About

I build GRC documentation for organizations that need audit-ready artifacts, and I write technical content that makes frameworks like NIST CSF 2.0 and ISO 27001 accessible to teams without dedicated compliance staff.

Work

At the Idowu Ajiri Foundation, the control environment had no documentation when I started. I built the risk register from scratch, beginning with asset identification, and presented findings to leadership in terms of likelihood and impact rather than compliance jargon. I then designed and hosted a security awareness training program targeting the human error patterns most likely to affect a small nonprofit.

When I identified a hosting infrastructure risk, I proposed migrating the Foundation's website off GoDaddy and WordPress to cloud infrastructure. The proposal was reviewed, approved, and implemented.

For VoipTower, an international SIP trunking provider operating across 25+ countries, I wrote technical content for operations teams evaluating Brazil market entry. The work required researching primary regulatory sources: the Lei Geral de Telecomunicações, ANATEL Resolution 553, and ITU numbering bulletins. The most operationally useful finding was one that practitioners miss on live configurations: Brazilian mobile numbers carry a mandatory ninth digit that legacy eight-digit databases do not account for, causing call failures. That accuracy only surfaces when the writer understands the subject well enough to know what teams get wrong in practice.

Background

GRC PortfolioFiverr ServicesLinkedIn