
GRC Professional | Risk, Compliance & Controls.
I'm a dual-qualified legal and technology professional specializing in data privacy and enterprise GRC. With a background spanning full-stack engineering and cyber law, I bridge the gap between regulatory requirements and technical implementation — building ISMS programs that actually work in practice, not just on paper.
What I Do
GRC
ISO/IEC 27001 ISMS design, gap analysis, risk assessment & treatment, Statement of Applicability, and SOC 2 readiness.
Data Privacy
GDPR and DPDP Act 2023 advisory, privacy-by-design reviews, and data subject rights implementation.
Security Frameworks
NIST CSF 2.0, ITGC, CMMI, control mapping, risk assessment, and compliance activities.