System Security Plan Rev. 2026.1 dexcopeland.dev

Dex Copeland

GRC engineer who codes. 12-year Air Force veteran. Cloud Security Assessor.

Guardrails aren't barriers — they're protective freedom. They give us a clear line of where we shouldn't be going, while giving us the freedom to operate within those boundaries.
CTRL-IMPL
6+ shipped tools
EXP-YRS
12 years USAF
FRAMEWORKS
NIST · CMMC · ISO
STATUS
Open to collaborate
Section 1 SA · System & Services Acquisition

System Overview

I'm not your typical GRC person who lives in spreadsheets. I build tools to escape them. My work sits at the intersection of compliance automation, AI, and education — with a strong belief that guardrails aren't barriers; they're where creativity begins.

Currently a Cloud Security Assessor at the Maryland Department of Information Technology, I bring 12 years of U.S. Air Force experience across finance, network operations, and cybersecurity. I joined wanting to be a teacher — that never left. Now I build content and tools for people breaking into GRC and veterans who know there's a better way.

Compliance Automation

If it can be automated, it should be. Structured, repeatable processes replace manual, error-prone workflows.

AI in GRC

Not AI replacing practitioners — AI amplifying what they can accomplish. LLMs + OSCAL can change assessment workflows.

Education & Mentorship

Building for people entering GRC and veterans in the field who know there's a better way to do things.

Section 2 CM · Configuration Management

Implemented Controls

Shipped tools and active development — each project is evidence of controls implemented in code, not slides.

PRJ-001 RA-5 · Automation
In Development

OSCAL Assessment Orchestration Platform

Custom assessment platform leveraging OSCAL and MCP to modernize security assessments — machine-readable controls, AI-assisted analysis, and structured evidence collection.

  • Python
  • OSCAL
  • MCP
PRJ-002 SC-7 · Security
Implemented

CMMC Level 2 Gap Analyzer

Automates NIST 800-171 control tracking, gap identification, POA&M management, and PDF report generation.

  • Python
  • Streamlit
★ 3
PRJ-003 RA-5 · Automation
Implemented

spec-to-ship

Claude Code project template — from raw idea to shipped code autonomously, combining spec-driven development with agentic coding loops.

  • Claude Code
  • Spec-driven
★ 3
PRJ-004 SI-12 · Information Handling
Implemented

Disabled Veteran Salary Calculator

Calculates gross salary needed to hit take-home targets, accounting for VA disability compensation plus federal and state taxes.

  • JavaScript
★ 2
PRJ-005 RA-5 · Automation
Implemented

Claude GRC Engineering Toolkit

Official open-source GRC toolkit from the GRC Engineering Club — Claude Code plugins for evidence collection and compliance workflows.

  • Claude Code
  • GRC
PRJ-006 AT-2 · Awareness
In Development

AI Engineering from Scratch

Learn it. Build it. Ship it for others — a curriculum for practitioners entering AI engineering.

  • Education
  • AI
Section 3 PS · Personnel Security

Personnel Record

Certifications & Education

  • ISO 42001 Lead Auditor
  • CySA+
  • PenTest+
  • Google Professional Cloud Security Engineer
  • WGU B.S. Cybersecurity — Capstone Excellence Award

Frameworks & Standards

  • NIST 800-53
  • NIST CSF
  • NIST RMF
  • NIST AI RMF
  • CMMC
  • IRS Pub 1075
  • ISO 27001
  • ISO 42001

Background

  • Cloud Security Assessor — Maryland Department of Information Technology
  • 12-Year U.S. Air Force Veteran — Finance, Network/System Ops, Cybersecurity
  • Languages & Tools: Python · OSCAL · Claude Code · Streamlit
Section 4 CA · Assessment & Authorization

Collaboration POA&M

Open to mentoring, speaking, open-source collaboration, consulting, and freelance work. If you're working on something at the intersection of GRC, AI, or compliance education — let's talk.