Joshua Sitompul

Joshua Sitompul

Lead GRC Analyst

Patch My PC

Remote

About Me

I do GRC in a regulated B2B SaaS, cloud first environment. I try to automate and build where I can that makes the most sense. I click with others easily and live to serve.

Experience Highlights

  • Have been supporting and leading audit engagements since the beginning of my career.
  • Utilized native Vanta RAG to automate enterprise DDQ responses, decreasing turnarounds by 50%
  • Created M365 Copilot Agent to automate vendor due diligence

Get in Touch

Reach out to me on LinkedIn https://www.linkedin.com/in/joshua-s17/

Specializations

Audit & AssuranceCloud SecurityCompliance AutomationIdentity & Access ManagementRisk ManagementSecurity GovernanceSecurity OperationsThird-Party RiskVulnerability ManagementAI GovernanceCloud Governance

Languages & Tools

OPA/RegoPythonTerraform

Frameworks

GDPRISO 27001ISO 42001SOC 2

Projects

HITRUST Terraform Evidence Lab

Independent lab codifying HITRUST evidence collection patterns into infrastructure-as-code, translating framework requirements into declarative Terraform modules.

M365 Copilot Agent for Due Diligence Intake

Built a Copilot agent that automates due diligence research on requested vendors.

Third-Party Risk Management Orchestrator

Built a serverless Third-Party Risk Management Orchestrator using Slack, AWS Lambda, API Gateway, DynamoDB, Terraform, IAM, and Python.