Tiffany Walker-Roper
Information Governance Program Lead
Connecticut, USA
About Me
I am a privacy and security professional specializing in AI governance and GRC engineering, combining legal and technical expertise across highly regulated environments. I build based on my interests, including practical GRC automation and AI threat modeling tools built with AI-assisted development, as well as experimenting with applying governance frameworks (NIST AI RMF, EU AI Act, ISO 42001) to AI systems.
Throughout my career, I have worked across a range of spaces - from being a litigation paralegal to fintech compliance to GRC at a cloud provider and a stint in Big 4 doing privacy and 3rd party security consulting - I'm presently a contractor in the defense industry as the Information Governance Lead for an advanced military engine program. My breadth of industry exposure helped me learn how to design and implement scalable compliance frameworks where they are needed most, get in the weeds of broken processes, and build solutions that hold up when it matters.
From conducting CCPA and CPRA readiness assessments to completing SIG-Lite and HECVAT questionnaires to serving as the assessor on the other side of the table, I have operated across the full spectrum of privacy and vendor risk work. That range allows me to bridge compliance strategy and technical implementation to create real organizational value.
What I am most passionate about in GRC is the intersection with AI governance - how do we apply GRC principles to AI systems, to agents, and protect the data in effective and scalable ways? What does AI GRC look like in reality? How do we apply GRC engineering to AI systems that are handling the most sensitive data - like PHI? Where do we put the onus on vendors to demonstrate that their new AI functionality is not a prompt injection away from a massive breach? These are the questions that modern GRC programs are facing in the age of AI, and they require technical solutions - a spreadsheet is not going to demonstrate anything here. I joined the GRC Engineering Club to sharpen my technical skills and think about how we solve these challenges.
Beyond my day-to-day work, I am a contributing member of an IEEE Standards Association subcommittee focused on human-centricity in technology, where we are developing a privacy nutrition label framework and scoring methodology. I am proud to serve as the 2026 Young Privacy Professional for the CT IAPP Chapter. I am also currently pursuing a Master of Science in Cybersecurity and Information Assurance with an expected completion in Spring 2027.
Experience Highlights
-
- Legal and regulatory compliance background
-
- Cybersecurity grad student
-
- Conducted third-party security assessments for a major bank
-
- Startup GRC experience
-
- Built a working personal AI governance toolset — from threat modeling to runtime LLM monitoring — mapped to NIST AI RMF, ISO 42001, and EU AI Act
Get in Touch
Contact me via LinkedIn
Specializations
Frameworks
Certifications
Projects
Runtime AI usage governance: detects PII and credential leaks in LLM prompts, scores risk, maps violations to GDPR / SOC 2 / ISO 27001 / NIST AI RMF, and generates audit-ready reports.
A simple threat modeling skill that can be run in Claude Code.
My capstone from the CGE-P certification. A HIPAA compliance project for a Patient Intake API..