Michael Koranteng
Michael Koranteng

AI GRC Lead and AI Assurance Consultant

Open to offers · Member since 28 Sep 2026
Location
United States
Desired salary
Unspecified
Work preference
Remote Only / Full Time, Contract
Experience level
Senior

About

Professional summary

I am a results-driven AI governance, risk, and compliance professional with extensive experience leading AI assurance, cybersecurity governance, and security control assessment initiatives. I specialize in building enterprise governance models that align emerging artificial intelligence deployments with regulatory, operational, and security requirements.

I bring advanced expertise in the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, generative AI governance, and algorithmic risk management. My work includes evaluating machine learning pipelines for bias, fairness, transparency, data governance, model validation, and security control effectiveness.

I have led and supported compliance programs across federal and commercial environments, including FedRAMP, CMMC 2.0, FISMA, HIPAA, PCI-DSS, NIST SP 800-53, NIST SP 800-37, and NIST SP 800-171. I translate complex regulatory and technical requirements into practical controls, policies, remediation plans, and executive-ready risk reporting.

My background includes security authorization and assessment, continuous monitoring, third-party risk management, vulnerability analysis, supply-chain cybersecurity, and audit readiness. I partner effectively with technical, procurement, logistics, leadership, and external stakeholder teams to identify risks and deliver measurable mitigation strategies.

I hold advanced AI and cybersecurity credentials including AAISM, AAIA, AAIR, CISM, CISA, Certified CMMC Professional, Certified CMMC Assessor, and CompTIA Security+. I am focused on helping organizations deploy trustworthy, secure, compliant, and well-governed AI systems.

Skills

16 capabilities

Experience

Career history

Compliance Manager / Quality Assurance Lead Exostar LLC

I spearhead development of enterprise AI governance policies, procedures, and risk frameworks aligned with NIST AI RMF and ISO/IEC 42001.

I lead automated GRC system maintenance, risk evaluations, algorithmic control assessments, and continuous compliance monitoring. I collaborate with technical teams on mitigation plans and ensure alignment with FedRAMP, CMMC 2.0, and evolving AI regulatory requirements.

CMMC Quality Assurance / Lead Auditor First Information Technology, VA

I perform quality assurance for eMASS CMMC Templates Version 3.9, including oversight of system uploads and workflow stages.

I conduct security assessments and mock evaluations, validate system scopes, boundaries, and data flows, and communicate assessment findings and certification documentation to stakeholders.

Supply Chain Cybersecurity Risk Management Analyst / Third-Party Risk Vigor Marine Group

I deliver supplier readiness and compliance consulting for prime contractors and subcontractors, with emphasis on CMMC 2.0 and DFARS clause adherence.

I assess cyber and supply-chain risks, analyze security data for vulnerabilities and compliance drift, and work with procurement, logistics, and IT teams to embed security measures into operations.

Security Analyst, Governance, Risk, and Compliance MacKenzie Engineering Inc

I developed governance policies, system procedures, and security control frameworks aligned with NIST guidance.

I analyzed vulnerability reports, drove risk mitigation and patching activities, supported third-party security control assessments, and provided GRC reporting and strategic recommendations to senior management.

Information System Security Officer / GRC Analyst / 800-53A Assessor ZenSecured Consulting LLC

I managed authorization and assessment packages, including System Security Plans, Contingency Plans, Security Assessment Reports, and Plans of Action and Milestones.

I served as a Security Control Assessor, performed control testing, vulnerability scan analysis, and CrowdStrike threat-hunting evaluations, and conducted continuous monitoring under NIST SP 800-137.

Security Control Assessor / Auditor Skytech Consulting LLC

I performed system security categorizations using FIPS 199 and NIST SP 800-60 guidelines.

I assessed security and privacy controls, evaluated vulnerability states, and developed and tracked POA&Ms to support timely remediation closure.

Third Party Vendor Risk Manager Skytech Consulting LLC

I executed third-party vendor risk assessments and reported vendor risk management metrics.

I partnered with cross-functional teams to address compliance gaps and data privacy needs, reviewed vulnerability findings, and recommended effective risk countermeasures.

Education

Learning history

University of Management, Economics and Finance

Bachelor of Business Administration

This professional hasn’t added portfolio projects yet.

This professional hasn’t listed any services yet.

Jobs Talent AI Tools Salaries
Menu