GRC Analyst
Send a job offer directly to this candidate
I help organizations figure out where the gaps in their controls are, why they exist, and what to do about them before an auditor (or an attacker) finds out first.
My background is a mix of hands-on IT support and GRC work. I spent five years as an IT Support Specialist, which meant I was the one investigating security incidents, reviewing access controls, and writing up what went wrong and why. That gave me a ground-level view of how policies actually play out (or fail) day to day.
I've since moved into GRC work, running operational and compliance audits, evaluating controls against frameworks like NIST, SOC 2, ISO 27001, and HIPAA, and turning findings into reports leadership can actually act on.