Open to senior GRC leadership roles

Noor Shehub

>

I build and run the compliance programs that let cloud platforms sell into regulated markets — federal, financial services, and healthcare. Twelve years of turning control frameworks into something engineering teams can actually operate.

01 — Profile

Compliance that holds up under audit

I'm a GRC and cloud security leader with 12+ years building and running compliance programs across multi-cloud environments — AWS, Azure, and GCP.

My work is hands-on: leading SOC 2 Type II, ISO 27001, FedRAMP, PCI DSS, HITRUST, and IRAP engagements with external auditors and assessors from planning all the way through certification. Authoring the security policies and standards underneath them. Fielding the customer security assessments and due-diligence reviews that gate enterprise deals. Supporting privacy obligations under GDPR and CCPA, and reviewing security and data-protection contract terms alongside Legal.

Right now I lead compliance for an enterprise AI/analytics platform, with growing involvement in AI governance and the controls needed to develop and deploy machine learning systems responsibly.

compliance-posture.log
FedRAMP Rev 5 READY
CMMC Level 2 IN PROGRESS
SOC 2 Type II CERTIFIED
ISO 27001 CERTIFIED
Framework coverage6 / 6
Cloud environmentsAWS · Azure · GCP
Certifications held12
02 — Selected work

Programs I've built and run

Multi-year compliance programs, federal authorizations, and the internal tooling that keeps them moving. Select any card for the full case study.

03 — Experience

Twelve years, one direction

Help desk to security analyst to federal assessor to cloud compliance lead. Every step added a layer to how I think about controls.

04 — Credentials

Twelve certifications, four disciplines

Security leadership, audit, cloud, and offensive/defensive practice — plus the degrees underneath them.

05 — Writing

Notes from inside the program

Field notes on federal authorization, CMMC scoping, and what AI governance actually looks like when you have to enforce it.

06 — Contact

Let's talk compliance

Whether you're heading into a first FedRAMP package, scoping CMMC, or trying to get five audit programs onto one evidence base — I'm happy to compare notes.