IT Auditor - GRC Engineering
Mark Janowski
IT auditor building compliance as code - turning control frameworks into Terraform, policy-as-code, and automated evidence.
Featured work
All projectsJul 2026
Executable NIST 800-53 Controls
Three NIST 800-53 controls rewritten as Open Policy Agent rules with a full unit-test suite, so a non-compliant Terraform plan is rejected automatically instead of being caught in next quarter's sample.
Jun 2026
Compliant-by-Default AWS Storage
Terraform that provisions S3 storage with encryption, versioning, access blocking, and audit logging enforced at creation time - so the control is satisfied before an auditor ever asks.