Five domains, 9 projects, 19 connections — and 8 of those projects belong to more than one domain. I have ADHD. The range isn't scattered; it's one system with a lot of surface.

Start a conversation Follow the network Hover or focus any node to see what it's wired to.

Where the work surfaces

Five lenses on the same network — not a second project catalog. Each card names the branch; the map above holds every connection.

Compliance Automation

6 in network

If it can be automated, it should be. Structured, repeatable processes replacing manual, error-prone ones.

5 more projects in the map

AI in GRC

4 in network

Not AI replacing practitioners — AI amplifying them. LLMs and OSCAL together change what an assessment can be.

No featured write-up here — still wired in the map above.

4 more projects in the map

Cloud Security Assessment

3 in network

The day job, and the source of every problem worth automating. Assessing real systems against real frameworks.

2 more projects in the map

Veteran Advocacy

1 in network

Twelve years in, and the transition math is still opaque on purpose. Tools that make it legible.

No featured write-up here — still wired in the map above.

1 more project in the map

What's actually shipped

Two projects get the full write-up. Everything else stays honest in the network — and lighter below, so these two can breathe.

Policy as Code Trainer

Static GitHub Pages app for practicing policy-as-code from a GRC seat — pick a control framework, generate a drill, compare the human control statement with annotated Rego, review evidence guidance, mock-evaluate scenarios, and quiz yourself with progress in localStorage. Sample coverage spans NIST 800-53, SCF, CIS, SOC 2, SOX ITGC, FedRAMP, and CMMC.

  • Vite
  • React
  • TypeScript
  • Tailwind
  • Rego

View on GitHub

Also on GitHub

Still part of the network above — lighter write-ups so the two featured projects can carry the page.

The record

I'm not the GRC person who lives in spreadsheets — I build tools to get out of them. Currently a Cloud Security Assessor at the Maryland Department of Information Technology, after twelve years in the U.S. Air Force across finance, network operations, and cybersecurity.

I joined wanting to be a teacher. That never left. Most of what I make now is for people breaking into GRC, and for veterans who already suspect there's a better way to do this.

Guardrails aren't barriers — they're protective freedom. They give us a clear line of where we shouldn't be going, while giving us the freedom to operate within those boundaries.

Certifications & education

  • ISO 42001 Lead Auditor
  • CompTIA CySA+
  • CompTIA PenTest+
  • Google Professional Cloud Security Engineer
  • WGU B.S. Cybersecurity — Capstone Excellence Award

Frameworks & standards

  • NIST 800-53
  • NIST CSF
  • NIST RMF
  • NIST AI RMF
  • CMMC
  • IRS Pub 1075
  • ISO 27001
  • ISO 42001

Languages & tools

  • Python
  • JavaScript
  • OSCAL
  • Claude Code
  • Streamlit

Let's connect something

Open to mentoring, speaking, open-source collaboration, consulting, and freelance work. If you're building at the intersection of GRC, AI, or compliance education, I want to hear about it.