tech grc :: product security

Tech GRC and Product Security specialist with an analytical mindset and a cross-cutting view of corporate cybersecurity: operations, network, cloud and AI. I assess the maturity of security services and operations and turn their data, risks and controls into metrics and dashboards that support decision-making. My background as a developer allows me to translate regulatory requirements into actionable technical controls.

ISC2 Certified in Cybersecurity | ISO 27001 Lead Auditor | ITIL 4 Strategist | Scrum Master | PRINCE2

Tech GRC

I assess the maturity of security operations and services using frameworks such as NIST CSF 2.0, SOC-CMM, SIM3, C2M2 and CSA CCM, and turn the results into metrics and executive dashboards. My experience includes aligning information security and AI management systems with ISO 27001, ENS and ISO 42001, risk analysis with MAGERIT, and defining security master plans.

Product Security

With a background in software development and digital product management, I define and verify security controls across the development lifecycle (SSDLC, DevSecOps): OWASP SAMM and ASVS, and SAST, DAST and SCA checks in CI/CD pipelines. I translate regulatory requirements such as GDPR and the AI Act into controls that teams can actually apply. As an ISC2 member, I adhere to its Code of Ethics.

Lab

Outside work, I run a local agentic AI lab (Ollama, CrewAI, MCP) designed with privacy by design, so data never leaves my network, and a secure home automation setup with network segmentation (VLANs), Thread and Matter, with no third-party cloud dependency.