About
I’m Will Johnson — a cybersecurity GRC and automation engineer with 6+ years of experience in compliance, cloud security, and DevSecOps. I specialize in applying NIST RMF, FISMA, and CMMC frameworks to real-world cloud and software environments, building Python tooling and serverless pipelines that make evidence collection, control validation, and audit preparation practical at scale. I’ve led accreditation activities, partnered with engineering teams to embed security controls into CI/CD pipelines, and engineered GRC automation solutions that cut manual compliance overhead by 30%+.
What I work on
- Cybersecurity GRC & compliance automation
- NIST RMF / FISMA / CMMC evidence gathering & remediation
- DevSecOps — SAST, DAST, SCA, and container security in CI/CD
- Cloud security across AWS, Azure, and GCP
- Python automation & serverless architecture (AWS Lambda)
- Windows privacy & host hardening tooling
I’m also active in the DoD/federal tech community — including the DevSecOps Community of Practice and open-source contributions to the .mil GitHub ecosystem — focused on advancing cloud compliance automation and secure pipeline adoption across government environments. My lab notebook Ramblings is where I share experiments, GRC automation ideas, and notes that might be useful to others.