Jonathan Perez
Senior Cybersecurity Specialist, GRC Engineer
Assurit
Virginia, USA
About Me
I am a GRC engineer focused on building systems that reduce real security risk while minimizing compliance overhead. My work sits at the intersection of vulnerability management, cloud security, and control governance, with an emphasis on automation, multi-framework assessment, and repeatable workflows.
Rather than treating compliance as a documentation exercise, I design solutions that treat controls as measurable, testable system behaviors. My approach is to pull evidence through automation, validate control requirements against the frameworks in play, and keep SSPs, findings, and remediation operable.
I spend most of my time engineering solutions that translate raw security data into control-aligned decisions, from TRACE vulnerability and POA&M operations to OSCAL continuous compliance pipelines that prove the package against live sources.
Experience Highlights
- Built TRACE, a customized vulnerability and POA&M management solution with Qualys sync, BOD and KEV triage, Threat Watch feed correlation, evidence vault, and closure tracking.
- Built an OSCAL continuous compliance pipeline that converts SSPs, reconciles claims against live evidence, and raises POA&Ms from real gaps.
- Delivered audit-ready sensitive data training in Google Workspace with NIST 800-53 AT implementation and automated completion email.
- Built CertSim, a memory-driven study engine with weak-domain targeting and timed exam-stress simulation.
- Improved vulnerability management execution through remediation-driving governance and measurable closure validation.
Get in Touch
Feel free to reach out if you want to discuss GRC engineering, GRC leadership, vulnerability management automation, OSCAL, AI governance, or building compliance systems that prioritize real security outcomes.
- LinkedIn: https://www.linkedin.com/in/cyberjp/
- Website: https://securitybyjp.com/
Specializations
Languages & Tools
Frameworks
Certifications
Projects
Purpose-built vulnerability and POA&M operations platform with Qualys API sync, BOD and KEV triage, Threat Watch, control-mapped POA&Ms, evidence vault, executive reporting, and Jira ticketing. Turns scanner noise into owned findings with closure proof.
Continuous compliance pipeline that converts SSPs to OSCAL, then discovers, assesses, reconciles claims against live tool evidence, and raises POA&Ms from real gaps. A living authorization package, not a one-time export. Hands-on companion workshop - https://github.com/GRCJP/oscal-pipeline-workshop.
Audit-ready annual security awareness training in Google Workspace implementing NIST 800-53 AT controls with interactive modules, certificates, and automated completion and renewal email.
Memory-driven study engine with adaptive recall, weak-domain targeting, timed exam-stress simulation, and study paths so practice compounds instead of scattering.
Resume optimization and job discovery for GRC professionals with ATS scoring, multi-board search, and privacy-first local application tracking.