Governance, Risk, Compliance & Security Leadership
Full-scope engagements spanning framework-based assessments, control audits, security program builds, and professional virtual experience programs.
NIST SP 800-171 Readiness Assessment
Enterprise-wide compliance evaluation against NIST SP 800-171 Rev 2 and CUI protection requirements. Complete gap analysis, policy development, and remediation planning across all 14 control families.
ISO 27001 Gap Assessment — Certification Readiness
Full Annex A gap assessment for a SaaS supply chain platform (250 employees, $35M ARR) seeking ISO 27001 certification for EU market expansion. All 93 controls assessed, Statement of Applicability, risk assessment, and 12-month remediation roadmap.
RiskCommand — CISO Security Program Build
Complete security program built from scratch for a Series B fintech startup. 50+ artifacts across 6 phases: risk assessment, policy framework, BCP/DR with tested runbooks, security awareness, vendor risk management, and executive reporting.
Incident Response Plan — Playbook Development & Tabletop Exercise
Comprehensive IR program for a fintech payment processor (180 employees, $48M ARR). Policy framework, 4 structured playbooks, full tabletop exercise with 8 injects, communication plan, and post-incident review process. NIST SP 800-61 Rev 2 aligned.
IT General Controls Audit — MediTrust Health
End-to-end ITGC audit for a digital health platform (HIPAA-covered). 16 test procedures across 4 domains (User Access, Change Management, Backup & Recovery, Segregation of Duties) with risk-rated findings and corrective action plan. COBIT 2019 framework.
COBIT-Based IT Governance Gap Assessment
Governance maturity assessment for a healthcare technology company (1,200 employees, 3 acquisitions). 19 COBIT 2019 objectives assessed against 0-5 maturity scale. Findings mapped to COSO Internal Control principles. Prioritized recommendations for SOX readiness.
PwC US Audit — Control Testing Job Simulation
Completed PwC US Audit job simulation on Forage. Conducted control tests of a client's purchasing process, compiled walkthrough documentation, outlined the purchase process in a flowchart, and developed a risk control matrix.
Mastercard Cybersecurity — Security Awareness Job Simulation
Completed Mastercard Cybersecurity job simulation on Forage. Served as an analyst on the Security Awareness Team, identified phishing threats, analyzed business areas needing robust security training, and implemented training courses and procedures.
ERP Access Control Audit Walkthrough
User access provisioning and role assignment audit in a self-hosted ERPNext environment for a logistics company. 200+ users analyzed across 6 departments. Segregation of duties conflict matrix identifying 12 incompatible combinations. Triggered by $250K fraud incident.