Skip to content

Navigation Menu

Sign in
Sign up
@tiffanidickerson437-lang
tiffanidickerson437-lang
Follow

Tiffani Dickerson tiffanidickerson437-lang

Highlights

  • Pro

Block or report tiffanidickerson437-lang

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Tiffani Dickerson

GRC program builder — SOC 2 · ISO 27001 / 27701 · HIPAA · AI governance · compliance as code.

I stand up security-compliance functions from zero and run them as infrastructure, not paperwork — controls defined once and rendered per framework, evidence pulled from systems of record, policy checks enforced in CI behind human-approval gates. I've owned SOC 2 Type II, ISO 27001, and HIPAA audit lifecycles end to end, and the customer-facing side too: security questionnaires, trust collateral, and third-party risk that keep enterprise deals moving.

📍 North Carolina · remote / Eastern Time


📌 compliance-program — GRC, as code

Scaffold FAIR Simulation Test Policy Tests

A framework-agnostic GRC engine that lives in Git: a 45-control Living Control Set (SCF 2026.1-mapped, OSCAL-native — catalog, 12 framework profiles, and a System Security Plan all validated in CI) rendered into every regime in scope: SOC 2, ISO 27001, NIST 800-53, GDPR, COPPA, ISO 42001, NIST AI RMF, EU AI Act. Risk is quantified, not color-coded: a FAIR Monte Carlo engine turns the risk register into loss-exceedance curves and ALE percentiles on every pull request. Framework coverage is computed by a set-theory mapping linter, never asserted. Rego policy-as-code with paired tests, drift monitoring that opens real GitHub Issues, and evidence validation run as GitHub Actions — the drift → Issue → PR loop runs in CI, behind human-approval gates. Evidence is computed from systems of record; the schema and a pre-tool-use hook both reject AI-authored evidence.

Agents draft. A human decides. The engine itself was built that way — AI drafted every unit, a human approved every merge: how I built this with AI.

Popular repositories Loading

  1. compliance-program compliance-program Public

    Agentic, controls-as-code GRC engine: one SCF-mapped control set → every framework. OSCAL-validated, FAIR-quantified, policy-as-code, human-gated AI. CI proves it.

    Python

  2. tiffanidickerson437-lang tiffanidickerson437-lang Public

    Profile

  3. mattermost-grc-manager-program mattermost-grc-manager-program Public

    Mattermost, onboarded: a GRC program rendered from one config by the compliance-program engine. Findings from the public record, four runnable instruments, and 30/60/90 plans.

    Python

  4. plaid-grc-engineering-program plaid-grc-engineering-program Public

    Plaid, onboarded: a GRC Engineering program rendered from one config. Ships the two framework mappings the engine could not render, and the two silent-failure defects that building it surfaced.

    Python

  5. jasper-grc-lead-program jasper-grc-lead-program Public

    A Senior GRC Lead program for Jasper, as code - one config in, findings and instruments out. Built from public sources.

    Python

  6. midpage-grc-program midpage-grc-program Public

    Midpage's compliance function, as code — seven findings from Midpage's own public surfaces, three machine-checked, plus a first quarter sized for a nine-person company.

    Python

AltStyle によって変換されたページ (->オリジナル) /