Hi, my name is Will

Cybersecurity GRC & Compliance Automation.

I’m a cybersecurity GRC and automation engineer with 6+ years in compliance, cloud security, and DevSecOps. I build tooling that makes compliance practical and repeatable — Python automation, serverless pipelines, and security controls embedded in CI/CD workflows across NIST RMF, FISMA, and CMMC environments.

I keep a lab notebook called Ramblings where I share ideas, experiments, and security write-ups.

Projects I'm proud of

Cloud Security & GRC

CloudComply

A terminal-based cloud compliance tool built in Go. CloudComply provides an interactive TUI for inspecting cloud infrastructure configurations against security frameworks like NIST and CMMC — surfacing control gaps directly in the terminal with a clean, navigable interface. Built with the Charm stack (Bubble Tea, Bubbles, Lip Gloss) and integrating AWS SDK for Go v2 for live infrastructure queries.

Technologies used include:

  • Go
  • Bubble Tea — TUI framework
  • Bubbles — table, spinner components
  • Lip Gloss — terminal styling
  • AWS SDK for Go v2
  • Cobra — CLI structure

View on GitHub

Host Security & Privacy

Windows Privacy

A collection of PowerShell scripts and tooling for hardening Windows hosts and reducing telemetry exposure — applicable to both personal privacy and enterprise endpoint security baselines. Built with STIG and CIS benchmark alignment in mind for practical host hardening at scale.

Technologies used include:

  • PowerShell
  • Windows Security
  • STIG / CIS Benchmarks
  • Host Hardening

View on GitHub

Lab Notebook & Write-ups

Ramblings

A personal lab notebook where I share experiments, project notes, and security write-ups — covering GRC automation, DevSecOps patterns, cloud compliance, and tooling I'm actively building. Think of it as public notes for future-me (and hopefully useful for you). Hosted on GitHub Pages.

Technologies used include:

  • Jekyll
  • Markdown
  • GitHub Pages

View on GitHub

Contact me

I'm always interested in connecting about GRC automation, cloud security compliance, DevSecOps, and compliance engineering. Reach out!

Email me