James Gladden

James Gladden

IT Audit Intern

Rackspace Technology

San Antonio, Texas

About Me

I got into GRC because I fell in love with the more hands-on direction the industry is heading into. I've discovered in recent years that my gift is more aligned with hands-on work. I figured I could get with the program and eventually become something greater, and fully express my creativity.

Experience Highlights

  • • Perform IT audit and technology risk assessments supporting enterprise cloud and managed services environments.
  • • Test access review controls across enterprise applications including OneStream and Novatus.
  • • Evaluate audit evidence supporting identity governance, user access reviews, and SOX-related IT controls.
  • • Work with SailPoint IdentityIQ, Splunk Enterprise, and Optro while supporting governance and compliance activities.
  • • Support control testing, audit documentation, and remediation tracking.
  • • Identify opportunities to improve evidence collection and governance workflows.
  • • Built Terraform-based AWS and Google Cloud environments implementing NIST SP 800-53 security controls.
  • • Implemented Infrastructure as Code, Compliance as Code, and Policy as Code using Terraform, GitHub Actions, OIDC, and OPA concepts.
  • • Designed audit-ready evidence collection workflows and governance automation.
  • • Completed the Certified GRC Engineering Practitioner (CGEP) program focused on cloud governance engineering.

Get in Touch

LinkedIn DM is the best way to contact me!

Specializations

Audit & AssuranceCloud SecurityCompliance AutomationIdentity & Access ManagementPrivacyDevSecOps

Languages & Tools

BashOPA/RegoOSCALPowerShellPythonSQLTerraform

Frameworks

CMMCGDPRNIST 800-53

Certifications

CGE-P

Projects

Patient Intake API

A minimal AWS workload: VPC, Lambda, API Gateway, DynamoDB, S3. It ingests patient intake submissions over HTTPS. Think of it as a system you have just inherited from an engineering team and been asked to make audit-defensible. This repository ships non-compliant on purpose. My job was to wrap it with the four CGE-P layers (Terraform GRC baseline, Rego policies, GitHub Actions evidence pipeline, OSCAL component) so the same workload becomes audit-defensible against HIPAA, SOC 2, and CMMC L2.