Compliance as engineering work, not paperwork
Contributed to achieving both SOC 2 and ISO 27001 certification, with a focus on risk management, and authored the IT policies and procedures that turned the controls into how the business actually operates.
Security and Compliance, 2021-Present, nimbus Cloud
Enterprise and government buyers ask hard questions about security posture, and a security questionnaire is not something you can talk your way through. Either the controls exist and you can evidence them, or the deal stalls.
The trap with certification is treating it as a documentation exercise. You can write a policy that describes a control nobody performs, pass an audit, and be no safer than you were. That approach also has to be redone from scratch every cycle.
I treated the control set as an engineering backlog rather than a compliance one. Where a control could be enforced by a system, we enforced it by a system, so the evidence is a by-product of the control working rather than a separate artefact somebody assembles before an audit.
Authored the IT policies and procedures covering MDM, Intune and Group Policy so that operational consistency has a written definition and a technical enforcement point behind it.
Risk management was the part that mattered most. Identifying what actually threatens the platform and the customer data in it, deciding deliberately what to mitigate and what to accept, and revisiting that on a cadence rather than annually under pressure.
Both SOC 2 and ISO 27001 certification achieved, with the underlying controls running as normal operations rather than as an audit-time scramble.
Security questionnaires became a retrieval exercise instead of a fire drill, which matters commercially when enterprise deals depend on the turnaround.
SOC 2, ISO 27001, Risk Management, IT Policy, Audit Readiness