Alexandria Seven
Senior InfoSec GRC & Compliance Automation Engineer
- San Francisco Bay Area, CA
- alexsevenresume@gmail.com
- linkedin.com/in/alexlnprofile
- 650-797-1104
Executive Summary
InfoSec GRC leader and hands-on compliance automation engineer with 15+ years transforming manual audit, risk, and vendor-management processes into scalable workflows and continuous control monitoring. Builds governance directly into AWS, CI/CD pipelines, and GRC platforms; has delivered zero-deficiency audits, unified 1,000+ controls across major frameworks, and accelerated third-party risk reviews for financial services, healthcare, SaaS, and global enterprises. Founder of GRC PROS, a practitioner resource reaching 500K+ security professionals.
Technical & Governance Toolkit
Compliance & Evidence Automation
ServiceNow IRM/GRC (Custom Workflows & APIs), OneTrust, Secureframe, SecurityScorecard, Sprinto, UCF Control Cross-Mapping, Continuous Control Monitoring (CCM)
Security & Regulatory Baselines
SOC 2 (Type I/II), ISO 27001, NIST 800-53, FISMA, HITRUST, HIPAA, PCI DSS (RoC), FFIEC/OCC, CUI, AI Governance (AIBOM/SBOM)
Cloud & Infrastructure Security
AWS Security Governance, Hybrid/On-Prem Architecture Reviews, DevSecOps & CI/CD Pipeline Controls, Threat Modeling, SSP Evaluation
Process & Systems Analysis
Technical Requirements Gathering, As-Is/To-Be Workflow Redesign, Vendor Risk Scoring, Post-M&A Security Integration
Case Studies
Select a card to see the challenge, approach, and measurable outcomes.
Automated Third-Party Risk Program
Multinational conglomerate · OneTrust + SecurityScorecard
Replaced manual vendor intake forms with an automated TPRM workflow and continuous external risk scoring.
Third parties monitored: 1,000s · Intake automation: Fully automated · Risk scoring: Continuous
Zero-Deficiency SOC 2 Type I & II
Regulated SaaS platform · Secureframe
Built a continuous-compliance monitoring pipeline mapping live cloud configuration to SOC 2 controls.
Major findings: 0 · Certifications: Type I + II · Schedule: On time
Unified Control Set Consolidation
Equinix / RingCentral / FRBSF · ServiceNow IRM
Collapsed 1,000+ scattered controls into one harmonized set to eliminate duplicate audit evidence requests.
Controls harmonized: 1,000+ · Frameworks unified: 5 · Evidence requests: De-duplicated
Compliance Gates in CI/CD
Move Inc. / Realtor.com · AWS DevSecOps
Embedded automated risk assessment and compliance checks directly into AWS deployment pipelines.
Release cadence: Unchanged · Control checks: Automated · Scope: Post-M&A
Selected Impact & Professional Experience
A3INFOSEC
2022 – Present- Automated Vendor Risk Management: Replaced manual intake forms for a multinational conglomerate by engineering an automated TPRM workflow in OneTrust integrated with SecurityScorecard API data—slashing vendor risk assessment turnaround times and maintaining continuous risk scoring across thousands of third parties.
- Zero-Deficiency SaaS Audit Acceleration: Built an automated continuous-compliance monitoring pipeline in Secureframe for a regulated SaaS platform, mapping live cloud configurations directly to SOC 2 Type I and Type II controls to achieve audit certification on schedule with zero major findings.
- Operationalized AI & Supply Chain Governance: Developed an AI Governance Maturity Framework and partnered with engineering teams to integrate AI Bill of Materials (AIBOM) and SBOM tracking into software release workflows, establishing defensible risk controls for client AI implementations.
- Built an Industry Media Asset: Founded GRC PROS from scratch, authoring 600+ deep-dive compliance automation guides, process frameworks, and risk scripts—growing an organic audience of 500K+ readers and 10K+ enterprise security subscribers.
Enterprise Client Engagements (Equinix, RingCentral, Federal Reserve Bank of San Francisco)
2019 – 2022- Eliminated Multi-Framework Audit Redundancy: Standardized 1,000+ scattered compliance controls down to a unified control set using the Unified Compliance Framework (UCF) in ServiceNow IRM, cutting redundant audit evidence requests across SOC 2, ISO 27001, HITRUST, C5, and SOX.
- Automated Evidence Gathering: Architected custom ServiceNow IRM workflows to automate policy approvals, continuous evidence collection, and issue tracking across multi-cloud and hybrid environments.
- Federal & Cloud Architecture Validations: Evaluated System Security Plans (SSPs), network flow diagrams, and vendor documentation against NIST 800-53, FISMA, and CUI baselines, validating technical controls before production sign-off.
Blue Shield of California
2017 – 2019- Modernized Legacy Policy Infrastructure: Overhauled static policy documentation across a massive healthcare ecosystem, building an automated policy governance lifecycle in ServiceNow to handle approvals, ownership tracking, annual attestations, and exception requests.
- Streamlined Auditor Validation Cycles: Acted as the single technical point of contact for external auditors across HIPAA, SOC 2, and Model Audit Rule engagements, organizing pre-validated evidence packages to shorten audit cycles and minimize operational disruption to IT teams.
Move Inc. / Realtor.com
2016 – 2017- Embedded Controls into CI/CD Pipelines: Partnered directly with DevOps and Cloud Engineering leads to integrate automated security risk assessments and compliance checks into AWS deployment pipelines, preventing non-compliant code from reaching production without stopping daily releases.
- M&A Infrastructure Risk Mapping: Executed post-acquisition security reviews across newly acquired business units, mapping critical data flows and unifying security policies under a single corporate baseline.
Enterprise Client Engagements (Visa, PayPal/Xoom, Fremont Bank)
2013 – 2016- Agile SDLC Security Assessments: Conducted risk assessments across rapid Agile release cycles, evaluating infrastructure changes, third-party software dependencies, and cloud migrations against PCI DSS, ISO 27001, and FFIEC standards.
- Remediated Post-Acquisition Compliance Gaps: Analyzed legacy systems for PayPal/Xoom following acquisition, identifying critical policy and technical control gaps against enterprise security standards and managing the engineering remediation roadmap to completion.
- Authored Formal PCI Reports on Compliance (RoC): Executed PCI DSS SAQ-D audits, tested technical control evidence, and authored formal RoC documentation for high-volume payment processing environments.
E*TRADE Financial
2008 – 2013- Engineered Internal Access Review Tools: Built custom web-based automation scripts to streamline recurring user access reviews across 100+ core banking applications, turning weeks of manual spreadsheet work into an automated review process.
- Scaled High-Volume Vendor Reviews: Executed 100+ third-party vendor reviews annually under OCC, FFIEC, and NIST baselines, establishing clear risk-scoring criteria for third-party software and service providers.
Technical Projects & Automation
Agentic AI Compliance Automation Tool
03/2026Designed and built a functional automation tool leveraging an agentic AI architecture and external APIs to ingest raw security data, cross-map controls, and automate multi-step GRC evidence compilation.
Certifications & Credentials
CISSP — Certified Information Systems Security Professional
ISC2 (Active, 2011–Present)
- Previous Professional Credentials: GRCP & GRCA (OCEG), PCI Qualified Security Assessor (QSA, PCI SSC)
Education
Bachelor of Science, Accounting Information Systems
California State University, Sacramento