gap analyses that caught issues before they became audit findings. Delivered mock audits that stress-tested client readiness and eliminated last-minute surprises. Automated the boring stuff — deployed Vanta, Drata, and Secureframe integrations so evidence collection ran continuously in the background instead of eating weeks of manual work. Cut audit prep time by up to 80% through automation-first compliance workflows.
GRC Consultant
GRC-BOXX • Tiempo completo
Jan 2021 - Dec 2022 • 1 yr 11 mos
Compliance frameworks: SOC 2, ISO 27001, HIPAA, GDPR, PCI-DSS, NIST Deliverables: policies & procedures, risk registers, vendor risk assessments, internal audit checklists, mock audits Automation: Vanta, Drata, Secureframe, OneTrust setup and configuration for continuous compliance monitoring Focus: reducing manual audit prep, building scalable GRC programs, and getting clients certification-ready efficiently Worked directly with startups and growing teams to implement right-sized compliance programs — not bloated, one-size-fits-all frameworks