Cybersecurity GRC Analyst with hands-on experience across governance frameworks, enterprise risk, third-party risk, and privacy compliance in healthcare, SaaS, and legal environments.
Real engagements — from consulting to capstone
Audited genzapp.com and mapped controls to PIPEDA and Bill S-5 data-blocking rules, producing a gap remediation roadmap ahead of public launch.
Maintained risk registers and compliance checklists aligned to ISO 27001 and SOC 2 control objectives, reducing pre-launch compliance gaps.
Designed a PIPEDA & GDPR compliance framework for a clinical mental-health platform — policies, data processing agreements, and PIAs to protect PII/PHI.
Ran quarterly vulnerability assessments and vendor reviews, tracking 15+ critical misconfigurations in a risk register with prioritized remediation.
Mapped organizational controls against ISO 27001 and SOC 2 Type II, producing gap analysis, remediation priorities, and an audit evidence inventory.
Led a 5-analyst team through a simulated multi-stage breach, applying NIST CSF-aligned containment and recovery, plus a board-level executive summary.
An n8n-powered tool that intakes project details, flags PHIPA retention violations against the 10-year CPSO minimum, scores risk automatically, and generates a formatted PIA doc in under a minute.
A daily n8n workflow that scans PHI records against enforceable HIPAA rules, scores violations by severity, logs a tamper-evident audit trail, and auto-drafts breach notifications — in your inbox before 8AM.
A full retention & destruction policy for a fictional Ontario hospital — mapping PHIPA, PIPEDA, and Regulation 965 across five data categories, with a built-in gap analysis against real hospital compliance failures.
A self-hosted n8n layer that tokenizes patient identifiers before anything reaches an AI model, lets GPT-4o-mini draft the letter PHI-free, then swaps tokens back — with a tamper-evident audit trail proving zero PHI exposure.
Grouped the way I actually work with them
Side experiments, outside the GRC lane
A separate space for side projects and experiments outside GRC work.
Open to full-time GRC roles and select consulting engagements — audits, framework buildouts, and privacy program design.