At Bloom Support Group, I built the GRC program from the ground up in Eramba, developing policies and control documentation aligned to ISO 27001 and NIST CSF. I identified seven critical gaps in data storage security and client privacy protections and drove their resolution.
I conduct risk and control assessments and work directly with third-party vendors to review SIG questionnaires and evaluate risk. I also apply the Australian Privacy Principles to support privacy compliance.
In my AWS risk assessment project, I triaged 116 scan findings into a scored risk register mapped to NIST CSF and delivered a prioritized remediation roadmap. I'm CompTIA Security+ certified, with AWS Certified Solutions Architect – Associate in progress.

