AI governance · GRC engineering · incident response. I make governance, risk, and compliance executable — including for AI systems — through controls as code, automated evidence, and continuous monitoring, and I lead the incidents when those controls are tested for real.
17 years across GovTech, international healthcare, critical infrastructure, and US federal / state / local government — environments where the audit burden is heaviest, AI assurance is becoming mandatory, and the cost of getting it wrong is real.
I build and audit AI management systems to ISO/IEC 42001 — the certifiable standard for governing how AI is developed, deployed, and operated safely. I pair it with the NIST AI Risk Management Framework and ISO/IEC 23894 to give regulated organizations a defensible answer to the question every board and auditor is now asking: how do you know your AI is secure, accountable, and under control?
ISO/IEC 42001 Lead [Implementer / Auditor] — [credential ref / year]
This is the rare convergence I lead with: someone who can write the AI control, map it to the frameworks, automate its evidence, and respond when an AI-driven system is part of an incident.
AI governance & assurance
- ISO/IEC 42001 AI management systems — establishing, implementing, and auditing AIMS for secure AI development and deployment.
- AI risk management — NIST AI RMF and ISO/IEC 23894 applied to real model and system risk, not checkbox theater.
- AI controls as code — extending compliance-as-code to AI-specific controls (data governance, model lifecycle, transparency, human oversight).
GRC engineering
- Compliance-as-code — control mapping and crosswalks across frameworks; policy-as-code; OSCAL-based control catalogs and SSP components.
- Evidence automation & continuous control monitoring — pipelines that collect, timestamp, and store control evidence so audits stop being fire drills.
- Risk quantification & tooling — turning qualitative risk into something measurable, and wiring GRC platforms into the systems that hold the data.
Incident response
- I lead incidents end-to-end — detection through containment, eradication, recovery, lessons-learned — including incidents involving AI-enabled systems — and feed what I learn back into the control set.
I think in process, controls, and decisions — not product logos. I'm fluent in automation and build it where it counts (Python / IaC); for heavier engineering I architect and direct. Most of what's here is deliberately vendor- and framework-neutral so it ports across stacks.
Frameworks: ISO/IEC 42001 · NIST AI RMF · ISO/IEC 23894 · NIST 800-53 / 800-171 / 800-61 · OSCAL · MITRE ATT&CK · ISO/IEC 27001 · CSF Regimes: FedRAMP · CMMC · StateRAMP · HIPAA / HITRUST · CISA ConMon
| Repo | What it shows |
|---|---|
| 🤖 ai-management-system | ISO/IEC 42001 + NIST AI RMF controls as code — securing AI development end-to-end |
| 🏗️ controls-as-code | Framework crosswalks, OSCAL control components, policy-as-code — GRC that executes |
| 📊 evidence-automation | Continuous control monitoring: collect → timestamp → store control evidence on a schedule |
| 🧭 emerging-threat-triage | Tool-agnostic IR framework — advisory to action, branch logic, NIST-phase mapping |
| 📑 incident-case-studies | Sanitized, method-focused postmortems — how I scope, contain, and decide |
Everything in these repositories is original or sanitized. Nothing reflects confidential details of any employer, client, or engagement — environments are generalized, indicators are synthetic, evidence samples are mock. That discipline is the same standard I bring to handling regulated and AI-governance material as a practicioner.