Benjamin S. Hobbs

GRC Engineer | AWS & GCP Security Specialist | Cloud Compliance
📍 Remote Preferred | Phoenix, AZ | Open to relocation

I'm a GRC Engineer with with over a decade of foundational risk management experience and 3+ years specializing in GCP and AWS cloud security architecture. I design and implement automated compliance workflows that empower engineering teams to move faster with confidence. By translating complex standards and frameworks (SOC 2, ISO 27001, ISO 42001, HIPAA, CSA STAR, PCI DSS) into actionable, policy-as-code (PaC) deployments, I help organizations mature their security postures and reduce audit preparation by an average of 30%. Let's connect to discuss how we can achieve your business objectives and build resilient environments together.

Connect on LinkedIn Download Resume Book a Meeting (30 mins)

Skills & Expertise

Core Competencies

Policy as Code (PaC) Infrastructure as Code (IaC) CI/CD Pipelines Threat Modeling Security Architecture Review TPRM

Tools & Technologies

Terraform AWS / GCP / Azure OPA / Rego Conftest Cosign / OSCAL Security Hub / GuardDuty VS Code / WSL Ubuntu Python / Bash

Frameworks & Standards

ISO 27001 / ISO 42001 SOC 2 HIPAA NIST 800-53 / 800-171 CIS Controls NIST RMF / CSF 2.0

Featured Projects

ISO 42001 AIMS Certification

Led the successful implementation and certification process for a ISO 42001 AI Management System.

  • Drafted over 12 policies for review and approval, and conducted annual review.
  • Gathered evidence and supervised submission of evidence for 88 custom controls.
  • Supported in-person and virtual meetings for internal and external audits with senior leadership and audit team.
  • Conducted quarterly access reviews and published initial Impact Assessment
GCP Vanta EntraID Confluence

ISO 27001 ISMS Certification

Supported and Implemented a certification process for a ISO 27001 Information Security Management System.

  • Drafted 45 policies for review and approval, and created artifacts for ISMS structure.
  • Gathered evidence and supervised submission of evidence for 81 custom controls across 3 separate locations.
  • Supported in-person and virtual meetings for internal and external audits with senior leadership and audit team.
  • Conducted 6 quarterly access reviews for 14 in-scope systems.
GCP Vanta EntraID Confluence

GRCEportfolio: Automated Governance Pipeline

Built a secure CI/CD pipeline to automate real-time audit-grade evidence gathering, reducing audit prep time by up to 85%.

  • Created secure Cloud IaC using Terraform.
  • Configured artifact signing using Cosign.
  • Automated Security Gates via GitHub Actions (grc-gate workflow) utilizing OPA, Rego, and Conftest.
  • Configured machine-readable documentation via OSCAL.
AWS Terraform OPA/Rego Conftest Cosign

Cerulean Shield: Threat Detection

Simulated Blue Team response to monitor defensive systems and improve threat detection capabilities following a sensitive data exposure misconfiguration incident.

  • Deployed Blue Team defense solutions for an AWS cloud environment against simulated attackers.
  • Leveraged network analysis and log monitoring.
AWS Splunk Snort

SilverLine Security: PCI DSS Cloud Infrastructure

Designed and implemented a secure, PCI DSS compliant cloud infrastructure with threat emulation.

  • Architected secure AWS infrastructure integrating VPC, EC2, KMS, and GuardDuty.
  • Developed comprehensive SOPs and Security Incident Plans.
  • Simulated VPC-contained attacks using Stratus Red Team.
AWS Architecture Wazuh SIEM Stratus Red Team

GreenGenius & Cloud Capstone Labs

Enterprise integration automation and extensive cloud deployment lab environments.

  • Automated employee data integration into Active Directory via secure VPC tunnels.
  • Provisioned complex, multi-environment infrastructure across capstone labs (cgep-capstone, cgep-labs-benny) validating architecture best practices.
Active Directory AWS VPC PowerShell

Certifications

  • ISC2 CISSP-Associate (Certified Information Systems Security Professional)
  • Certified GRC Engineer - Practitioner (CGE-P)
  • GCP Professional Cloud Security Engineer (GCP CSEP)
  • GCP Associate Cloud Engineer (GCP ACE)
  • CSA Certified Cloud Security Knowledge (CSA CCSK)
  • CompTIA Security+
  • CompTIA Network+
  • GIAC Continuous Monitoring (GIAC GMON)
  • GIAC Incident Handling (GIAC GCIH)
  • GIAC Security Essentials (GIAC GSEC)
  • GIAC Foundational Cybersecurity Technologies (GIAC GFACT)