Andrew Largent
Security Engineer
About Me
I bring a background in GRC, cybersecurity, and technical operations, with a focus on making security and compliance practical, repeatable, and useful in real environments. My work has centered on translating complex control requirements into clear processes, strong documentation, and systems that teams can actually maintain. I’ve also spent time in the space between security, infrastructure, and engineering, which has given me a good appreciation for how compliance succeeds only when it supports the people doing the work.
At the moment, my work continues to focus on security automation, evidence collection, control validation, and helping technical teams build processes that reduce manual effort while improving confidence in audit readiness. I’m especially interested in the way automation can make GRC more scalable without losing rigor, whether that means using policy-as-code, improving documentation workflows, or creating clearer paths from findings to remediation. That combination of structure and practicality is what I enjoy most about the field.
What I’m most passionate about in GRC is bridging the gap between what a framework requires and what a team can realistically execute. I like solving messy problems, bringing order to ambiguity, and helping organizations build controls that are not only compliant, but genuinely effective. The best GRC work, in my view, is the kind that strengthens trust, supports operations, and makes it easier for teams to do the right thing consistently.
Experience Highlights
- GRC and cybersecurity professional focused on turning complex requirements into practical, repeatable processes.
- Experience supporting control validation, evidence collection, audit readiness, and technical documentation across security and infrastructure workflows.
- Strong collaborator across security, infrastructure, and engineering teams, with a focus on clear communication and dependable execution.
- Hands-on interest in security automation, policy-as-code, and reducing manual effort without sacrificing rigor.
- Motivated by work that strengthens trust, improves operations, and makes compliance more actionable for technical teams.
Get in Touch
Email me at alargent87@gmail.com or DM me on LinkedIn https://www.linkedin.com/in/alargent87
Specializations
Languages & Tools
Frameworks
Certifications
Projects
Full Terraform + OPA/Rego policy suite that evaluates infrastructure against PQC migration requirements and generates CI compliance evidence automatically. Covers NIST-finalized PQC algorithms and hybrid transition scenarios.
Automated scanning, evidence collection, and compliance workflow platform targeting NIST, FedRAMP, and CMMC requirements. Includes a live GitHub Pages deployment and structured CI pipeline for continuous compliance evidence generation.
A practitioner-focused collection of cybersecurity tools, concept implementations, and security engineering references. Serves as the parent ecosystem hub for the Forge platform series.