Larry W.Wilkes
GRC Engineer
Philadelphia, Pa
About Me
I'm a GRC Engineer with a background that sits at the intersection of hands-on technical work and real-world compliance enforcement. I spent 20 years as a Correctional Police Lieutenant, regularly handling data within CJIS-governed systems and learning firsthand what it means to operate inside a regulated environment where documentation, evidence integrity, and procedural rigor aren't optional — that experience shaped how I think about controls long before I had a name for it.
Over the past few years, I've built hands-on technical depth in observability and cloud security — I'm a certified Splunk Enterprise Admin and Splunk Core Power User, and both a Cribl Certified Services Consultant and Cribl Certified Engineer, with production experience deploying Cribl Stream/Edge pipelines across multiple enterprise clients. That work pulled me naturally toward compliance: building regex-based PII masking pipelines to meet HIPAA and PCI-DSS requirements, and applying Azure Regulatory Compliance controls (NIST 800-53, PCI-DSS, HIPAA/HITRUST) through Microsoft Defender for Cloud and Sentinel. Earning my Certified GRC Engineer, Auditor Specialty (CGE-AUD) credential formalized what I'd already been doing in practice.
What I care about most is the gap between paper compliance and technical reality — a control isn't real until it's implemented and verifiable in code, not just written in a policy document. That's what drove me to build a Terraform-based AWS S3 project mapping directly to specific NIST 800-53 controls (SC-28, AU-3, AU-6, CM-6, AC-3) with machine-readable evidence. I'm a US Army Veteran, and I bring that same discipline into this field: take the requirement seriously, document everything, and don't claim more than you can prove.
Get in Touch
DM me on LinkedIn or email LarryWWilkes@gmail.com
Specializations
Languages & Tools
Frameworks
Certifications
Projects
A Terraform module that provisions a Google Cloud Storage bucket with a hardcoded security and compliance floor. Consumers can change business configuration (environment, retention period, naming), but cannot disable, weaken, or opt out of any control enforced inside the module.
Created an Information Asset Management Policy and prepared a PowerPoint presentation explaining the IAR document and how it should be completed.
Accessed ManageEngine DLP via Chrome (https://localhost:8020) and created a data classification rule named "blocking files," configured to detect PDF file extensions. Deployed the rule with a Removable Storage Devices action to block sensitive file transfers, then validated it by attempting to copy a PDF file to a USB storage device on a Windows 10 machine.
Nessus Tenable Scans and Group Policy — Built and executed Basic, Advanced, and Advanced Dynamic scan policies in Nessus (including a Basic Scan run against Windows10-PC1), paired with Group Policy configuration.
Planned and produced a detailed information security awareness campaign focused on phishing attacks, framed around the principle that security awareness is one of the core controls in any IS standard — citing that roughly 85% of organizational data breaches stem from a lack of employee awareness. Delivered the campaign as a video presentation.