John Anderson

John Anderson

Security and Compliance Manager

Fleetio

Memphis, TN

About Me

My background in GRC has been shaped by working at the intersection of security, compliance, risk management, and technology. I’ve spent much of my career translating complex security and regulatory requirements into practical controls and processes that organizations can actually operate. I enjoy digging into the technical side of GRC—understanding how systems are architected, how controls are implemented, and whether the evidence behind a compliance claim truly supports it—rather than treating compliance as a checkbox exercise.

In my current work at Fleetio, I focus on strengthening and scaling the company’s governance, risk, and compliance program. My responsibilities span areas such as third-party risk management, security assessments, SOC 2 and other assurance activities, privacy and data protection considerations, and preparation for increasingly rigorous regulatory frameworks. A significant part of my work involves evaluating risk across vendors, systems, and business processes and then partnering with Security, IT, Legal, Engineering, and business stakeholders to find solutions that balance security requirements with the realities of operating and growing a SaaS company.

What I’m most passionate about in GRC is making it useful. I’m particularly interested in automation, AI, and better ways to connect technical security data with risk and compliance workflows. I believe strong GRC programs should do more than produce evidence for auditors—they should help organizations understand their actual risk, make better decisions, and build trust with customers. I enjoy finding ways to reduce manual compliance work, improve the quality of risk decisions, and turn GRC into an enabling function rather than a roadblock.

Experience Highlights

  • Building and scaling GRC programs within a growing SaaS organization
  • Leading third-party and vendor security risk assessments, including SOC 2 report analysis and control evaluations
  • Supporting SOC 2 and other security assurance and compliance initiatives
  • Advancing organizational readiness for FedRAMP Moderate and other rigorous security frameworks
  • Translating regulatory and security requirements into practical, operational controls
  • Partnering cross-functionally with Security, Engineering, IT, Legal, Finance, and business stakeholders to manage risk
  • Evaluating privacy, data protection, subprocessors, and third-party data handling risks
  • Developing risk-based approaches to security questionnaires, customer assurance, and compliance evidence
  • Assessing technical security controls across cloud infrastructure, vulnerability management, endpoint security, identity, and application security
  • Improving GRC processes through automation, AI, and more efficient evidence and risk-management workflows
  • Bridging the gap between technical security teams and business stakeholders by translating complex risks into actionable decisions
  • Advocating for GRC as a business-enabling function focused on measurable risk reduction rather than checkbox compliance

Get in Touch

DM me on LinkedIn, or email me at jandersonut@gmail.com.

Specializations

Audit & AssuranceIdentity & Access ManagementIncident ResponseRisk ManagementSecurity GovernanceThird-Party RiskVulnerability Management

Languages & Tools

Python

Frameworks

CMMCCSA STARGDPRISO 27001NIST 800-53PCI-DSSSOC 2StateRAMP

Certifications

CISMCRISC