IT Audit & Technology Risk, AI Governance
I help regulated organizations make evidence-based technology risk decisions that stand up to executive, audit, and regulatory scrutiny.
I began my career building and administering enterprise infrastructure and databases before moving into systems security, IT audit, technology risk, and AI governance within Tier-1 financial institutions. That progression gave me both the technical depth to understand complex environments and the governance judgment to help organizations navigate them.
As an IT auditor, my responsibility was to provide objective, evidence-based assessments. Management owned every decision; my role was to make the risks, control gaps, and supporting evidence visible enough that those decisions could withstand independent scrutiny.
Today, I work further upstream. Rather than evaluating decisions after they have been made, I help management make better decisions in the first place. By grounding governance decisions in evidence, established frameworks, and practical implementation realities, I help organizations make technology risk decisions that are explainable, defensible, and capable of withstanding executive challenge, internal audit, and regulatory review.
Targeting: Senior IT Audit Manager · Technology Risk Manager · AI Governance Lead · AI Risk & Controls Architect
Five Strongest Examples
Each demonstrates a different dimension of governance capability.
AI Architecture & Innovation
AI Governance in Operation
Governed AI environment with specialized agents, runtime controls, observability, and evidence — not a policy about AI, but a governed AI system.
Executive & Risk Communication
Board Risk Appetite Report
Translated technical findings into board-level risk decisions with clear governance recommendations and quantified risk appetite thresholds.
Tooling & Automation
Control Profiler
Metadata-driven classification engine profiling controls across 7 dimensions with local AI. One pass enables mapping to any framework.
Methodology & Technical Judgment
Threat-Informed CRI Assessment
Evidence-traceable assessment methodology mapping institutional controls to CRI diagnostic statements through deterministic rules and AI-assisted analysis.
Threat Intelligence & Detection
CRI Threat Advisory
Transforms control coverage gaps into threat-informed risk intelligence — mapping gaps to ATT&CK techniques, D3FEND countermeasures, detection logic, and prioritized remediation.
Threat-Informed Methodology
A 12-stage process grounded in NIST CSF 2.0 — from asset classification through threat profiling and coverage analysis to evidence packaging. Likelihood is driven by adversary behavior, not opinion. Impact is driven by control gaps, not guesswork. Every finding is traceable.
Frameworks & Standards
Grounded in the frameworks that matter to regulators, auditors, and boards.