Audit readiness
Preparing teams for external reviews by keeping audit requests, control evidence, and certification needs organized and actionable.
CISA-certified compliance professional helping software and technology teams turn requirements into controls, evidence, and audit-ready operating practices.
Experience supporting SOC 2, ISO 27001, HIPAA, and PCI-DSS compliance work across security, IT, legal, product, and operations teams. Background in QA, technical support, and product delivery, with a practical understanding of how technical teams document, test, and operationalize controls.
Core Strengths
Hands-on experience helping compliance programs run cleanly across audits, controls, risk, and operational execution.
Preparing teams for external reviews by keeping audit requests, control evidence, and certification needs organized and actionable.
Helping control owners translate framework requirements into operating practices, testing activity, and maintainable records.
Turning gaps, exceptions, and risk findings into clear ownership, next steps, timelines, and completion visibility.
Framework Experience
Hands-on experience with core security and compliance frameworks, plus familiarity with adjacent privacy and risk frameworks commonly followed by software teams.
Hands-on experience
Familiar with
Selected Compliance Work
Experience
11:11 Systems
Supported enterprise compliance operations across security and regulatory frameworks, with emphasis on external audits, OneTrust workflows, control operations, risk assessments, and control testing activity.
ThreeFlow
Led cross-functional delivery work connecting product execution, security requirements, Vanta-supported compliance activities, and external audit needs in a software environment.
ThreeFlow
Improved support and delivery operations by building processes, coordinating feature rollouts, and assisting product teams with testing and adoption.
Ceterus
Led QA operations across manual and automated testing, helping improve release quality, team performance, and test coverage.
Ceterus
Executed test planning and defect validation across multiple applications, with a focus on quality, reproducibility, and technical accuracy.
Ceterus
Handled technical support operations, documentation, and data quality work while serving as a bridge between users and engineering.
Projects
Kasbah Labs
Designed and built an applied GRC workflow application for control ownership, evidence handling, policy workflows, remediation status, and audit preparation.
Education
Western Governors University
Salt Lake City, Utah
Tools & Platforms
Platforms used for control operations, audit workflows, and compliance program management.
Security and identity tools used in environments connected to control operations and audit evidence.
Systems used for ticketing, knowledge management, workflow coordination, and operational records.
Technical tools used to support analysis, testing, reporting, and software delivery context.
Approach
I’ve worked close to audits, controls, product teams, engineering, and delivery. That makes me useful in roles where requirements need to become real processes, real systems, and real follow-through.
Contact
For roles focused on GRC, compliance operations, audit programs, risk work, and technical compliance.