Mission: GRC & Security Operations

From criminal investigations to information security

An unlikely trajectory — from Interpol investigations to building GRC programs from zero in fintech. The common thread? Protecting what matters, with evidence and precision.

Every phase was a step toward the same destination

What looks like career pivots on paper is actually one continuous trajectory — from investigating human threats to defending digital ones. Each phase built on the last.

2010 – 2016 · THE FOUNDATION

International Law Enforcement

Ministry of Interior, Bulgaria · Interpol · Europol · SIRENE

Started in Drug Enforcement (2010–2013) performing undercover and operational work against organized crime rings, before advancing to the International Cooperation Unit. There, I managed joint cross-border projects and collaborated directly with Interpol, Europol, and SIRENE. Every audit I run today relies on the skills forged here: flawless evidence integrity, precise documentation under strict legal standards, and high-stakes risk assessment.

2019 – 2021 · THE BRIDGE

Global Incident Management

DXC Technology · Senior Major Incident Manager

Led major incident response for global enterprise clients — coordinating engineers across time zones under SLA pressure. This is where I discovered that investigation skills translate directly to triage: structured evidence gathering, hypothesis testing, and communicating under pressure. I also participated in client compliance audits, gaining hands-on exposure to audit processes and control assessments that would inform everything I built next.

2021 – 2026 · THE MISSION

GRC & Security Operations in Fintech

Gravity Payments · IT, Security & GRC

This is where it all came together. Co-built the Information Security program from zero alongside the CISO at a PCI-regulated payment processor. Co-authored the complete policy suite with the CISO, stepping in as the primary owner to maintain and drive enforcement. Designed a Common Controls Framework harmonizing SOC 2, PCI DSS, and NIST, and led both the SOC 2 and PCI DSS compliance programs—with a strategic roadmap to expand into additional frameworks. Championed the Third-Party Risk Management program (45+ vendors), implemented GRC automation, and ran 24/7 incident response. Every incident became a direct feedback loop into stronger controls.

Tools I build to make governance fly

I believe GRC should accelerate the business, not create drag. These tools automate compliance, assess risk, and reduce friction between security and engineering.

In Flight
🔍

Compliance Evidence Collector

Python CLI tool that connects to Okta, GitHub, and AWS APIs, gathers security evidence, evaluates it against SOC 2 controls defined in YAML, and generates automated pass/fail compliance reports. Turns weeks of manual evidence gathering into minutes.

Python REST APIs CLI YAML Okta AWS
SOC 2
Operational
🛡️

AI Governance Risk Assessor

Interactive web application applying the NIST AI Risk Management Framework across Govern, Map, Measure, and Manage functions. Evaluates AI use cases through structured risk assessments and produces risk-scored governance reports.

JavaScript HTML/CSS Risk Scoring Interactive
NIST AI RMF
Pre-Launch

SOC 2 Readiness Assessment

Self-service readiness assessment evaluating organizational controls against SOC 2 Trust Service Criteria. Identifies gaps, scores maturity levels, and generates prioritized remediation roadmaps for audit preparation.

Web App Assessment Engine Remediation
SOC 2 TSC
Pre-Launch
📋

ISO 27001 Gap Analysis

Automated gap analysis mapping existing controls to ISO 27001 Annex A requirements. Scores maturity across all 93 controls and generates implementation roadmaps with effort estimates and prioritization.

Web App Maturity Model Gap Analysis
ISO 27001
Operational
📊

Incident Response Dashboard

Operational intelligence dashboard tracking MTTD, MTTR, severity distribution, SLA compliance, and root cause analysis. Demonstrates how incident data drives continuous improvement.

Dashboard Metrics MTTD/MTTR SLA
ITIL
Operational
🛡️

Security Program Maturity Assessment

Interactive 25-question self-assessment across the NIST CSF functions — Identify, Protect, Detect, Respond, Recover. Generates maturity scores and prioritized recommendations.

Assessment Maturity Model Interactive
NIST CSF

Where I operate

📜
Security Governance
Policy authoring, standards development, security awareness, control ownership mapping, executive reporting
⚖️
Risk Management
Risk assessments, risk register management, KRI design, risk-based decision frameworks, remediation tracking
🔒
Compliance & Audit
SOC 2, PCI DSS, NIST CSF — audit coordination, control testing, evidence collection, audit readiness programs
🔗
Third-Party Risk
Vendor security assessments, due diligence, risk scoring, remediation follow-up — 45+ vendor program built from scratch
🚨
Incident & Problem Management
24/7 incident response, bridge call coordination, root cause analysis, blameless retrospectives, playbook development
⚙️
GRC Automation
Drata, Vanta — platform implementation, control mapping, automated evidence collection, Python scripting for automation
💳
Fintech & Payments
PCI DSS compliance, payment processing operations, cardholder data security, merchant risk, regulatory reporting
📊
Tools & Platforms
Datadog, CrowdStrike, Okta, Jira, Confluence, Python, SQL — from monitoring to automation

Certifications & Education

📋
PMP — Project Management Professional
PMI
📘
ITIL 4 Foundation
AXELOS — Service Management
📐
Advanced Certified ScrumMaster (A-CSM)
Scrum Alliance
🎓
CISA — Certified Information Systems Auditor
ISACA (In Progress)
🛡️
CISM — Certified Information Security Manager
ISACA (In Progress)
🤖
AIGP — AI Governance Professional
IAPP (In Progress)

GRC professionals should be leading AI governance

Every organization is racing to adopt AI, most without guardrails. The conversation is split between technologists who understand models but not risk frameworks, and regulators who understand compliance but not the technology. GRC professionals sit at the intersection.

We already know how to assess risk, build control frameworks, and create audit trails that satisfy regulators. The NIST AI RMF isn't a departure from traditional GRC — it's an extension of it. The same skills that build a SOC 2 program can build an AI governance program.

The organizations that will win aren't the fastest to adopt AI — they're the ones that move fastest with confidence. That's why I'm building tools like the AI Governance Risk Assessor and pursuing the AIGP. The future of GRC isn't just protecting what exists — it's enabling what's next.

Let's connect

Whether it's building a GRC program from scratch, improving your incident response, or automating compliance — I'd love to hear from you.