I am a Senior GRC and Cybersecurity Risk Consultant with more than eight years of experience across Big Four consulting, global technology, and enterprise environments. I specialize in cybersecurity governance, enterprise risk management, third-party risk management, compliance, and audit readiness.
I conduct security, privacy, technology, and AI risk assessments, helping organizations identify control gaps, assess residual risk, and implement practical remediation strategies. My experience includes vendor due diligence, security questionnaires, evidence analysis, risk registers, control mapping, and control effectiveness assessments.
I am a certified ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor with hands-on experience conducting certification audits, including Stage 1, Stage 2, and surveillance activities. I also work with ISO/IEC 27701, SOC 2, NIST Cybersecurity Framework, CIS Controls, ITGC, and SOX compliance requirements.
I partner closely with engineering, IT, privacy, legal, procurement, and executive stakeholders to translate technical, regulatory, and contractual requirements into actionable security and compliance programs. I have supported organizations in financial services, technology, manufacturing, retail, and other regulated industries.
I am trilingual in Spanish, English, and Portuguese and experienced in managing multiple concurrent engagements in fully remote international environments. I am focused on strengthening security governance, improving control maturity, and enabling responsible AI and data protection practices.