Senior DevSecOps & GRC Security Engineer focused on building secure, compliant, and automated cloud environments.
I specialize in turning complex regulatory and compliance requirements into practical, automated security controls β bridging GRC, DevSecOps, and Cloud Security.
- Design and implement policy-as-code and compliance automation solutions
- Integrate security into CI/CD pipelines and cloud infrastructure
- Lead evidence collection, control validation, and audit readiness efforts
- Build tools that reduce manual GRC work while strengthening security posture
- CloudComply β Compliance and security tooling
- CycloneDx-Viewer β SBOM visualization and analysis tool
Cloud & Security
- AWS (IAM, Config, Security Hub, Control Tower), Azure, GCP
- NIST RMF, FISMA, CMMC, Compliance Automation
- DevSecOps, CI/CD Security, IaC Security (Terraform)
Languages & Tools
- Python, Go, Bash
- Policy-as-Code, Infrastructure as Code
- Prowler, Nessus, SIEM, Container Security
Focus Areas
- GRC Engineering β’ Cloud Security Architecture β’ Automation β’ Audit Readiness
- Portfolio: willj4945.github.io/portfoliov2
- LinkedIn: linkedin.com/in/will-johnson-...
- Currently open to: Senior Cloud Security Engineer, GRC Engineer, and Security Assurance roles (Remote or hybrid)
Always learning, automating, and securing the cloud.


