AI Governance & GRC Engineer
Open to mid-level and senior IC roles, W2, remote (US).
I write AI governance policy as a build that fails when a control is missing, and the build generates the evidence a reviewer can re-run.
policy as codebuild-generated evidenceframework mappinggatereceipt
Requirements and proof
| Requirement | Proof |
|---|---|
| Express a framework requirement (NIST AI RMF, ISO/IEC 42001, EU AI Act) as a control that fails the build when it is missing | Governance-mapping case study |
| Generate evidence from the build itself instead of collecting it by hand | Governance-mapping case study - Release-gate case study |
| Keep one control portable across more than one framework mapping | Governance-mapping case study |
| Prioritize evidence that reduces real risk over evidence that only satisfies an assessor | Deterministic gate battery case study |
| Support an assessor with technical evidence mapped to the framework, not a static document | Governance-mapping case study |
| Produce evaluation evidence an independent reviewer can re-run and get the same verdict | Artifact-lineage case study - Release-gate case study |
What could go wrong hiring me
Most proof here is self-built, not a control run inside a regulated organization.
Counter: Release-gate case study
These framework mappings were written by the person who built the system, not an outside assessor.
No formal third-party certification has been issued for this work.
Verify in 60 seconds
- Open the governance-mapping case study and check one control against its stated artifact, /cases/ai-governance-mapping
- Open the release-gate case study and read what one failing assertion does to a merge, /cases/eval-release-gate
- Open the deterministic gate battery case study and read which false-green claim it rejected, /cases/deterministic-gate-battery