
Senior GRC and Information Security leader with 9+ years of experience spanning Big Four advisory (EY) and progressive leadership roles in compliance, risk management, and assurance delivery across complex SaaS and enterprise environments. Currently leads a 25-person compliance organization and operates Centers of Excellence for Risk Assessments, HIPAA, and C5, defining standardized methodologies, control frameworks, and scalable audit execution practices that drive consistency and quality across XXX SOC and risk engagements annually. Serves as the executive owner of a strategic partnership with Vanta, acting as the primary liaison between audit delivery teams and platform stakeholders to align SOC, HIPAA, and risk assessment methodologies with modern compliance automation and GRC platform workflows. Recognized for translating audit friction, customer compliance challenges, and framework interpretation issues into structured feedback loops that improve internal processes and inform platform optimization and product-adjacent improvements. Combines deep technical expertise in SOC 1, SOC 2, HIPAA, C5, CSA STAR, Microsoft SSPA, IT general controls, and NIST-based risk assessments with a systems-oriented approach to scaling compliance programs, improving audit readiness, and advancing compliance toward automated, platform-driven models, serving as a trusted advisor to internal leadership, auditors, and technology partners focused on operational excellence, SME development, and the evolution of modern GRC ecosystems.