Technology Risk, GRC, and IT audit. Eight years across financial services, healthcare, federal and DoD environments. CRISC and CTPRP certified. Currently building automation for the compliance work I used to do by hand.
Chesapeake, VA · vaughanjc2@outlook.com · LinkedIn · GitHub
I assess controls, test whether they actually operate, and write up what I find in a way the business can act on. Most of that has been in regulated environments where the evidence has to hold up to someone else's scrutiny — external auditors, federal assessors, banking regulators.
The through-line across nine roles has been the same question in different clothes: is this control real, and can you prove it? I'm now answering that question with code as well as documentation.
SOX ITGC, PCI DSS, and GDPR control evaluation at an international financial services organization. Ran recurring joiner/mover/leaver, role-based, and privileged access reviews, including exception investigation and closure validation. Owned Proofpoint phishing simulations and the Power BI reporting behind them. Participated in Change Advisory Board and assessed implementation risk.
Led the NIST SP 800-53 Revision 4 to Revision 5 control and documentation update for a DoD and U.S. Army-aligned SAP cloud authorization environment. Maintained System Security Plans, FIPS 199 categorizations, privacy documentation, and evidence repositories supporting FedRAMP and RMF authorization readiness. Ran functional and tabletop incident response and disaster recovery testing with engineers and system owners.
Planned and executed 40+ global third-party technology risk assessments for financial services and healthcare clients, end to end: scoping, evidence requests, interviews, control evaluation, risk rating, reporting, remediation, and closure. Led ISO 27001 and GDPR assessments for Lloyds Banking Group. Helped establish the third-party risk program at City of Hope. Challenged incomplete evidence, unsupported control assertions, and remediation plans that did not address the underlying requirement.
Recurring third- and fourth-party risk assessments using a customized NIST SP 800-53 methodology aligned to GLBA, FFIEC, COBIT, and PCI DSS. Helped transition the program from the Shared Assessments SIG to a NIST-based model and standardize evidence, risk-rating, and reporting practices.
Developed cybersecurity, cloud, and system-support procedures for a public-safety telecommunications program, translating technical requirements into controlled documentation validated with application and system owners.
NIST SP 800-53A and 800-171 security control assessments across Windows, network, application, and cloud environments. Policy review, personnel interviews, configuration examination, and control testing. Used Tenable Nessus and Wireshark to evaluate vulnerabilities and network safeguards. Wrote the Security Assessment Reports.
Ten Python tools that automate compliance tasks I have done manually for years. Built independently, tested against synthetic data, all source public.
These are functional prototypes tested on synthetic data, not production systems. Source on GitHub
Deployed from a CloudFormation template: private S3 bucket, CloudFront distribution with Origin Access Control so nothing but CloudFront can read the bucket, HTTPS enforced. Infrastructure defined as code and reproducible.
I reviewed the template before running it and logged two gaps against my own site: encryption is not explicitly declared, and access logging is not enabled. Neither breaks anything — S3 encrypts by default — but a control that is not declared is a control an assessor cannot verify. Source on GitHub
A six-week build taking cloud infrastructure from working to audit-defensible: compliant infrastructure as code in Terraform, policy as code in Rego, a CI gate that blocks non-compliant pull requests, cryptographically signed evidence, and a NIST SP 800-53 control mapping in OSCAL. Adding one piece per week.
NIST SP 800-53 and 800-53A, NIST SP 800-171, RMF, FedRAMP, ISO 27001, SOX ITGC, PCI DSS, GLBA, FFIEC, COBIT, GDPR, HIPAA, HITRUST, FIPS 199
Python, pandas, Power BI, Excel, Git, SQL-adjacent data work, RSA Archer, OneTrust, Diligent, eMASS, Xacta, ServiceNow, Jira, Tenable Nessus, Wireshark, Proofpoint, AWS, Azure, Terraform
CRISC — Certified in Risk and Information Systems Control, ISACA
CTPRP — Certified Third Party Risk Professional, Shared Assessments