portfolio.sh
secure session

$ whoami

Ricardo Lewin Lewinsohn

I design and scale GRC programs for fast-growing technology companies, translating risk, resilience, and compliance requirements into practical, accountable operating processes.

Profile loaded successfully.

A GRC engineer focused on making governance practical, connecting security requirements with accountable and sustainable execution.

profile.tsread-only
const ricardo = {
role: "GRC Engineer",
mission: "connect governance, business priorities, and technical execution",
domains: [
"governance", "risk", "compliance",
"identity", "audit readiness", "security operations""business continuity""compliance automation"
],
approach: "practical, collaborative, and evidence-driven"
};

Core modules.

Three areas that define how I operate across security and governance programs.

assurance.modulestable

Compliance & Assurance

Control design, evidence quality, audit readiness, and continuous compliance across complex security frameworks.

PCI DSSSOC 2ISO 27001Audit Readiness
risk-resilience.moduleactive

Risk & Resilience

Enterprise risk assessment, accountable treatment plans, business continuity, and disaster recovery practices.

Risk ManagementBCPDRISO 22301
grc-engineering.moduleconnected

GRC Engineering

Platform ownership, workflow automation, service design, and practical integrations that make governance scale.

AutomationAuditBoardIntakeEvidence

Execution log.

Selected experience showing how compliance requirements become operating processes.

$ execute --scope grc

TRACTIAN // GRC & Security

Leading risk management, business continuity, disaster recovery, and broader GRC initiatives at an industrial technology company that combines software, hardware, IoT, and AI for maintenance and reliability operations.

  • Established an official GRC intake process and launched an internal help center.
  • Automated security questionnaire workflows to improve consistency and response efficiency.
  • Conducted risk assessments across business functions and created the enterprise risk management program.
  • Improved governance documentation and implemented workflow automations.
  • Developed business continuity and disaster recovery practices alongside the broader compliance program.
Risk ManagementBCP & DRISO 27001ISO 22301ISO 42001SOC 2FedRAMP

$ execute --scope grc

Azion // GRC & Security

Progressed from IT Operations Intern to Information Security Analyst III, moving from scalable IT operations and endpoint governance into ownership of GRC programs, risk management, and audit readiness.

role_progression.log

  1. Information Security Analyst III
  2. Information Security Analyst II
  3. Information Security Analyst I
  4. IT Operations Analyst II
  5. IT Operations Intern
  • Delivered full PCI DSS 4.0.1 compliance, implementing newly applicable requirements ahead of schedule.
  • Led and matured GRC programs across PCI DSS, SOC 2, and ISO frameworks.
  • Optimized AuditBoard workflows and control structures, reducing audit preparation time by 20%.
  • Built Python and workflow automations for compliance operations, evidence collection, and control execution.
  • Reduced tooling expenses by BRL 150,000 per year without impacting compliance operations.
  • Implemented endpoint and identity controls across 250+ macOS devices and established the first centralized IT asset inventory.
PCI DSSSOC 2ISO 27001AuditBoardPythonJira

Selected repositories.

Selected GRC programs showing compliance delivery, platform engineering, and scalable service design without exposing confidential information.

projects/auditboard-grc-automation

Azion

GRC platform implementation & automation

Implemented and operated AuditBoard with standardized control structures, evidence collection, policy and risk workflows, and supporting automation for recurring compliance activities.

result.output20% reduction in audit preparation time
AuditBoardWorkflow AutomationEvidence
projects/grc-intake-automation

TRACTIAN

GRC intake & questionnaire automation

Created an official GRC intake process and internal help center, then automated security questionnaire workflows to improve consistency and make governance support easier to access.

result.outputA scalable entry point for GRC requests and guidance
Service DesignQuestionnairesAutomation

Tools in the environment.

Platforms and technologies used across governance, security, IT, and automation workflows.

01

Vanta

GRC

02

AuditBoard

GRC

03

OneTrust

GRC

04

AWS

Cloud

05

Google Workspace

IT

06

JumpCloud

Identity

07

Apple Business Manager

IT

08

GitHub

Engineering

09

Jira & Confluence

IT

10

Jira Service Management & Assets

IT

11

Python

Engineering

12

n8n

Engineering

13

Tenable

Security

14

Wazuh

Security

15

Teleport

Identity

16

Vault

Security

17

SonarQube

Engineering

18

KnowBe4

Security

Framework context.

Framework experience and verified credentials across security, resilience, AI governance, and compliance.

frameworks.json
  • SOC 2Security
  • ISO 27001Security
  • ISO 22301Resilience
  • ISO 42001AI Governance
  • FedRAMPSecurity
  • PCI DSSPayments
  • LGPDPrivacy
  • GDPRPrivacy

certifications.env

// Credentials verified against the professional profile.

VERIFIED // MastermindISO/IEC 27001:2022 Lead Auditor
VERIFIED // MastermindISO/IEC 42001:2023 Lead Auditor
VERIFIED // VantaVerified Vanta Admin
VERIFIED // JumpCloudJumpCloud Advanced Certification 2025
VERIFIED // PROFESSIONAL PROFILEITIL 4 Foundation Certificate in IT Service Management
VERIFIED // AuditBoardAuditBoard Certified Core Administrator
VERIFIED // VoxyVoxy Proficiency Achievement Certificate

Initialize connection.

$ open connection.config

connect(career, security, governance)

Open to conversations about GRC, security compliance, audit readiness, and international opportunities.