Bentley Grant

Bentley Grant

Sr GRC Engineer

Seattle

About Me

My career in information security started inside one of the most demanding compliance environments that exists: the United States Army. Over 20 years, I managed enterprise cybersecurity operations across global regions, built and led technical teams in high-stakes conditions, and learned what it actually means to be accountable for security outcomes when failure has real consequences. That foundation shaped how I think about governance, risk, and compliance today. GRC is not a documentation exercise. It is a management discipline, and it only works when the people running it understand the operational environment they are protecting.

After transitioning from the Army, I moved into consulting and then into a senior leadership role at Norstella, a cloud-native health IT SaaS organization where I built the enterprise Information Security Management System from the ground up. That work covered the full compliance stack simultaneously: HITRUST CSF validated assessment, SOC 2 Type II audit management, HIPAA Security Rule compliance across a 300-plus vendor population, and NIST CSF 2.0 risk governance across 12 business units.

The part of GRC that I find most interesting is the translation problem. Security leaders spend enormous energy building technically sound programs that executives do not understand and engineering teams do not follow. I have spent most of my career working on that gap. The risk register has to connect to a business decision. The control framework has to reflect how the product actually works. The audit evidence has to tell a coherent story, not just fill a checklist. When those connections exist, security becomes something the organization genuinely owns rather than something it tolerates during audit season.

Right now my focus is on healthcare and health IT organizations navigating the intersection of cloud-native architecture, interoperability requirements, and increasingly demanding regulatory environments. HITRUST certification, HIPAA compliance at scale, and SOC 2 in product driven SaaS companies are the areas where I do my best work. I am also paying close attention to how AI risk governance is evolving inside regulated industries, where the stakes for getting it wrong are highest and the frameworks are still catching up to the technology.

Experience Highlights

  • Built an enterprise Information Security Management System from scratch across 12 business units at a cloud-native health IT SaaS organization, achieving HITRUST CSF validated certification and clean SOC 2 Type II audit outcomes simultaneously.
  • Managed HIPAA Security Rule compliance across a 300-plus vendor population, including annual risk analysis execution, PHI data flow documentation, and business associate agreement lifecycle oversight.
  • Reduced audit evidence preparation time 35% by implementing and configuring the OneTrust GRC platform for risk register management, policy lifecycle automation, and control assessment distribution.
  • Cut phishing simulation click-through rates 42% year over year by rebuilding a KnowBe4 security awareness program with role-specific content tracks and monthly simulation cycles.
  • Delivered HITRUST gap assessments, SOC 2 readiness engagements, and HIPAA compliance projects across multiple healthcare and health IT clients as a security consultant at Avanade.
  • Supported FedRAMP and FISMA authorization activities including System Security Plan development, control implementation statements, and POA&M lifecycle management.
  • Led a $13M-plus enterprise IT and cybersecurity portfolio across global regions during a 20-year U.S. Army career, managing 25-plus senior contributors in mission-critical operating environments.
  • Maintained 99.9% platform uptime for critical infrastructure while enforcing NIST and FISMA compliance across international operations.

Get in Touch

The best way to reach me is directly. If you have a specific engagement or opportunity in mind, email works best. For general networking or an initial conversation, LinkedIn is fine.

Email: [bentleygrant1@gmail.com] LinkedIn: [ linkedin.com/in/bentleygrant9952 ]

Specializations

Identity & Access ManagementRisk ManagementSecurity GovernanceThird-Party RiskVulnerability Management

Frameworks

HIPAAISO 27001ISO 27017NIST 800-53NIST 800-171SOC 2