Skip to main content
Ledy FlorezLF
Open to opportunities

Ledy Florez

@ledyflorez

GRC & IT compliance risk analyst blending legal expertise with hands-on cybersecurity implementation.

Germany
Message

What I'm looking for

I’m looking for a junior GRC, IT Compliance, or Information Security Analyst role in Germany or remote within Europe—where I can translate regulations (ISO 27001/GDPR/EU AI Act) into controls, documentation, and risk processes with a legal + cybersecurity approach.

I’m a GRC-focused information security professional combining a legal background with hands-on technical training in governance, risk, and compliance. I hold a Master’s in Digital Law (Data Protection, Cybersecurity & Compliance) and completed a 3000-hour Cybersecurity program specializing in AI Cybersecurity at MSIT Berlin.

In my most recent role as a GRC Specialist internship at RESEARCHPRENEURS, I worked independently across the full compliance lifecycle—driving ISO 27001 gap analysis, supporting ISMS/policy documentation, and executing GDPR compliance activities (including DPIA and DPA review). I also built GRC artifacts such as a RoPA register from scratch for 20+ processing activities, and developed a prioritized risk register with mitigation actions, owners, and review cycles.

What sets me apart is how I connect legal interpretation to technical execution: I translate regulations into implementable controls and evidence, whether that’s cookie compliance (audit-ready policy and vendor review) or multi-framework regulatory analysis covering the EU AI Act and TTDSG. I’m actively seeking junior GRC, IT Compliance, or Information Security Analyst roles in Germany or remote within Europe.

Experience

Work history, roles, and key accomplishments

RESEARCHPRENEURS logoRE

GRC Specialist

Feb 2026 - Apr 2026 (2 months)

-Conducted ISO 27001 gap analysis, built an asset inventory in Eramba GRC, and developed a full policy pack (DPIA, BYOD, remote work, acceptable use, access control) aligned with ISO 27001 and GDPR.

-Performed structured risk assessments (likelihood, impact, residual risk scoring) and built a prioritized risk register with mitigation actions, control owners, and review cycles.

-Delivered a multi

CB

Professional development

Career Break

Jan 2019 - Oct 2023 (4 years 9 months)

-Relocated to Germany and completed intensive English and German language courses (B2 level) as preparation for postgraduate studies and career development.

-This period laid the foundation for successful postgraduate studies in Digital Law and technical training in cybersecurity.

Self-employed logoSE

Freelance Legal Counsel

Jan 2017 - Jan 2019 (2 years)

-Advised SMEs and individuals on labor and social insurance compliance, contributing to reduced legal exposure and improved regulatory adherence.

-Drafted over 100 contracts and legal submissions, supporting favorable outcomes in administrative and civil proceedings.

Fabio Salazar- Lawyer logoFL

Legal Coordinator

Dec 2015 - Dec 2016 (1 year)

-Managed legal collections across 200+ active cases, ensuring data accuracy and timely documentation to support litigation.

-Represented clients in court and advised on credit liquidation strategies, contributing to the successful recovery of outstanding debts.

Asauinsa S.A.S logoAS

Legal Counsel – Asauinsa S.A.S

Sep 2014 - Nov 2015 (1 year 2 months)

-Led internal compliance initiatives, aligning company policies with Colombian labor and commercial regulations.

-Reduced internal legal incidents by implementing structured HR protocols and representing the company in court 4+ times with a high success rate.

Education

Degrees, certifications, and relevant coursework

MA

Masterschool

Cybersecurity | AI Cybersecurity

2025 - 2026

3000-hour program · AZAV Certified · Specialization: AI Cybersecurity

Program covered: risk management & compliance (NIST CSF, ISO 27001, GDPR, HIPAA), security operations (SIEM, EDR, incident response), vulnerability management (Nmap, Nessus, Metasploit, OWASP ZAP), IAM, cloud security (AWS, GCP), AI/ML for threat detection, adversarial AI, SOAR/SOC automation, AI governance, and EU AI Act compl

MA

Masterschool

Cybersecurity Program (AI Cybersecurity), Cybersecurity (AI)

2025 - 2026

Activities and societies: Specialization areas include NIST CSF, ISO 27001, GDPR, HIPAA, SIEM/EDR, incident response, SOAR/SOC automation, adversarial AI, and AI governance.

3000-hour Cybersecurity program specializing in AI Cybersecurity, AZAV certified. Includes a 320-hour GRC internship and coursework covering risk management, security operations, vulnerability management, IAM, cloud security, and AI governance with EU AI Act compliance.

UR

Universidad Internacional de La Rioja

Master Universitario en Derecho Digital

2023 - 2024

Key modules: Cybersecurity, Digital Law Challenges, Risk Compliance, Data as Strategic Assets.

UL

Universidad Libre ®

ESPECIALIZACIÓN EN DERECHO LABORAL Y SEGURIDAD SOCIAL

2018 - 2018

UL

Universidad Libre ®

Especialización en Derecho Procesal, Derecho

2015 - 2016

UL

Universidad Libre ®

Abogada, Derecho

2006 - 2012

Tech stack

Software and tools used professionally

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan