Kurtes Allen

Kurtes Allen

GRC Engineer

Ribuex

North Carolina, USA

About Me

I’m a GRC Engineer focused on building automated, cloud‑native, and AI‑driven compliance systems that scale. My background blends governance, security engineering, and automation, enabling organizations to move from manual, spreadsheet‑driven processes to reproducible, auditable, engineering‑grade workflows.

I design systems that reduce operational overhead, improve audit readiness, and strengthen security posture. Whether supporting internal teams or working with clients, my goal is the same: make compliance faster, smarter, and far more efficient through automation and intelligent tooling.

Experience Highlights

  • Engineered Python-based automation workflows that reduced manual evidence collection by 40%.
  • Designed NIST/ISO-aligned control validation logic automating 30+ controls.
  • Improved audit readiness and reduced review cycles by 25% through standardized artifacts.

Get in Touch

www.linkedin.com/in/kurtesallen

Specializations

Audit & AssuranceCloud SecurityCompliance AutomationPrivacyRisk ManagementAI GovernanceCloud GovernanceGRC Engineering

Languages & Tools

OSCALPythonTerraform

Frameworks

ISO 27001ISO 42001NIST 800-53NIST CSFNIST RMFPCI-DSSSOC 2

Certifications

ISO 27001 LAISO 42001 LAAWS CLOUD PRACTIONERAWS AI PRACTIONER

Projects

Automated AWS Access Review System

The Automated AWS Access Review System is a cloud security automation project designed to audit AWS IAM users, roles, and permissions. It continuously evaluates access usage, identifies security risks, and generates actionable alerts and reports. This project demonstrates real-world cloud security practices, including least privilege enforcement, automated compliance checks, and serverless architecture using AWS managed services.

Policy-as-Code Engine

Automate GRC compliance with policy-as-code, risk scoring. This project evaluates cloud and on-prem resources against defined policies and generates reports.

Sensitive Data Compliance Pipeline (AWS CDK)

A cloud-native compliance pipeline that monitors sensitive S3 buckets, enforces backup/restore, and generates daily compliance reports.