Last login: Loading... on ttys000
josh@joshdoes.it:~$

Josh Jones

> GRC Engineering & Security Automation Specialist
Operationalizing GRC programs through code, integrations, and workflow automation across enterprise environments.
josh@joshdoes.it:~$ cat about.txt

About Me

// Professional Summary

GRC engineering and security operations specialist skilled at turning compliance frameworks into scalable controls, building audit-ready systems, and bridging regulatory and engineering worlds in fast-paced environments. Experienced across IT and security domains including security architecture, security governance, security risk management, system administration, networking, and application development.

// Certifications
  • > CISSP - Certified Information Systems Security Professional
  • > CISA - Certified Information Systems Auditor
  • > CSIS (A+, Network+, Security+)
  • > PCI ISA - PCI Internal Security Assessor
  • > PCIP - Payment Card Industry Professional
  • > Project+
  • > ISO 42001:2023 Lead Auditor
// Contact Info
// Education
degree: BS, IT - Information Assurance and Security
school: Capella University
status: Graduated Summa Cum Laude (4.0 GPA)
NSA & DHS Designated National Center of Academic Excellence
josh@joshdoes.it:~$ cat experience.log

Work Experience

Compliance Programs Manager, Security and Healthcare

06/2024 - Present
InComm Payments • Atlanta, GA
  • > Built the enterprise Compliance Engineering function, automating continuous monitoring across Azure, M365, AWS, OCI, and on-premises environments
  • > Reduced audit prep time for controls through automated audit evidence collection, saving engineering teams countless hours
  • > Built custom agentic AI review processes for control and policy/standard mapping, POAM drafting, evidence review, and questionnaire response drafting
  • > Successfully completed over 25 external audits or assessments annually covering PCI DSS, PCI Secure Software Standard, HITRUST, SOC1, SOC2, SOC3, and partner audits
  • > Partnered with DevOps, Security, and Infrastructure teams to embed compliance into SDLC practices
  • > Performed control mapping to enable the development of a common control framework

Security & Healthcare Compliance Analyst IV, Lead

01/2022 - 06/2024
InComm Payments • Atlanta, GA
  • > Served as the primary internal PCI subject matter expert covering four level one PCI DSS ROCs and one PCI Secure Software Standard product
  • > Led internal Operational Readiness reviews for hundreds of projects and new products, partnering with product and engineering teams
  • > Collaborated with PCI SSC's Special Interest Group (SIG) to help develop industry guidance "PCI DSS Scoping and Segmentation Guidance for Modern Network Architectures"
  • > Participated in RFCs as a PCI SSC Participating Organization, helping to develop numerous PCI standards

Senior PCI Security Analyst

06/2021 - 12/2021
Information & Infrastructure Technologies, Inc. • Herndon, VA
  • > Worked with numerous high-profile clients to improve security readiness and compliance with PCI DSS
  • > Reviewed technical controls, system configurations, policies, and procedures to assess compliance and recommend improvements
  • > Worked closely with company executives and clients on the development of a SaaS-based integrated risk management (IRM) platform capable of supporting 800+ compliance standards

Information Security Analyst

01/2021 - 06/2021
Information & Infrastructure Technologies, Inc. • Herndon, VA
  • > Worked under the PCI QSA and assisted with PCI assessments
  • > Wrote various scripts to assist with the collection of evidence

Systems Analyst

10/2019 - 01/2021
City of Kingsport • Kingsport, TN
  • > Administered numerous systems including ERP, ITAM, POS, E-Mail, Document/Records Management, M365, Public Safety, and more
  • > Administered a mixed environment of Windows, Linux, and IBM i operating systems
  • > Implemented various security technologies such as the Elastic Stack for SIEM and centralized logging capability as well as CrowdStrike for EDR
  • > Wrote various scripts and utilities to assist with patch management, automation, and more
  • > Assisted with security compliance related activities (PCI DSS and CJIS)

IT Helpdesk Analyst

03/2019 - 10/2019
City of Kingsport • Kingsport, TN
  • > Triaged and routed all IT service requests as the sole Help Desk Analyst
  • > Provided tier 1 & 2 technical support for over 600 users and 800 devices including mobile phones, laptops, desktops and servers
  • > Performed Active Directory administration including the management of users, organizational units, security groups, and group policies

Co-Founder

05/2018 - 09/2019
Cell4More.com • Kingsport, TN
  • > Developed web application front-end and back-end for e-waste recycling business
  • > Operated e-waste recycling business, refurbishing and reselling used electronics including cell phones, laptops, desktops, and more
josh@joshdoes.it:~$ ls skills/

Technical Skills

Frameworks & Standards

  • • PCI DSS, Secure Software Standard, Secure Software Lifecycle, Key Management Operations, Point-to-Point Encryption, PIN
  • • SOC 1, SOC 2, SOC 3
  • • HITRUST CSF
  • • HIPAA
  • • CMS Chapter 9 and 21
  • • ISO 42001
  • • CJIS
  • • More...

Tools & Technologies

  • • Wiz, ImPAC, Qualys, Snyk
  • • ServiceNow, Jira, Azure DevOps
  • • Copilot Studio
  • • Power Automate, Python, Bash, PowerShell
  • • Elastic Stack, Exabeam, CrowdStrike
  • • Hyperproof

Cloud Platforms

  • • AWS
  • • Azure
  • • GCP
  • • OCI
josh@joshdoes.it:~$ ./contact.sh

Get In Touch

Ready to discuss security compliance challenges or explore collaboration opportunities? Drop me a message and let's secure the digital world together.