Who
I am

A cybersecurity professional with three years across security engineering, cloud security, operations, and GRC.

I'm Roman — a cybersecurity professional with three years of experience spanning security engineering, cloud security, security operations, and governance, risk, and compliance. I've worked across internships at Fortune 500 companies, state government, and financial services — each building a different dimension of the security picture.

My focus now is GRC-as-Code: treating compliance as a software engineering problem. That means Python automation, infrastructure-as-code, OSCAL data models, and AI-assisted remediation — not spreadsheets and manual checklists.

Currently completing a BS in Cybersecurity and Information Assurance at WGU. I write about compliance engineering on this blog and share tooling on GitHub.

CySA+CompTIA
SSCP(ISC)²
CC(ISC)²
Security+CompTIA
Network+CompTIA
A+CompTIA
Linux EssentialsLPI
AWS CCPAmazon
CCSPIn progress
Pentest+In progress
BS Cybersecurity & Information AssuranceWestern Governors University · In progress
AAS IT – CybersecurityCompleted
FEB 2026 — PRESENT · REMOTE
Security Analyst Intern
Mutual of Omaha · Governance, Risk, and Compliance Team. Applying GRC-as-Code principles in an enterprise financial services environment.
SEP 2025 — JAN 2026 · LINCOLN, NE
Security Engineer I
State of Nebraska · Contract · Security Operations Team. On-site security engineering for state government infrastructure.
JUN 2025 — AUG 2025 · DALLAS, TX
Cybersecurity Intern
Hilton · Cloud Security Engineering Team. Hybrid role focused on cloud security posture across a global hospitality enterprise.
SEP 2023 — APR 2025 · LINCOLN, NE
Information Security Intern
Ameritas · Security Engineering Team. 1 year 8 months across security engineering in a financial services environment. Foundation for the GRC and automation focus that followed.
MAY 2023 — JUL 2023 · LINCOLN, NE
Technology Intern
Nebraska Department of Transportation · Unified Communications Technology Team. On-site technology infrastructure role. Entry point into professional IT and cybersecurity.