Larry W.Wilkes

Larry W.Wilkes

GRC Engineer

Philadelphia, Pa

About Me

I'm a GRC Engineer with a background that sits at the intersection of hands-on technical work and real-world compliance enforcement. I spent 20 years as a Correctional Police Lieutenant, regularly handling data within CJIS-governed systems and learning firsthand what it means to operate inside a regulated environment where documentation, evidence integrity, and procedural rigor aren't optional — that experience shaped how I think about controls long before I had a name for it.

Over the past few years, I've built hands-on technical depth in observability and cloud security — I'm a certified Splunk Enterprise Admin and Splunk Core Power User, and both a Cribl Certified Services Consultant and Cribl Certified Engineer, with production experience deploying Cribl Stream/Edge pipelines across multiple enterprise clients. That work pulled me naturally toward compliance: building regex-based PII masking pipelines to meet HIPAA and PCI-DSS requirements, and applying Azure Regulatory Compliance controls (NIST 800-53, PCI-DSS, HIPAA/HITRUST) through Microsoft Defender for Cloud and Sentinel. Earning my Certified GRC Engineer, Auditor Specialty (CGE-AUD) credential formalized what I'd already been doing in practice.

What I care about most is the gap between paper compliance and technical reality — a control isn't real until it's implemented and verifiable in code, not just written in a policy document. That's what drove me to build a Terraform-based AWS S3 project mapping directly to specific NIST 800-53 controls (SC-28, AU-3, AU-6, CM-6, AC-3) with machine-readable evidence. I'm a US Army Veteran, and I bring that same discipline into this field: take the requirement seriously, document everything, and don't claim more than you can prove.

Get in Touch

DM me on LinkedIn or email LarryWWilkes@gmail.com

Specializations

Audit & AssuranceCloud SecurityCompliance AutomationIdentity & Access ManagementIncident ResponsePrivacyRisk ManagementSecurity GovernanceVulnerability Management

Languages & Tools

BashJavaScriptPowerShellSQLSPLKQL

Frameworks

CJISHITRUSTISO 27001NIST 800-53PCI-DSS

Certifications

Splunk Certified AdminCribl Engineer

Projects

Compliant S3 Bucket (Terraform, AWS)

A Terraform module that provisions a Google Cloud Storage bucket with a hardcoded security and compliance floor. Consumers can change business configuration (environment, retention period, naming), but cannot disable, weaken, or opt out of any control enforced inside the module.

IAR-Procedure — Information Asset Register Procedure

Created an Information Asset Management Policy and prepared a PowerPoint presentation explaining the IAR document and how it should be completed.

Data Loss Prevention — DLP Blocking Rule for Removable Storage Devices

Accessed ManageEngine DLP via Chrome (https://localhost:8020) and created a data classification rule named "blocking files," configured to detect PDF file extensions. Deployed the rule with a Removable Storage Devices action to block sensitive file transfers, then validated it by attempting to copy a PDF file to a USB storage device on a Windows 10 machine.

Nessus Tenable Scans and Group Policy

Nessus Tenable Scans and Group Policy — Built and executed Basic, Advanced, and Advanced Dynamic scan policies in Nessus (including a Basic Scan run against Windows10-PC1), paired with Group Policy configuration.

Information Security Awareness Campaign — Phishing Attacks

Planned and produced a detailed information security awareness campaign focused on phishing attacks, framed around the principle that security awareness is one of the core controls in any IS standard — citing that roughly 85% of organizational data breaches stem from a lack of employee awareness. Delivered the campaign as a video presentation.