A cybersecurity professional with three years across security engineering, cloud security, operations, and GRC.
I'm Roman — a cybersecurity professional with three years of experience spanning security engineering, cloud security, security operations, and governance, risk, and compliance. I've worked across internships at Fortune 500 companies, state government, and financial services — each building a different dimension of the security picture.
My focus now is GRC-as-Code: treating compliance as a software engineering problem. That means Python automation, infrastructure-as-code, OSCAL data models, and AI-assisted remediation — not spreadsheets and manual checklists.
Currently completing a BS in Cybersecurity and Information Assurance at WGU. I write about compliance engineering on this blog and share tooling on GitHub.