Angeline Williams

GRC Analyst | Cloud Compliance & Automation

Open to GRC, cloud compliance, and security compliance roles

About Me

I'm a GRC and cloud compliance specialist with nine years across internal audit, consulting, and enterprise information security. I know the manual side of compliance, including walkthroughs, evidence collection, remediation tracking, and audit readiness, because I've done it at scale in fintech and enterprise environments.

Today I bring that foundation to roles where governance, risk, and compliance meet modern infrastructure. I evaluate controls against NIST, SOC 2, ISO 27001, SOX, and PCI requirements, partner with engineering and security teams on findings, and build automation with AWS, Python, Terraform, and OPA that turns recurring control checks into repeatable workflows instead of annual fire drills.

I publish hands-on compliance labs on GitHub, teach what I'm actively learning on my YouTube channel, and was a guest speaker for a graduate Network Security & AI course at California Science and Technology University.

For me this isn't just a job title. Cybersecurity is how I move through the world by respecting people's data, earning trust, and treating privacy as something worth protecting in every part of life, not just at work.

Featured Projects

CI/CD Compliance Pipeline

An end-to-end compliance pipeline that runs policy checks on every Terraform change. Non-compliant configs fail the build so they never deploy. Uses short-lived AWS credentials (not long-lived keys) and policy-as-code so preventive controls live in the pipeline and not in a spreadsheet.

Frameworks: SOC 2 · NIST 800-53 · ISO 27001

Evidence produced: Failed/passed policy gate logs, Terraform plan output, CI run history for change-management audits.

CircleCIAWS OIDCOPA / RegoTerraform
View on GitHub →

AWS IAM Compliance Scanner

An automated compliance scanner that checks 3 IAM controls that auditors ask for first: password policy strength, MFA enforcement, and root account activity. It produces audit-ready JSON and CSV evidence mapped to frameworks, so you spend less time formatting evidence and more time on remediation.

Frameworks: SOC 2 · NIST 800-53 · ISO 27001

Evidence produced: Timestamped JSON + CSV reports with per-control pass/fail and finding details.

PythonAWS LambdaCloudFormation
View on GitHub →

CGE-P Capstone

The capstone project remediates a non-compliant healthcare API across four layers: Terraform baseline fixes, OPA Rego policy gates, a signed-evidence CI/CD pipeline, and OSCAL component definitions. Includes a red PR that fails the gate and a green PR that passes.

Frameworks: CMMC Level 2 · NIST SP 800-171

Evidence produced: Cosign-signed evidence bundles, S3 Object Lock vault, OSCAL component/profile artifacts, PR gate pass/fail history.

TerraformOPA / RegoGitHub ActionsOSCAL
View on GitHub →

Skills & Expertise

Cloud & Security

  • AWS
  • Terraform
  • CI/CD Pipelines
  • Policy-as-Code (OPA / Rego)

GRC & Compliance

  • NIST CSF & RMF
  • SOC 2 & ISO 27001
  • Risk Assessment & Audit
  • Compliance Automation

Engineering & AI

  • Python & Boto3
  • Amazon Bedrock
  • Bash
  • CloudFormation / IaC

Certifications

CISA Certification Badge

Certified Information Systems Auditor (CISA)

CGE-P Certification Badge

Certified GRC Engineer - Practitioner (CGE-P)

AWS AI Certification Badge

AWS Certified AI Practitioner

AWS Cloud Certification Badge

AWS Cloud Practitioner

ISO 42001 Badge

ISO/IEC 42001:2023 Lead Auditor

ISO 27001 Badge

ISO/IEC 27001:2022 Lead Auditor

ISO 27701 Badge

ISO/IEC 27701:2025 Lead Auditor

Comptia Network Plus Badge

CompTIA Network+

Comptia A Plus Badge

CompTIA A+

Linux Badge

LPI Linux Essentials

Let's Connect

Open to GRC, cloud compliance, and security compliance roles. Connect on LinkedIn, GitHub or YouTube.

What YouTube Viewers Are Saying