Focus
Information Security Governance
Information Security / GRC / AI Governance
My work focuses on making security governance, audit readiness, privacy, and responsible AI easier to understand, document, and defend.
Focus
Information Security Governance
Experience
4+ years experience
Current work
Defined.ai
Frameworks
ISO 27001 / 27701 / 42001, SOC 2
Profile
This site is here to make the practical parts of my work easy to understand: the frameworks I work with, the evidence I care about, and how I think about keeping governance usable inside real teams.
I work across information security, governance, risk, and compliance, with a focus on ISO management systems, SOC 2 controls, privacy, and strategic IT management.
I am especially interested in work where security, privacy, and responsible AI need to be clear enough for real teams, real reviews, and real decisions.
Experience
A shorter view of the work covered in my CV, focused on the security, GRC, risk, and compliance responsibilities that have shaped my career so far.
June 2025 - Present
Defined.ai
My current role sits across GRC program management, audit support, vendor risk, and risk ownership.
May 2022 - May 2025
Strolid
This role built the foundation for my security and compliance work across policies, audits, incidents, and IT controls.
What I Work On
My work includes policies, control mapping, risk registers, audit evidence, and ownership models that teams can maintain.
I support ISO 27001, ISO 27701, and ISO 42001 work across information security, privacy, and AI management.
I organize evidence, map trust services criteria, support customer and vendor responses, and work with control owners.
I work on responsible AI governance with attention to data handling, transparency, and regulatory expectations.
How I Work
I start by understanding the current setup, then connect the requirements to practical controls, evidence, and reporting that people can actually use.
01
I start by getting clear on scope, owners, business context, evidence gaps, and the risks that need attention.
02
I connect ISO, SOC 2, privacy, and AI governance requirements to the work teams already do.
03
I work on documentation, review routines, exception handling, and evidence libraries that are easy to use.
04
I turn findings into clear reporting, remediation plans, and habits that improve the program over time.
Framework
Information security management
Risk treatment, controls, policies, internal audit, management review
Privacy information management
PII processing, privacy controls, roles, retention, supplier handling
AI management system governance
AI risk checkpoints, accountability, transparency, lifecycle documentation
Trust services control readiness
Control narratives, owner evidence, exception tracking, audit response
Work Themes
I work on control performance, ownership, exceptions, and review cadence without turning evidence into busywork.
I bring privacy expectations into security control work so policies, assessments, and procedures support each other.
I support AI governance with controls for accountability, data provenance, risk review, and management documentation.
Frameworks and background
CV
It gives a fuller view of my experience, education, and the security and governance work I have been building.
CV preview
Contact