Compliance Automation
6 in networkIf it can be automated, it should be. Structured, repeatable processes replacing manual, error-prone ones.
5 more projects in the map
Five domains, 9 projects, 19 connections — and 8 of those projects belong to more than one domain. I have ADHD. The range isn't scattered; it's one system with a lot of surface.
Five lenses on the same network — not a second project catalog. Each card names the branch; the map above holds every connection.
If it can be automated, it should be. Structured, repeatable processes replacing manual, error-prone ones.
5 more projects in the map
Not AI replacing practitioners — AI amplifying them. LLMs and OSCAL together change what an assessment can be.
No featured write-up here — still wired in the map above.
4 more projects in the map
The day job, and the source of every problem worth automating. Assessing real systems against real frameworks.
2 more projects in the map
I joined the Air Force wanting to teach. That never left. Curricula, toolkits, and lab guides for people breaking in.
3 more projects in the map
Twelve years in, and the transition math is still opaque on purpose. Tools that make it legible.
No featured write-up here — still wired in the map above.
1 more project in the map
Two projects get the full write-up. Everything else stays honest in the network — and lighter below, so these two can breathe.
Static GitHub Pages app for practicing policy-as-code from a GRC seat — pick a control framework, generate a drill, compare the human control statement with annotated Rego, review evidence guidance, mock-evaluate scenarios, and quiz yourself with progress in localStorage. Sample coverage spans NIST 800-53, SCF, CIS, SOC 2, SOX ITGC, FedRAMP, and CMMC.
Reworked cloud security lab guides so the exercises actually teach the control, not just the click path.
Still part of the network above — lighter write-ups so the two featured projects can carry the page.
I'm not the GRC person who lives in spreadsheets — I build tools to get out of them. Currently a Cloud Security Assessor at the Maryland Department of Information Technology, after twelve years in the U.S. Air Force across finance, network operations, and cybersecurity.
I joined wanting to be a teacher. That never left. Most of what I make now is for people breaking into GRC, and for veterans who already suspect there's a better way to do this.
Guardrails aren't barriers — they're protective freedom. They give us a clear line of where we shouldn't be going, while giving us the freedom to operate within those boundaries.
Open to mentoring, speaking, open-source collaboration, consulting, and freelance work. If you're building at the intersection of GRC, AI, or compliance education, I want to hear about it.