Jonathan Perez

Jonathan Perez

Senior Cybersecurity Specialist, GRC Engineer

Assurit

Virginia, USA

About Me

I am a GRC engineer focused on building systems that reduce real security risk while minimizing compliance overhead. My work sits at the intersection of vulnerability management, cloud security, and control governance, with an emphasis on automation, multi-framework assessment, and repeatable workflows.

Rather than treating compliance as a documentation exercise, I design solutions that treat controls as measurable, testable system behaviors. My approach is to pull evidence through automation, validate control requirements against the frameworks in play, and keep SSPs, findings, and remediation operable.

I spend most of my time engineering solutions that translate raw security data into control-aligned decisions, from TRACE vulnerability and POA&M operations to OSCAL continuous compliance pipelines that prove the package against live sources.

Experience Highlights

  • Built TRACE, a customized vulnerability and POA&M management solution with Qualys sync, BOD and KEV triage, Threat Watch feed correlation, evidence vault, and closure tracking.
  • Built an OSCAL continuous compliance pipeline that converts SSPs, reconciles claims against live evidence, and raises POA&Ms from real gaps.
  • Delivered audit-ready sensitive data training in Google Workspace with NIST 800-53 AT implementation and automated completion email.
  • Built CertSim, a memory-driven study engine with weak-domain targeting and timed exam-stress simulation.
  • Improved vulnerability management execution through remediation-driving governance and measurable closure validation.

Get in Touch

Feel free to reach out if you want to discuss GRC engineering, GRC leadership, vulnerability management automation, OSCAL, AI governance, or building compliance systems that prioritize real security outcomes.

  • LinkedIn: https://www.linkedin.com/in/cyberjp/
  • Website: https://securitybyjp.com/

Specializations

Vulnerability ManagementCloud SecurityCompliance AutomationAI Governance

Languages & Tools

PythonJavaScriptOSCAL

Frameworks

NIST RMFNIST CSFNIST 800-53NIST AI RMFFedRAMPSOC 2ISO 27001ISO 42001IRS Pub 1075COBITGAO Green BookCMS ARC-AMPECMMC

Certifications

CISSPCISMCGRCCMMC LCCACMMC CCPAWS Solutions Architect AssociateAWS Cloud InstituteCCSKCAISSCSA TAISEISO 42001 Lead ImplementerCCZTCISA HVA Technical LeadCISA HVA Assessment Lead

Projects

TRACE - Customized Vulnerability and POA&M Management Software Solution

Purpose-built vulnerability and POA&M operations platform with Qualys API sync, BOD and KEV triage, Threat Watch, control-mapped POA&Ms, evidence vault, executive reporting, and Jira ticketing. Turns scanner noise into owned findings with closure proof.

OSCAL Continuous Compliance Pipeline

Continuous compliance pipeline that converts SSPs to OSCAL, then discovers, assesses, reconciles claims against live tool evidence, and raises POA&Ms from real gaps. A living authorization package, not a one-time export. Hands-on companion workshop - https://github.com/GRCJP/oscal-pipeline-workshop.

Sensitive Data Training Platform

Audit-ready annual security awareness training in Google Workspace implementing NIST 800-53 AT controls with interactive modules, certificates, and automated completion and renewal email.

CertSim

Memory-driven study engine with adaptive recall, weak-domain targeting, timed exam-stress simulation, and study paths so practice compounds instead of scattering.

GRC Resume Builder

Resume optimization and job discovery for GRC professionals with ATS scoring, multi-board search, and privacy-first local application tracking.