LEADERSHIP PROFILE
Senior GRC and Information Security practitioner with 15+ years of experience building and improving governance, risk, security, compliance, and audit programs across SaaS, cloud, financial services, healthcare, and technology environments.
Practical Execution
Program Maturity
Risk & Assurance
GRC Technology
Translating complex regulatory compliance frameworks into actionable, high-performing security controls that protect corporate assets and support growth.
Designing, scaling, and operationalizing governance, risk, and compliance programs from the ground up for highly regulated enterprise environments.
Delivering robust risk management frameworks and continuous assurance to build trust with customers, auditors, and key stakeholders.
Automating manual compliance workflows and integrating modern GRC technology platforms to reduce operational friction and overhead.
PROVEN CAPABILITIES
A proven track record of designing, implementing, and scaling enterprise-grade governance, risk, and compliance frameworks across highly regulated financial and technology sectors.
1K+
UCF Controls
100+
Banking Apps
100+
Vendor Audits
600+
GRC Guides
Mapped extensive Unified Compliance Framework controls to streamline multi-framework compliance across diverse global standards and regulatory mandates.
Supported secure operations for critical banking applications, ensuring alignment with stringent financial sector security and data protection regulations.
Conducted comprehensive third-party risk assessments annually, safeguarding the supply chain and identifying critical vendor vulnerabilities.
Authored and published authoritative practitioner guides, establishing industry best practices for modern governance, risk, and compliance professionals.
SOC 2
NIST
ServiceNow IRM
M&A
SOC 2 Type I to Type II program experience, establishing robust continuous control monitoring and auditing workflows to satisfy strict enterprise security requirements.
NIST Risk Assessment Playbook design, delivering structured methodologies for identifying, assessing, and mitigating critical information security risks across the enterprise.
ServiceNow IRM/GRC implementation, automating compliance tracking, policy management, and audit evidence collection to streamline multi-framework operations.
Multiple M&A governance integrations, successfully aligning security postures, risk registers, and compliance baselines during complex corporate acquisitions.
As the culmination of a fifteen-year enterprise security journey, A3INFOSEC provides senior-level advisory to help organizations operationalize robust risk management and modern compliance frameworks.
ComplianceAutomation
TPRM
Cloud & AI Governance
Accelerating SOC 2 and ISO 27001 readiness through modern GRC program development and compliance automation frameworks designed to scale with your engineering team.
Managing third-party risk with robust software supply-chain security, including SBOM, AIBOM, and comprehensive risk mitigation strategies built for modern enterprise ecosystems.
Establishing forward-looking cloud governance, AI governance programs, and AIBOM alignment to safely secure emerging enterprise technologies and maintain continuous compliance.
Executing a multi-year GRC and IRM roadmap to unify compliance frameworks, automate control traceability, and implement continuous monitoring across global enterprise operations.
The Challenge
The Approach
The
Impact
Managing disconnected compliance requirements across SOC 2, ISO, CUI, and SOX. The enterprise faced fragmented control tracking, manual audit preparation, and a lack of real-time visibility into continuous monitoring across systems.
Designed a ServiceNow IRM implementation mapping over 1,000 UCF controls. Developed robust APIs for system integration, established rigorous User Acceptance Testing (UAT), and automated control traceability workflows.
Achieved continuous compliance monitoring with automated evidence collection. Reduced audit preparation cycles, established a single source of truth for control mappings, and enabled real-time risk reporting.
1,000+
UCF Control Mappings
4
Frameworks Unified
100%
Continuous Traceability
Following its acquisition by News Corp, Move (Realtor.com) required rapid alignment with enterprise security standards. We designed and executed a comprehensive GRC program to secure cloud assets and foster stakeholder adoption.
The Challenge
The Approach
The
Impact
Integrating legacy systems into News Corp's stringent framework required rapid policy alignment, structured data classification, and robust AWS security governance without slowing down active development pipelines.
We established critical-asset 'Crown Jewels' governance, embedded automated compliance checks into DevSecOps workflows, and executed targeted risk assessments to bridge operational gaps and align security assurance.
Delivered a unified GRC program that secured rapid stakeholder adoption, streamlined continuous compliance across cloud environments, and successfully validated alignment with parent company enterprise standards.
Framework-Driven Assessments
NIST Playbook & Archer GRC
We conducted comprehensive security assessments spanning Agile releases, core infrastructure, internal applications, and third-party vendors. Compliance and control mapping were validated against ISO 27001, PCI DSS, NIST, and FFIEC standards.
To operationalize GRC, we built a custom NIST-based Risk Assessment Playbook for standardized scoring, and integrated all assessment workflows directly into RSA Archer for centralized enterprise risk management.
50+
Policy Gap Analyses
20
Technical-Standard Analyses
Executive Risk Reporting
Designed and delivered high-impact risk posture dashboards and reporting structures to provide executive leadership and board members with actionable risk insights.
Rigorous security alignment, policy harmonization, and post-acquisition governance integration across high-profile enterprise transactions, ensuring continuous compliance and robust risk management throughout the transition.
Move / News Corp
PayPal / Xoom
SAP Ariba
Led critical-asset governance and post-acquisition integration. Executed comprehensive policy and control-gap assessments to align security postures, ensuring compliance across newly acquired corporate entities.
Spearheaded governance alignment and remediation. Directed critical-asset governance and post-acquisition integration to satisfy rigorous FinTech compliance benchmarks and secure transition pathways.
Collaborated on policy and control-gap assessments. Supported governance alignment, remediation, and post-acquisition integration within complex enterprise cloud procurement environments.
BUSINESS IMPACT
A robust GRC program is more than a compliance checklist. It is a strategic driver that protects reputation, streamlines operations, and enables secure, confident business scaling.
Stronger Governance
Clearer Risk Visibility
Continuous Audit Readiness
Direct alignment of security frameworks with your business objectives drives corporate accountability and supports sustainable, secure organizational growth.
Structured risk registers identify, assess, and mitigate enterprise threats, providing clear visibility and actionable insights for key stakeholders.
Robust, repeatable controls keep your organization perpetually prepared for stringent external audits, turning compliance reviews into routine validations.
Scalable Controls
Better Evidence
TPRM & Automation
Flexible security controls adapt seamlessly as your cloud systems, engineering teams, and product lines scale without introducing operational friction.
Structured, reliable evidence repositories simplify compliance validation, reduce audit friction, and eliminate the need for manual data gathering.
Disciplined Third-Party Risk Management paired with practical compliance automation eliminates repetitive operational tasks and significantly reduces compliance overhead.
DIRECT ADVISORY
Ready to Begin?
Let’s Discuss What Your GRC Program Needs Next.
Schedule a brief call to evaluate your compliance roadmap and resource needs.
Every engagement begins with a practical conversation about your frameworks, timelines, technology, and internal capacity. We will address your current GRC challenges with direct access to senior GRC expertise to keep your business moving forward.


