GRC Spot Owner & Curator

For more than three decades, I have worked in IT and IT-related positions across hardware and software support, application and network engineering, IT audit, and cybersecurity GRC disciplines, helping organizations build practical, sustainable approaches to managing risk.

My experience spans global education technology, financial services, consulting, retail operations, and manufacturing environments, with a primary focus on enterprise cybersecurity governance, risk, and compliance management programs.

I have led and supported compliance and assessment initiatives across multiple frameworks and regulatory requirements including NIST, ISO 27001, SOC 2, PCI DSS, FedRAMP, HIPAA, SOX, GDPR, and others, translating complex requirements into business-aligned solutions.

My approach emphasizes integrity, common sense, and operational reality—building programs that support business objectives while strengthening security and compliance outcomes.

The articles, insights, and resources shared here reflect my own experience, analysis, and perspective developed through years of hands-on work in the field.

Trending