Susan Shepard
Staff - Trust, Risk, and Compliance Analyst - Information Security
Rapid7
Boston, MA, USA
About Me
I'm a Staff Trust, Risk & Compliance Analyst at Rapid7, and I've spent the last decade-plus building security and compliance programs across enterprise SaaS, biotech, healthcare, and robotics — Veritas, iRobot, Nuance, Acquia, Seven Bridges, and now Rapid7. Before any of that I served in the U.S. Air Force, which is where the execution discipline underneath everything I do now actually comes from: how systems hold up under pressure, and why a control nobody's tested is a control nobody has. I hold an M.S. in Computer Information Systems from Boston University and a B.S. in Information Technology, magna cum laude, from UMass Lowell, along with CISM, CRISC, AAISM, AAIR, CC, and AWS Cloud Practitioner certifications.
At Rapid7 I own the Integrated IS Risk Management framework end-to-end — quantitative risk, third-party risk, and customer risk assessment run as one operating model with board-level visibility, instead of three teams reporting the same control three different ways. I built the org's first FAIR-based risk quantification model and embedded it in an LLM application, stood up the GRC platform from scratch with API-automated remediation, and lead the SEC Cyber Incident Disclosure program off an Incident Severity Calculator I designed to score OWASP severity and EO-14028 materiality separately. None of it stays theoretical for long — cutting findings triage time 40% and moving Customer Risk Assessment SLAs from weeks to days only happens if the framework survives contact with an actual audit.
What I actually care about is dragging GRC out of the heat-map era. Red is a color, not a unit of risk measurement — I build FAIR models, Monte Carlo simulations, and loss exceedance curves that give leadership a defensible loss-exposure range a CFO can budget against, and I use AI only where it sharpens that decision, not where it just produces more output for someone to review. I write my own tools rather than just spec them out — React/Vite front ends, Node/Express services, and evidence pipelines that pull continuous control evidence out of cloud infrastructure and IdPs instead of asking a human to screenshot it. A handful of those, including an AI risk register, an SEC materiality workbench, an incident severity calculator, and a FAIR taxonomy trainer, are public on my GitHub and portfolio for anyone who wants to see the reasoning, not just the output.
That belief is also why I founded this chapter: GRC is at its best when it's engineered, not administered, and the fastest way to spread that is to build it in public with people who think the same way. Outside of work I mentor through ISACA and Big Brothers Big Sisters, mentor prospective students through Boston University admissions, and write occasionally on Medium when a risk problem needs more room than a Slack thread.
Experience Highlights
- Architected and engineered InsightGRC end-to-end — full-stack continuous control monitoring platform on React/Vite, Node.js/Express, and PostgreSQL/Cloud SQL
- Built automated import engines and crosswalk parsers spanning 15+ frameworks including NIST SP 800-53 r5, ISO 27001/27017, PCI-DSS, FedRAMP, GovRAMP, TxRAMP, DORA, NIS2, CSA CCM/CAIQ, and OSCAL
- Designed PostgreSQL schemas with immutable audit logging, automated migrations, and dual-write operational state tracking
- Developed "AI Evidence Scout" and automated rubric assessors that validate evidence sufficiency and score control health
- Built a Node.js/Slack Bolt evidence automation pipeline pulling from GCP infrastructure, IdPs, EDRs, Google Drive, and Jira/Freshservice
- Shipped a Manifest V3 Chrome extension automating customer risk assessment questionnaire fulfillment across Archer, OneTrust, and Ombud portals
- Integrated FAIR quantitative risk modeling into an LLM application for automated, contextual risk scoring at scale
- Architected Rapid7's first Integrated IS Risk Management Framework, consolidating enterprise, third-party, and customer risk into a single governance model
- Led Rapid7's SEC Cyber Incident Disclosure program and built the Incident Severity Calculator (OWASP + EO-14028 materiality analysis)
- Directed SOC 2 and FedRAMP audit readiness to 100% evidence submission with zero findings; cut customer risk assessment SLAs from weeks to days
- CISM, CRISC, AAISM, AAIR (ISACA), CC (ISC2), AWS Cloud Practitioner
- M.S. Computer Information Systems, Security concentration — Boston University; B.S. Information Technology, magna cum laude — UMass Lowell
Get in Touch
DM me on LinkedIn.