Download PDF

Experience

  1. Jan 2025 - Present

    IT Audit Senior

    Schellman · Columbus, Ohio

    • Cut audit preparation time 25% in six months by redesigning the sampling process for a large enterprise client, using the Fieldguide API, Python, and local bash scripts.
    • Identify and document control deficiencies across 10+ SOC examinations a year, then partner with control owners to build and execute remediation plans.
    • Lead control walkthroughs with engineering, IT operations, internal audit, and HR stakeholders to scope and validate evidence across the control environment.
    • Map client control sets to SOC 2, ISO 27001, and HIPAA requirements to identify the high-watermark controls and reduce repeat findings.
    • Guide first-time clients through their initial SOC 2 examination, mapping existing controls to the Trust Services Criteria to identify where controls currently operate and where coverage is thin.
    • Mentor 3+ associate auditors on AICPA guidance, reviewing their workpapers and testing approach.
  2. Jul 2023 - Dec 2024

    IT Audit Associate

    Schellman · Columbus, Ohio

    • Tested controls across 15+ SOC 1 and SOC 2 engagements, focused on access management, change management, and logical security.
    • Cut audit cycle times 40% by driving adoption of a new audit platform, Fieldguide, and running team enablement sessions.
    • Served as the primary point of contact for client control owners through evidence collection, keeping engagements on schedule.

Education

  1. Jul 2026 - Present

    Master of Science, Cybersecurity and Information Assurance

    Western Governors University · Remote

    • Expected graduation July 2027.
  2. Aug 2020 - Dec 2022

    Bachelor of Science in Business Administration, Accounting

    The Ohio State University · Columbus, Ohio

Projects

  • Sep 2026

    CGE-P Capstone

    I inherited a patient intake API that shipped non-compliant on purpose and wrapped it so the same system could stand up to a HIPAA review.

    • CGE-P Capstone
    • Terraform
    • OPA
    • AWS
    • HIPAA
    • OSCAL
    • KMS
    • Object Lock
    • Rego
    • Conftest
    • GitHub Actions
    • Cosign
    • CloudTrail
  • Aug 2026

    CGE-P Curriculum

    The CGE-P labs in one repo. Infrastructure that comes up compliant, policies that block a bad plan, and a pipeline that keeps the proof.

    • GRC Engineering Academy
    • Terraform
    • OPA
    • AWS
    • GCP
    • NIST 800-53
    • KMS
    • Object Lock
    • Rego
    • Conftest
    • GitHub Actions
    • OIDC
    • Cosign
    • Sigstore
    • CloudTrail
    • Security Hub
    • Org Policy
    • WIF
    • OSCAL

Skills

Audit & Assurance

  • SOC 1 & SOC 2 examinationsLead end-to-end Type I and Type II examinations across 10+ clients a year.
  • Control walkthroughsScope and validate evidence with engineering, IT operations, internal audit, and HR stakeholders.
  • Evidence collectionPrimary point of contact for client control owners, keeping engagements on schedule.
  • Deficiency identification & remediationDocument control deficiencies, then partner with control owners to build and execute remediation plans.
  • Readiness for first-time examinationsGuide clients through an initial SOC 2, identifying where controls operate today and where coverage is thin.
  • Workpaper review & mentoringMentor associate auditors on AICPA guidance and audit methodology, reviewing their workpapers and testing approach.

Frameworks & Standards

  • SOC 2 (Type I / II)Map existing control sets to the Trust Services Criteria.
  • SOC 1 (Type I / II)Controls at a service organization relevant to user entities' financial reporting.
  • ISO 27001
  • HIPAA
  • NIST SP 800-53
  • Control rationalizationMap one control set across SOC 2, ISO 27001, and HIPAA to reduce overlapping tests and repeat findings.

GRC Competencies

  • Control design & testingAssess whether a control is designed to meet its objective, then test operating effectiveness.
  • IT general controls (ITGC)
  • Access managementA primary testing focus across 15+ SOC 1 and SOC 2 engagements, alongside change management and logical security.
  • Change management
  • Logical security
  • Risk assessment
  • Third-party / vendor risk

Audit Process & Delivery

  • Sampling designRedesigned the sampling approach for a large enterprise client, cutting audit preparation time 25% in six months.
  • Audit tooling adoptionDrove adoption of a new audit platform and ran team enablement sessions, cutting cycle times 40%.
  • Stakeholder communicationTranslate control findings into remediation owners can act on, across technical and non-technical teams.

GRC Engineering (in progress)

  • TerraformCompliant-on-creation infrastructure in the CGE-P Curriculum build.
  • Open Policy Agent (Rego)Policy library that gates a Terraform plan on NIST 800-53 controls in the CGE-P Curriculum build.
  • Conftest
  • Policy-as-code
  • GitHub Actions
  • AWS
  • GCP

Contact

See also certifications and projects.