Information Security GRC | Cyber Risk | Control Assurance | Cloud Governance | GRC Engineering
I am an information security GRC and cyber risk professional with 10 years of cybersecurity experience across governance, risk, compliance, security operations, incident response, secure product environments, and technical capacity building.
My work focuses on translating security and compliance requirements into practical controls, measurable remediation plans, reliable evidence, and clear guidance for technical and executive stakeholders.
I am currently extending that experience into GRC engineering by building automated, testable, and evidence-driven control workflows.
Good GRC connects risk, controls, technology, evidence, and accountable action.
I am building a hands-on GRC engineering portfolio focused on:
- Cloud governance
- Compliance automation
- Control validation and assurance
- Infrastructure-as-code
- Policy-as-code
- Audit-ready evidence
- Evidence integrity
- Continuous control monitoring
- Risk and control mapping
- Human-governed remediation decisions
| Project | What it demonstrates | Technologies | Status |
|---|---|---|---|
| AWS GRC Evidence and Control Assessment | Identity-first AWS resource inventory, selected S3 and IAM control assessments, deterministic findings, management reporting, and integrity-verified evidence packaging. Includes 453 automated tests and a fictional local demonstration. | Python, boto3, JSON, CSV, SHA-256 | Published |
| Continuous Compliance Engineering Lab | Fictional SOC 2 compliance-program design in Probo, including organization and scope definition, AWS asset and third-party records, scenario-based risk assessment, treatment planning, control mapping, and implementation-task management. | Probo, SOC 2, AWS, Risk Management, Control Mapping | Active - Milestone 1 complete |
| Compliant S3 Resource | Terraform-based implementation of selected AWS S3 controls, including encryption, versioning, public-access blocking, access logging, required tags, verification scripting, and machine-readable plan evidence. | Terraform, AWS, S3, Bash, JSON | Published |
| GRC Control Register Validator | Local modeling and validation of a fictional GRC control register, including schema checks, control-quality rules, readable findings, exit codes, and 14 automated tests. | Python, CSV, unittest | Published |
The GRC Control Register Validator translates control-record quality requirements into repeatable Python validation logic.
It demonstrates:
- Structured control-record modeling
- Required-field validation
- Accepted-value checks
- Cross-field control logic
- CSV processing
- Readable validation findings
- Process exit codes
- Automated testing
The AWS GRC Evidence and Control Assessment begins at the AWS identity boundary and moves selected technical observations through:
- Identity validation
- Resource inventory
- Inventory export
- S3 control assessment
- IAM access-key assessment
- Finding transformation
- Management summary
- Evidence packaging
- Temporary cleanup
The project includes selected read-only S3, IAM, and EC2 workflows, strict stage validation, deterministic findings, management reporting, canonical JSON, SHA-256 evidence integrity, bounded cleanup, and 453 automated tests.
The public demonstration is entirely fictional and local. It does not use configured AWS credentials, make network requests, change AWS resources, or persist evidence by default.
The Continuous Compliance Engineering Lab demonstrates how a fictional SOC 2 compliance program can be structured in Probo.
The completed baseline includes:
- Fictional organization and compliance-scope definition
- SOC 2 framework import
- AWS third-party and asset registration
- Scenario-based privileged-identity risk assessment
- Inherent and initial residual risk documentation
- Risk-treatment selection
- Control and measure mapping
- Read-only implementation-task planning
- Sanitized public documentation and screenshots
The next planned milestone introduces Prowler for selected AWS technical assessment, evidence review, finding management, remediation planning, and residual-risk reassessment. These later capabilities are not yet represented as completed work.
The Compliant S3 Resource demonstrates how selected cloud-control requirements can be implemented and verified through Terraform.
It includes:
- Encryption at rest
- Public-access blocking
- Versioning
- Access logging
- Required governance tags
- Verification scripting
- Machine-readable Terraform plan evidence
- Led a 245-point ITGC/IS assessment across 11 domains and supported remediation of 95 findings.
- Closed 78% of audit findings through evidence validation, retesting, owner follow-up, ageing analysis, and escalation.
- Sustained zero major non-conformities across more than 10 external assessments.
- Built and managed risk registers, control workbooks, remediation trackers, evidence logs, executive dashboards, management responses, and Board reporting.
- Embedded GRC, privacy, quality-management, evidence-integrity, and product-security controls across forensic and investigative products.
- Co-architected and operationalized AlienVault USM across more than 37 critical assets.
- Reduced phishing susceptibility from 60% to 15% through targeted security-awareness improvements.
- Led and mentored multidisciplinary cybersecurity teams while managing concurrent technical and assurance projects.
- Trained and mentored more than 200 cybersecurity professionals.
I approach GRC engineering as the practical bridge between governance requirements and operational implementation.
My focus is on:
- Translating risk and compliance requirements into technical controls
- Designing evidence that supports audit readiness and control assurance
- Using automation to reduce repetitive compliance effort
- Separating technical observations from business risk decisions
- Connecting infrastructure configuration to governance outcomes
- Building safe failure and cleanup boundaries
- Applying least-privilege and identity-first principles
- Making control implementation understandable to technical and non-technical stakeholders
- Documenting assumptions, limitations, and human decision points clearly
- Keeping remediation and risk acceptance subject to appropriate authorization
ISO/IEC 27001 ISO/IEC 27002 ISO/IEC 27701 ISO/IEC 42001 PCI DSS NIST CSF NIST SP 800-53 CIS Controls CIS Benchmarks SOC 2 GDPR Kenya Data Protection Act OWASP
Risk Registers Control Workbooks Evidence Logs Corrective Action Tracking Audit Readiness Control Testing Risk Treatment Control Mapping CIS CSAT Pro CIS RAM CIS Controls Navigator CIS-CAT Probo
Python AWS Terraform Git GitHub Bash PowerShell SQL JSON YAML OPA/Rego Conftest
AlienVault USM Splunk ArcSight Tripwire Nessus Qualys BMC Remedy
- Certified GRC Engineer, Auditor Speciality (CGE-AUD)
- ISO/IEC 27701:2025 Lead Auditor
- GIAC Critical Controls Certification, GCCC
- GIAC Certified Incident Handler, GCIH
- GIAC Security Essentials Certification, GSEC
- GIAC Foundational Cybersecurity Technologies, GFACT
- AWS Cloud Practitioner Essentials
- TCM Security GRC Analyst Master Class
- ISO/IEC 27001:2022 Lead Auditor coursework in progress
- ISO/IEC 42001:2023 Lead Auditor coursework in progress
- Founding President, Nairobi Chapter, GRC Engineering Club
- GRC Engineering Club
- GIAC Advisory Board member
- Women in Cybersecurity member
I am interested in opportunities involving:
- GRC engineering
- Security compliance
- Technical GRC
- Security assurance
- Cyber risk and controls
- Cloud governance
- Compliance automation
- Audit readiness
- Security program management
- Product security governance
I am also open to collaboration on practical projects involving compliance-as-code, policy-as-code, automated evidence, secure infrastructure, continuous control monitoring, privacy engineering, and security education.