Jeffrey Collins
Founder/CEO
Eagle Defense Systems, LLC
The Woodlands
About Me
I got into GRC to transfer the skills I built across three distinct disciplines into a single, unified career path. As a former Army Staff Sergeant and Ranger-qualified Reconnaissance Squad Leader, I developed deep instincts for risk identification, mission planning, and decisive execution under pressure. I later applied that same structured thinking in executive security and corporate accounting, where I built familiarity with internal controls, financial integrity, and organizational risk. GRC became the natural convergence point where military leadership, physical security operations, and financial compliance all speak the same language.
I am the founder of Eagle Defense Systems (EDS), a GovCon-focused AI compliance and cybersecurity firm building tools that help small and mid-size contractors achieve and maintain CMMC, NIST, and FedRAMP alignment. My work sits at the crossroads of technical implementation and legal compliance strategy, and I hold a BSc in IT (Cybersecurity), Magna Cum Laude, with active pursuit of CGRC, CISM, ISO 27001 Lead Auditor, and CISSP certifications.
My current focus is developing AI-powered compliance tooling that competes in the GovCon market with an emphasis on Third Party Auditor (3PAO/C3PAO) readiness, cloud security architecture, and procedural data integrity. What separates my approach from most GRC practitioners is that I am currently matriculating at Texas A&M University School of Law, concentrating in Cybersecurity Law and Policy and Risk Management and Compliance. That legal foundation is how I connect to GRC Engineering at a structural level: I do not just implement controls, I understand the regulatory intent, liability exposure, and policy architecture behind them. I am also a Professional Member of the CMMC Network and an Associate Member of ISC2
Specializations
Languages & Tools
Frameworks
Certifications
Projects
A hands-on GRC automation demonstration built on Google Cloud Platform that simulates audit evidence collection and compliance workflow automation. Designed to showcase how GovCon and enterprise security teams can operationalize evidence gathering aligned with NIST 800-53, RMF, and FedRAMP requirements. The project serves as a practical reference for GRC engineers transitioning compliance processes into cloud-native, auditable pipelines. Tags / Skills: GCP, GRC Automation, Audit Evidence, NIST 800-53, RMF, FedRAMP, Cloud Compliance, Python, IaC
A hands-on GRC automation demonstration that transforms CMMC Level 2 Access Control findings into audit-ready Excel evidence packs. Automates evidence collection across six critical AC controls mapped to NIST 800-171, eliminating manual copy-paste workflows and reducing evidence packaging time for assessment teams. Designed to showcase how GovCon and defense industrial base organizations can operationalize compliance reporting through Python-driven automation aligned with CMMC L2, NIST 800-171, and FedRAMP reporting standards. Featured on the Aspire Cyber Podcast. Tags / Skills: CMMC L2, NIST 800-171, Access Control, Evidence Automation, Python, FedRAMP, GRC Automation, Audit Readiness, Excel Reporting Sonnet 4.6 Extended
Interested in working with Jeffrey Collins?