I am a CISA-certified cybersecurity GRC professional working at the intersection of regulatory cybersecurity, IT audit, risk and compliance.
My current work is regulatory: driving compliance audits and cybersecurity inspections across regulated entities, assessing controls against framework requirements, reviewing third-party audit reports and governing the incident lifecycle from RCA through to risk-based reporting. Before that, my time was spent in security operations — SIEM monitoring, endpoint detection and response, DLP, vulnerability assessment and incident handling.
That combination is deliberate. Governance without technical grounding produces documents nobody can operate; technical work without governance produces fixes nobody can evidence. I work on the connection between the two — regulatory requirement, control design, operating reality, and the risk that remains.
View professional profile (PDF)