Skip to content
View rubynjoroge's full-sized avatar

Block or report rubynjoroge

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
rubynjoroge/README.md

Hi, I'm Ruby Njoroge

Information Security GRC | Cyber Risk | Control Assurance | Cloud Governance | GRC Engineering

I am an information security GRC and cyber risk professional with 10 years of cybersecurity experience across governance, risk, compliance, security operations, incident response, secure product environments, and technical capacity building.

My work focuses on translating security and compliance requirements into practical controls, measurable remediation plans, reliable evidence, and clear guidance for technical and executive stakeholders.

I am currently extending that experience into GRC engineering by building automated, testable, and evidence-driven control workflows.

Good GRC connects risk, controls, technology, evidence, and accountable action.

Current Focus

I am building a hands-on GRC engineering portfolio focused on:

  • Cloud governance
  • Compliance automation
  • Control validation and assurance
  • Infrastructure-as-code
  • Policy-as-code
  • Audit-ready evidence
  • Evidence integrity
  • Continuous control monitoring
  • Risk and control mapping
  • Human-governed remediation decisions

GRC Engineering Portfolio

Project What it demonstrates Technologies Status
AWS GRC Evidence and Control Assessment Identity-first AWS resource inventory, selected S3 and IAM control assessments, deterministic findings, management reporting, and integrity-verified evidence packaging. Includes 453 automated tests and a fictional local demonstration. Python, boto3, JSON, CSV, SHA-256 Published
Continuous Compliance Engineering Lab Fictional SOC 2 compliance-program design in Probo, including organization and scope definition, AWS asset and third-party records, scenario-based risk assessment, treatment planning, control mapping, and implementation-task management. Probo, SOC 2, AWS, Risk Management, Control Mapping Active - Milestone 1 complete
Compliant S3 Resource Terraform-based implementation of selected AWS S3 controls, including encryption, versioning, public-access blocking, access logging, required tags, verification scripting, and machine-readable plan evidence. Terraform, AWS, S3, Bash, JSON Published
GRC Control Register Validator Local modeling and validation of a fictional GRC control register, including schema checks, control-quality rules, readable findings, exit codes, and 14 automated tests. Python, CSV, unittest Published

Portfolio Progression

Control automation and evidence engineering

Milestone 1: Local control validation

The GRC Control Register Validator translates control-record quality requirements into repeatable Python validation logic.

It demonstrates:

  • Structured control-record modeling
  • Required-field validation
  • Accepted-value checks
  • Cross-field control logic
  • CSV processing
  • Readable validation findings
  • Process exit codes
  • Automated testing

Milestone 2: AWS assessment and evidence workflow

The AWS GRC Evidence and Control Assessment begins at the AWS identity boundary and moves selected technical observations through:

  1. Identity validation
  2. Resource inventory
  3. Inventory export
  4. S3 control assessment
  5. IAM access-key assessment
  6. Finding transformation
  7. Management summary
  8. Evidence packaging
  9. Temporary cleanup

The project includes selected read-only S3, IAM, and EC2 workflows, strict stage validation, deterministic findings, management reporting, canonical JSON, SHA-256 evidence integrity, bounded cleanup, and 453 automated tests.

The public demonstration is entirely fictional and local. It does not use configured AWS credentials, make network requests, change AWS resources, or persist evidence by default.

Continuous compliance and GRC platform implementation

The Continuous Compliance Engineering Lab demonstrates how a fictional SOC 2 compliance program can be structured in Probo.

The completed baseline includes:

  • Fictional organization and compliance-scope definition
  • SOC 2 framework import
  • AWS third-party and asset registration
  • Scenario-based privileged-identity risk assessment
  • Inherent and initial residual risk documentation
  • Risk-treatment selection
  • Control and measure mapping
  • Read-only implementation-task planning
  • Sanitized public documentation and screenshots

The next planned milestone introduces Prowler for selected AWS technical assessment, evidence review, finding management, remediation planning, and residual-risk reassessment. These later capabilities are not yet represented as completed work.

Infrastructure-as-code control implementation

The Compliant S3 Resource demonstrates how selected cloud-control requirements can be implemented and verified through Terraform.

It includes:

  • Encryption at rest
  • Public-access blocking
  • Versioning
  • Access logging
  • Required governance tags
  • Verification scripting
  • Machine-readable Terraform plan evidence

Selected Security and GRC Impact

  • Led a 245-point ITGC/IS assessment across 11 domains and supported remediation of 95 findings.
  • Closed 78% of audit findings through evidence validation, retesting, owner follow-up, ageing analysis, and escalation.
  • Sustained zero major non-conformities across more than 10 external assessments.
  • Built and managed risk registers, control workbooks, remediation trackers, evidence logs, executive dashboards, management responses, and Board reporting.
  • Embedded GRC, privacy, quality-management, evidence-integrity, and product-security controls across forensic and investigative products.
  • Co-architected and operationalized AlienVault USM across more than 37 critical assets.
  • Reduced phishing susceptibility from 60% to 15% through targeted security-awareness improvements.
  • Led and mentored multidisciplinary cybersecurity teams while managing concurrent technical and assurance projects.
  • Trained and mentored more than 200 cybersecurity professionals.

How I Approach GRC Engineering

I approach GRC engineering as the practical bridge between governance requirements and operational implementation.

My focus is on:

  • Translating risk and compliance requirements into technical controls
  • Designing evidence that supports audit readiness and control assurance
  • Using automation to reduce repetitive compliance effort
  • Separating technical observations from business risk decisions
  • Connecting infrastructure configuration to governance outcomes
  • Building safe failure and cleanup boundaries
  • Applying least-privilege and identity-first principles
  • Making control implementation understandable to technical and non-technical stakeholders
  • Documenting assumptions, limitations, and human decision points clearly
  • Keeping remediation and risk acceptance subject to appropriate authorization

Frameworks, Platforms, and Tools

Frameworks and regulations

ISO/IEC 27001 ISO/IEC 27002 ISO/IEC 27701 ISO/IEC 42001 PCI DSS NIST CSF NIST SP 800-53 CIS Controls CIS Benchmarks SOC 2 GDPR Kenya Data Protection Act OWASP

GRC, risk, and assurance

Risk Registers Control Workbooks Evidence Logs Corrective Action Tracking Audit Readiness Control Testing Risk Treatment Control Mapping CIS CSAT Pro CIS RAM CIS Controls Navigator CIS-CAT Probo

Engineering and cloud

Python AWS Terraform Git GitHub Bash PowerShell SQL JSON YAML OPA/Rego Conftest

Security operations and validation

AlienVault USM Splunk ArcSight Tripwire Nessus Qualys BMC Remedy

Certifications and Professional Development

  • Certified GRC Engineer, Auditor Speciality (CGE-AUD)
  • ISO/IEC 27701:2025 Lead Auditor
  • GIAC Critical Controls Certification, GCCC
  • GIAC Certified Incident Handler, GCIH
  • GIAC Security Essentials Certification, GSEC
  • GIAC Foundational Cybersecurity Technologies, GFACT
  • AWS Cloud Practitioner Essentials
  • TCM Security GRC Analyst Master Class
  • ISO/IEC 27001:2022 Lead Auditor coursework in progress
  • ISO/IEC 42001:2023 Lead Auditor coursework in progress

Professional Affiliations

  • Founding President, Nairobi Chapter, GRC Engineering Club
  • GRC Engineering Club
  • GIAC Advisory Board member
  • Women in Cybersecurity member

Open To

I am interested in opportunities involving:

  • GRC engineering
  • Security compliance
  • Technical GRC
  • Security assurance
  • Cyber risk and controls
  • Cloud governance
  • Compliance automation
  • Audit readiness
  • Security program management
  • Product security governance

I am also open to collaboration on practical projects involving compliance-as-code, policy-as-code, automated evidence, secure infrastructure, continuous control monitoring, privacy engineering, and security education.

Connect

Pinned Loading

  1. aws-grc-evidence-and-control-assessment aws-grc-evidence-and-control-assessment Public

    Identity-first AWS GRC automation for resource inventory, selected S3 and IAM control assessments, findings, management reporting, and integrity-verified evidence packaging.

    Python

  2. grc-continuous-compliance-lab grc-continuous-compliance-lab Public

    Fictional SOC 2 compliance engineering lab using Probo for risk, control, asset, third-party, and task management.

  3. grc-compliant-s3-resource grc-compliant-s3-resource Public

    Terraform-based AWS S3 control implementation demonstrating secure cloud storage, automated verification, and audit-ready evidence.

    HCL

  4. grc-control-register-validator grc-control-register-validator Public

    A tested Python tool for validating fictional GRC control registers stored in CSV format.

    Python