I spent 13 years in mechanical engineering — teaching, academic project coordination, and compliance-cycle work (institutional and program accreditation). After moving to Germany, I completed an MBA in International Management and worked as a working student and intern within Deutsche Börse Group, supporting IT demand management, PMO governance, and audit/compliance tracking.
Alongside this, I built hands-on technical grounding in DevOps and infrastructure — Terraform, Docker, CI/CD pipelines, and Linux/scripting (see my other repositories). That technical foundation now feeds directly into where I'm headed: Governance, Risk & Compliance, with a focus on Third-Party Risk Management (TPRM) and Enterprise Risk Management (non-financial).
This is my ongoing GRC knowledge log — what I'm learning, how I'm learning it, and the artifacts I'm building along the way.
I'm building toward Enterprise Risk Management, starting with Risk Assessment — identifying, scoring, and prioritizing risk — since that's the most realistic entry point for where I am now. Over time, I'm aiming toward Audit and Implementation work, since that's the side of GRC I find most engaging: not just defining rules, but checking whether they actually hold up in practice. I stay open to opportunities across Policy, Risk, and Audit as they come.
This is self-directed learning, built from publicly available GRC/TPRM concepts and frameworks found across the internet. Templates were generated using AI tools, based on general business document structures and my own study notes. I have not yet worked professionally in a dedicated GRC role — this reflects study and applied practice while transitioning into the field, not on-the-job experience.
| Folder | Focus |
|---|---|
/TPRM |
Third-party risk lifecycle — planning, due diligence, contracting, monitoring, disengagement |
/ERM |
Enterprise risk frameworks, risk assessment, non-financial risk |
/ISO27001 |
Information security management notes and artifacts |
/ITIL |
Service management foundations |
/Security+ |
Security fundamentals notes |
- ISO 31000 (Enterprise Risk Management)
- ISO 22301 (Business Continuity)
- ISO 42001 (AI Governance)
- DORA, NIST frameworks
- GDPR, PCI DSS, HIPAA, OWASP
Still loading — this list grows as I do.
Because this reflects study rather than lived practice, some structures or sequencing here may not perfectly match how these functions run inside a real organization. If you work in this field and spot something off, corrections are genuinely welcome — feel free to open an issue or a pull request. I'd rather this be accurate than polished.