Compliance & Assurance
Control design, evidence quality, audit readiness, and continuous compliance across complex security frameworks.
$ whoami
I design and scale GRC programs for fast-growing technology companies, translating risk, resilience, and compliance requirements into practical, accountable operating processes.
A GRC engineer focused on making governance practical, connecting security requirements with accountable and sustainable execution.
const ricardo = { role: "GRC Engineer", mission: "connect governance, business priorities, and technical execution", domains: [ "governance", "risk", "compliance", "identity", "audit readiness", "security operations""business continuity""compliance automation" ], approach: "practical, collaborative, and evidence-driven"};Three areas that define how I operate across security and governance programs.
Control design, evidence quality, audit readiness, and continuous compliance across complex security frameworks.
Enterprise risk assessment, accountable treatment plans, business continuity, and disaster recovery practices.
Platform ownership, workflow automation, service design, and practical integrations that make governance scale.
Selected experience showing how compliance requirements become operating processes.
$ execute --scope grc
Leading risk management, business continuity, disaster recovery, and broader GRC initiatives at an industrial technology company that combines software, hardware, IoT, and AI for maintenance and reliability operations.
$ execute --scope grc
Progressed from IT Operations Intern to Information Security Analyst III, moving from scalable IT operations and endpoint governance into ownership of GRC programs, risk management, and audit readiness.
role_progression.log
Selected GRC programs showing compliance delivery, platform engineering, and scalable service design without exposing confidential information.
Azion
Helped lead delivery of PCI DSS 4.0.1 Level 1 Service Provider compliance, coordinating the implementation of newly applicable requirements across a globally distributed technology platform.
Azion
Implemented and operated AuditBoard with standardized control structures, evidence collection, policy and risk workflows, and supporting automation for recurring compliance activities.
TRACTIAN
Created an official GRC intake process and internal help center, then automated security questionnaire workflows to improve consistency and make governance support easier to access.
Platforms and technologies used across governance, security, IT, and automation workflows.
GRC
GRC
GRC
Cloud
IT
Identity
IT
Engineering
IT
IT
Engineering
Engineering
Security
Security
Identity
Security
Engineering
Security
Framework experience and verified credentials across security, resilience, AI governance, and compliance.
certifications.env
// Credentials verified against the professional profile.
$ open connection.config
Open to conversations about GRC, security compliance, audit readiness, and international opportunities.