Karizma Hanshaw

Karizma Hanshaw

GRC & Compliance Analyst

Remote

About Me

My background in cybersecurity spans Governance, Risk, and Compliance (GRC), third-party risk management, security operations, and information security auditing. Throughout my career, I’ve worked across both technical and compliance-focused environments, which has given me a strong understanding of how security controls translate from written requirements into real-world operations. My experience includes assessing organizations and third parties against frameworks and regulatory requirements such as ISO 27001, NIST, SOC 2, SOX, GDPR, HIPAA, and PCI, as well as reviewing security evidence, identifying control gaps, documenting findings, and working with stakeholders through remediation.

In my current work, I focus heavily on security compliance, risk assessment, audit readiness, and improving GRC processes. I’ve managed vendor security assessments, reviewed SOC reports and supporting evidence, tracked security findings and remediation through platforms such as ServiceNow, and worked cross-functionally to ensure risks are appropriately identified, documented, and addressed. I’ve also continued strengthening my audit expertise by earning my ISO/IEC 27001 Lead Auditor certification and expanding my knowledge of how organizations can build and maintain effective information security management systems.

What I’m most passionate about in GRC is finding ways to make compliance and risk management more efficient, scalable, and valuable to the business. I’m particularly interested in the intersection of GRC and AI to streamline evidence collection, control testing, risk analysis, continuous monitoring, and other traditionally manual compliance activities while maintaining appropriate human oversight. Long term, I want to help organizations move beyond viewing compliance as a checkbox exercise and instead build GRC programs that provide meaningful insight into risk, strengthen security, and support better business decisions.

Experience Highlights

  • Conducted third-party security and privacy risk assessments, evaluating vendors against SOC 2, ISO 27001, SOX, GDPR, HIPAA, PCI, and internal security requirements.
  • Reviewed SOC reports, security documentation, and control evidence to identify gaps, exceptions, and areas requiring remediation.
  • Managed security findings and remediation activities through ServiceNow, partnering with vendors and internal stakeholders to establish timelines and monitor higher-risk issues through resolution.
  • Supported cybersecurity audits and assessments using frameworks including ISO/IEC 27001, NIST CSF, and other industry security and compliance standards.
  • Earned the ISO/IEC 27001 Lead Auditor certification, building upon existing hands-on experience with information security controls, risk management, and audit practices.
  • Applied experience across both security operations and GRC to better understand technical risks and translate them into actionable compliance and risk-management decisions.
  • Experienced with GRC and security technologies including ServiceNow, OneTrust, Splunk, CrowdStrike, Black Kite, Qualys, Tenable, and other security platforms.
  • Exploring AI and automation opportunities within GRC to streamline evidence collection, control testing, risk assessments, continuous monitoring, and audit workflows.
  • Passionate about building scalable GRC programs that move beyond checkbox compliance and use risk insights to strengthen organizational security and business decision-making.

Get in Touch

I can be reached via: Linkedin DM Email: karizmahanshaw73@gmail.com Phone: 346-634-1576

Specializations

Audit & AssuranceCompliance AutomationIdentity & Access ManagementIncident ResponseRisk ManagementSecurity GovernanceThird-Party RiskAI GovernanceGRCVendor Risk Management

Languages & Tools

PowerShellPythonTerraform

Frameworks

CSA STARFedRAMPISO 27001ISO 27017ISO 27018ISO 42001NIST 800-53NIST 800-171NIST CSFPCI-DSSSOC 2

Certifications

CompTIA Security+ISO 27001 Lead AuditorISO 42001 Lead AuditorAI Security & Governance (Securiti)OneTrustCISSP (in progress)