Gregory Wilson

Gregory Wilson

Central Valley CA

Available for: mentoringconsultingopen-sourcehiringfreelancecollaboration

About Me

With 20 years of experience across military, government, and commercial sectors, I bring a practical approach to aligning security operations, risk reduction, and business needs.

My work centers on PCI DSS v4.0.1, GRC Engineering, and Zero Touch Compliance, building automation, guardrails, and cloud-focused practices that make compliance part of how the environment runs.

A key part of my philosophy is "Shift-left GRC Enablement", moving compliance, control thinking, and audit readiness earlier into architecture, engineering, and operational workflows so teams can scale with less friction and stronger outcomes

Experience Highlights

  • Key Account Strategy: Served as the dedicated Security Liaison for a Level 1 Service Provider (PCI DSS), managing complex Third-Party Risk Management (TPRM) requirements and external audit defense.
  • Audit Remediation: Partnered with QSAs and enterprise clients to translate regulatory findings into actionable engineering tickets, accelerating remediation closure rates by 45%.
  • Security Alignment: Created reusable system-hardening baselines that aligned client environments with SOC 2 Type II and ISO 27001 standards, cutting compliance variance by 35% across the AMER region.
  • Cross-Functional Leadership: Mentored technical support teams on secure-by-design principles, embedding GRC checks earlier in the customer deployment lifecycle.

Get in Touch

You can reach me at me@gregorywilsonjr.com.

Specializations

Audit & AssuranceCloud SecurityCompliance AutomationIdentity & Access ManagementSecurity ArchitectureSecurity OperationsVulnerability ManagementDevSecOpsZero-Touch Compliance

Languages & Tools

BashOPA/RegoPowerShellPythonSQLTerraformJenkinsDockerNexusKubernetesAnsiblePrometheusVaultGitLeaksDefectDojoZAPTrivy

Frameworks

CSA STARISO 27001NIST 800-53PCI-DSS

Certifications

CISSPCISAISO/IEC 27001:2022 Lead Auditor

Projects

PCI DSS v4.0.1 Continuous Compliance Automation

End-to-end simulation of a PCI-compliant AWS environment using Terraform, AWS Config, Security Hub, and automated evidence collection. Demonstrates Zero-Touch compliance monitoring, continuous evidence capture, and control mapping for PCI DSS Requirements 1, 2, 7, 8, 10, 11, and 12.

Interested in working with Gregory Wilson?