Skill · 09
← All skills
Security

Governance, Risk & Compliance

Turning frameworks into operational, audit-ready controls.

At a glance
15%
Critical vulnerabilities reduced
Audit-ready
Standardized evidence & controls
Capabilities
6
Tools & platforms
6
Discipline
Security
Overview

Translate regulatory and industry frameworks — SOC 2, ISO 27001, NIST 800-53, HIPAA and FedRAMP — into operational security controls. Run risk assessments, control validation, continuous monitoring and audit readiness across distributed cloud environments.

Capabilities
6 areas
  • Security control assessments and risk evaluations
  • Audit readiness and standardized evidence collection
  • Framework mapping — NIST RMF (800-37), 800-53, HIPAA, FedRAMP
  • POA&M management and remediation tracking
  • Third-party / vendor risk management (TPRM)
  • Security policies, standards and procedures
Software & Tools

The stack behind the work.

The tools I reach for day to day — with a rough sense of where my depth sits.

Expert
Advanced
Proficient

NIST 800-53

Advanced

Control framework & baselines

SOC 2

Advanced

Trust Services audit readiness

ISO 27001

Advanced

ISMS controls & certification

NIST RMF (800-37)

Advanced

Risk management framework

FedRAMP

Proficient

Cloud authorization & POA&M

HIPAA

Proficient

Healthcare data safeguards

Let's work together

Have a project that needs Governance, Risk & Compliance?