// full_stack_grc

I build security programs
and the tools to run them.

GRC leader with 12+ years building compliance, risk, and security programs at high-growth tech companies and public-sector orgs. I don't just manage audits. I write the code that automates them.

12+
Years in Security & GRC
20+
Company & Customer Audits
6
Internal Apps Shipped
75%
Manual Work Eliminated
The Arc

I started in the trenches: racking servers, writing PowerShell scripts, managing VMware clusters. That sysadmin foundation taught me how infrastructure actually works, which turned out to be the thing most GRC people are missing.

From there I moved into security operations and eventually into GRC program management, leading risk programs and building a vendor assessment process covering 2,000+ vendors for the City of San Francisco (55 departments, 30,000 employees) before shifting to high-growth startups.

At Amplitude and Handshake, I found my groove building compliance programs that actually work. SOC 2, ISO 27001, and PCI DSS on the company side. SSPA, bank due diligence, and Mag 7 customer assessments on the other. I built the programs and simultaneously built the internal tooling to automate the boring parts. This is also where I learned firsthand how painful customer trust workflows are and became convinced that no human should ever manually fill out a security questionnaire again.

AI has been part of my toolkit since the early GPT-3.5 days, when I started using it to accelerate GRC workflows like policy drafting, risk analysis, and evidence mapping. That evolved into writing Python scripts with Copilot, then building full production applications with Claude. Today I use AI-assisted development to ship internal security tools on GCP, going from idea to deployed Cloud Run service in days, building tools that would otherwise never exist.

The throughline: I make security programs that don't depend on me being in the room. Automated evidence collection, self-service vendor reviews, codified risk processes. Programs that outlast the audit cycle.

Current Role
Technical Lead Manager, GRC, Handshake AI
Location
San Francisco, CA
Education
M.S. CIS, Boston University
Certifications
CISSP · CISM · OPEN FAIR
What I Do
The intersection of program management, security engineering, and software development.
🛡

Compliance

End-to-end ownership of audit programs from scoping through delivery. Zero-exception track record across SOC 2, ISO 27001, and PCI DSS. Built automated evidence collection pipelines that cut audit prep time by 80%.

SOC 2 ISO 27001 PCI DSS Anecdotes
⚖

Governance & Risk

Build governance and risk programs from scratch: policy frameworks, risk registers, risk councils, and assessment methodologies. Experienced with FAIR quantitative risk and ISO 27005 qualitative approaches.

FAIR ISO 27005 Policy Frameworks Risk Registers
💻

AI-Assisted Development

Design, build, and deploy production security applications using Claude Cowork. Full-stack apps on GCP Cloud Run that automate vendor risk, customer trust, and compliance workflows, shipping tools in days that would otherwise never exist.

Claude Cowork GCP Cloud Run FastAPI React
👥

Customer Trust & Third-Party Risk

Deployed self-service customer trust portals and AI-powered questionnaire response, reducing time spent on security questionnaires by 90%+. Built vendor risk programs assessing 2,000+ vendors with risk-based tiering and SLA-driven review processes.

SafeBase Sudozi SecurityScorecard Wolfia
🔐

Security Culture & Awareness

Enterprise-scale security awareness and training programs with onboarding controls, phishing simulations, and completion enforcement. Build security culture through education, not just policy.

KnowBe4 Phishing Simulations Training Programs
⚙

Infrastructure & Operations

Deep infrastructure roots: VMware, Active Directory, Linux/Windows ops. PowerShell and Ansible automation. The foundation that makes everything else possible.

PowerShell Ansible VMware Linux
Where I Am Now
Technical Lead Manager, GRC | Handshake AI
Jun 2025 – Present
  • Led the company's first SOC 2 Type I audit for Handshake's AI product, leveraging existing core controls to deliver a streamlined audit with zero exceptions
  • Managed vulnerability management and the security exception program, achieving 95%+ SLA compliance and 100% exception coverage across all open findings
  • Reduced manual effort on customer security questionnaires by 90%+ by deploying Wolfia and standardizing AI-assisted response workflows
  • Built and deployed 6 production internal security applications using AI-assisted development, replacing multi-day manual workflows with automated tooling on GCP Cloud Run
  • Stood up the insider threat program, deploying DLP controls to surface risk indicators and deliver data-driven briefings that inform leadership decision-making
View full experience →
Things I've Built View all →
Production applications and automation, not proofs of concept.
Production

Customer Security Intake

Fully automated security request intake system, from GTM to Linear to Wolfia. 14 systems integrated, zero manual steps. Reduced time spent on customer security questionnaires by 90%+.

→ 90%+ time reduction on questionnaires
Next.js Cloud Run Linear Wolfia IAP
View case study →
Production

TPRM | Third-Party Risk Management

Automated vendor risk platform that syncs with procurement (Ramp) and project tracking (Linear). Tracks 162 vendors with automated risk evaluation, daily syncs, and Slack alerts.

→ 162 vendors, 100% audit coverage
FastAPI React Cloud Run Ramp API Linear
View case study →
Production

Security Policies as Code

22 security policies managed as markdown in GitHub with automated publishing to Notion via GitHub Actions. Every change is version-controlled, peer-reviewed, and audit-ready.

→ 22 policies, 0 manual publishing steps
Markdown GitHub Actions Notion API Claude
View case study →
Production

Vulnerability Management Operations

Automated the operational layer behind a vulnerability management program: weekly reporting, metrics reconstruction, triage routing from code ownership, exception tracking, and program hygiene. Daily jobs handle the remembering so the program does not depend on one person.

→ Full program automation, zero manual reporting
Python Linear API Slack Claude APScheduler
View case study →
Production

Risk Intake Pipeline

Self-service security risk submission from Slack, through security team review, to a fully populated 33-column risk register and Linear tracking issue. Zero spreadsheet clicks per new risk.

→ 0 manual data entry, 6 fields to full assessment
Claude Cowork Slack Linear Apps Script
View case study →
Active

Overseer

A report-only agent that runs a daily standup over my open issues and scheduled agents. It reports what moved, what has gone quiet, what looks finished but was never closed, and which agents ran. It never changes anything.

→ Read-only, one report per weekday
Claude Cowork Scheduled Tasks Report-Only
View case study →
Useful Claude Skills View all →
Reusable skill files for Claude Code and Cowork. Drop them into your .claude/skills folder and they work immediately. Built from real production workflows, anonymized for public use.
What I've Learned View all →
Reflections on building, shipping, and figuring it out as I go.
Education & Certifications

Education

  • M.S. Computer Information Systems
    Boston University
    2013
  • A.S. Computer Networking & IT
    City College of San Francisco
    2010
  • B.A. International Relations / Russian
    UC Davis
    2007

Certifications

  • CISM
    Certified Information Security Manager
    Active
  • CISSP
    Certified Information Systems Security Professional
    Active
  • Security+
    CompTIA
    2020
  • OPEN FAIR Certified
    The Open Group
    2019