Led SOC 2 and ISO 27001 programs from discovery through audit
Led the implementation of SOC 2 Type II for a company in the energy space and ISO 27001 for an insurance-industry company. In both cases, I owned the program end to end: discovery, policy writing, control implementation, evidence collection, stakeholder coordination, and the full audit process.
Both audits resulted in good reports with no major findings. More importantly, the programs were built to be useful after certification: controls mapped to real systems, policies reflected how the business actually operated, and evidence collection became part of normal work instead of a last-minute audit scramble.
- Mapped requirements to cloud, identity, SDLC, vendor, incident-response, and governance controls.
- Wrote policies that were practical enough for engineering and business teams to follow.
- Kept the security program focused on reducing real risk, not just collecting a certificate.