Technology GRC
GRC & ComplianceRisk, controls, evidence, ownership and remediation workflows.
Evidence · 10-system portfolio
Computer Science undergraduate focused on Technology GRC, third-party risk, security compliance and AI governance. I turn framework requirements into inspectable risk registers, control maps, questionnaires and evidence workflows—without presenting portfolio work as prior client tenure or certification.
10
proof-of-work systems
15
AI use cases mapped
25
buyer questions mapped
10
vendors assessed
01 / Flagship proof-of-work
This portfolio simulation connects customer assurance, third-party risk and AI governance through the same decision chain: requirement → evidence → risk → owner → next action.
Integrated modules
Module 01 · Customer assurance
A portfolio model showing how broad trust claims can be decomposed into owners, evidence, framework references and reviewable remediation decisions.
15
Evidence domains
SOC 2 + ISO
Primary lenses
Traceable
Evidence state
| Domain | Buyer question | Evidence | Priority |
|---|---|---|---|
| Access | How is privileged access controlled? | RBAC · MFA · access review | High |
| Encryption | Is customer data encrypted? | TLS · storage · KMS evidence | High |
| Incident | How are incidents escalated? | IR plan · exercise · notice flow | High |
| Assurance | What audit evidence exists? | SOC scope · ISO certificate | High |
02 / 10 inspectable systems
Each project turns a real governance problem into a concrete artifact: risk, control, evidence, owner and decision. The work is independent proof-of-work, not a claim of prior client delivery.
03 / Capability matrix
Every capability is paired with the artifact or implementation context where I applied it, so a reviewer can inspect the work instead of trusting a self-rated percentage.
Risk, controls, evidence, ownership and remediation workflows.
Evidence · 10-system portfolio
Trust Services Criteria mapped to operational controls and audit evidence.
Evidence · 15-domain control inventory
ISMS control architecture, risk treatment and evidence mapping.
Evidence · Control-to-evidence system
Canonical buyer answers with evidence links, owners and review dates.
Evidence · 25-question knowledge base
Population/sample thinking, expected result, exception and retest workflow.
Evidence · Audit operations system
Govern, Map, Measure and Manage applied to operational AI use cases.
Evidence · 15-system AI register
Provider/deployer transparency analysis for interactive and synthetic content.
Evidence · 15-use-case register
AI management-system governance integrated with risk/evidence workflows.
Evidence · AI Governance OS
Use-case, stakeholder, oversight, testing and residual-risk mapping.
Evidence · AI Governance OS
Prompt DLP, approved channels, redaction and unsanctioned-use controls.
Evidence · 12-control DLP standard
Criticality tiering, evidence review, findings and treatment decisions.
Evidence · 10-vendor TPRM register
Processor contracts, subprocessors, assistance, deletion and audit rights.
Evidence · 12-clause control set
Evidence requests spanning assurance, IAM, crypto, privacy and AI providers.
Evidence · 20-question vendor assessment
Likelihood, impact, residual risk, appetite, treatment, KRI and escalation.
Evidence · 15-risk executive register
Typed component systems and interactive frontend architecture.
Evidence · This portfolio
Static-first App Router site with SEO metadata and accessible interactions.
Evidence · This portfolio
Version control, repository documentation and CI workflow.
Evidence · Portfolio repository
Data transformation and artifact-generation workflows.
Evidence · GRC evidence workbooks
Computer Science foundations supporting technical risk analysis.
Evidence · BSc Computer Science
Data modeling and query fundamentals for control/evidence systems.
Evidence · BSc Computer Science
04 / About & trajectory
I am a Computer Science undergraduate targeting analyst-level Technology GRC, TPRM, Security Compliance and AI Governance work. The portfolio is intentionally explicit about what is simulated, what comes from public evidence, and what would require internal verification.
2026 · Now
Built ten inspectable proof-of-work systems spanning customer assurance, AI governance, TPRM, SOC 2/ISO evidence, executive risk, Article 50 transparency, shadow AI, Article 28 and audit operations.
Aug 2026
Mapped interactive and generative AI use cases to the European Commission's Article 50 transparency guidance while keeping legal applicability distinct from generic framework alignment.
2026
Produced source-backed public trust assessments that separate observed evidence, public evidence not identified and matters requiring internal verification instead of making unsupported compliance conclusions.
Current
Building the technical foundation behind technology risk work: software engineering, algorithms, databases, systems and disciplined problem solving.
05 / Framework references
These standards and regulations structure the portfolio work. They are references for analysis—not audit opinions, legal determinations, certifications or proof of prior program ownership.
Voluntary AI risk-management framework used to structure Govern, Map, Measure and Manage activities across the AI proof-of-work.
Portfolio application
ISMS requirements used as a reference for risk treatment, control ownership and evidence mapping. This portfolio does not claim ISO certification.
Portfolio application
Trust Services Criteria for security, availability, processing integrity, confidentiality and privacy used to structure control-and-evidence examples.
Portfolio application
Transparency duties for certain interactive and synthetic AI systems, used here for provider/deployer applicability and disclosure decision examples.
Portfolio application
Processor and subprocessor requirements used to structure DPA evidence, assistance, deletion/return and audit-right questions in the TPRM work.
Portfolio application
AI management-system requirements and guidance used as a reference for governance, accountability and continual-improvement concepts.
Portfolio application
06 / Hiring conversation
I am open to Technology GRC, Security Compliance, Third-Party Risk, Technology Risk and AI Governance opportunities. The fastest way to evaluate fit is simple: review the evidence, scan the resume, then email me with the role and problem you need solved.
Best-fit conversation
GRC · TPRM · security compliance · AI governance
Kuala Lumpur, Malaysia · open to remote opportunities
Independent proof-of-work available for direct review