Hi, I'm Terence Webster

Aspiring GRC Professional | ISO 27001 & ISO/IEC 42001 Lead Auditor

Certified ISO 27001 & ISO/IEC 42001 Lead Auditor with 8+ years enterprise experience, building automated compliance solutions for AWS environments. Expertise in AI governance, information security, SOC 2, and NIST frameworks with 10 production security automation projects.

95%
Time Reduction in Compliance Reporting
100%
S3 Compliance Achieved in 24 Hours
$2,400
Monthly Cost Savings from Automation
10+
Production Security Tools Built

About Me

I'm a certified ISO 27001 & ISO/IEC 42001 Lead Auditor and GRC professional transitioning from 8+ years in B2B technology sales to cloud security and compliance. I combine an auditor's mindset with hands-on AWS security automation expertise and proven business acumen.

My Certifications Set Me Apart: As an ISO 27001 Lead Auditor and ISO/IEC 42001 Lead Auditor (AI Management Systems - the world's first international AI governance standard), I bring deep knowledge of information security management systems, AI governance, and audit processes. Combined with CompTIA Security+ and AWS Certified Cloud Practitioner, I understand both the compliance frameworks organizations must meet and the technical controls needed to implement them in AWS environments.

From ByteChek to Building: My passion for GRC was ignited at ByteChek, where I sold compliance automation solutions and worked directly with security teams implementing SOC 2, ISO 27001, and NIST frameworks. I saw firsthand how organizations struggle to bridge the gap between audit requirements and technical implementation, so I decided to become the bridge.

Technical Expertise: I've built 10 production-ready AWS security automation tools using Python and AWS services, demonstrating practical experience with IAM policy analysis, Security Hub integration, compliance monitoring, and automated remediation. Each project translates security controls into measurable, automated solutions.

Business Value: With 8+ years leading enterprise accounts and consistently exceeding sales targets by 30%, I excel at stakeholder communication, translating technical concepts for executives, and aligning security initiatives with business objectives. I don't just implement controls, I ensure they drive business value.

🏆 Certifications

  • ISO 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor (NEW - AI Governance)
  • CompTIA Security+
  • AWS Certified Cloud Practitioner

💼 Experience

  • Key Accounts Team Lead
    Housecall Pro
  • Account Executive
    ByteChek (Compliance SaaS)
  • 8+ Years B2B Technology Sales
  • Consistently 30%+ Above Quota

Professional Certifications

Validated expertise in security, compliance, and cloud technologies

🏆

ISO 27001 Lead Auditor

International Register of Certificated Auditors (IRCA)

Certified to conduct comprehensive information security management system (ISMS) audits. Deep expertise in ISO 27001 controls, audit processes, and compliance frameworks.

ISMS Auditing ISO 27001 Risk Assessment Compliance
🔒

CompTIA Security+

CompTIA

Industry-standard certification validating foundational cybersecurity skills including threat analysis, risk management, cryptography, and security operations.

Threat Analysis Network Security Cryptography Risk Management
🤖
NEW CERTIFICATION

ISO/IEC 42001 Lead Auditor

Mastermind Assurance

Certified to audit AI Management Systems (AIMS) under the world's first international standard for AI governance. Expertise in AI risk management, responsible AI practices, ethical AI implementation, and regulatory compliance for AI systems.

AI Governance ISO/IEC 42001 AI Risk Management Responsible AI AI Ethics
☁️

AWS Certified Cloud Practitioner

Amazon Web Services (AWS)

Foundational AWS certification demonstrating understanding of cloud concepts, AWS services, security, architecture, and pricing models.

AWS Services Cloud Architecture AWS Security Cost Optimization

Featured Projects

AWS Security Automation & GRC Tools

All Projects

🏢

Multi-Account Security Hub Aggregator

Enterprise-scale Lambda function aggregating Security Hub findings across AWS accounts with Excel reporting. Processed 446+ findings.

Lambda Security Hub STS Multi-Account
View on GitHub
📊

AWS Security Hub Excel Pipeline

Serverless pipeline generating professional compliance reports from Security Hub findings with CloudFormation deployment.

Lambda S3 CloudFormation Excel
View on GitHub
🔧

S3 Auto-Remediator

Automatically enables versioning on non-compliant S3 buckets with dry-run safety mode for secure operations.

Python S3 Automation Remediation
View on GitHub
🔍

IAM Policy Auditor

Detects overly permissive IAM policies with full admin access patterns and generates detailed CSV reports.

IAM Security Compliance Auditing
View on GitHub
🛡️

Least-Privilege Compliance Checker

Advanced IAM policy analyzer detecting 5 types of least-privilege violations with severity-based findings and actionable recommendations.

IAM Least-Privilege Security Analysis Compliance
View on GitHub
💾

EBS Volume Remediator

Identifies and removes unattached EBS volumes for cost optimization and security improvement.

EC2 Cost Optimization Automation
View on GitHub
🔔

GRC Alerter

Event-driven security monitoring with AWS SNS email alerts for IAM policy violations.

SNS Alerting Monitoring
View on GitHub
🪣

S3 Bucket Auditor

Audits S3 buckets for versioning and public access compliance with detailed reporting.

S3 Compliance Auditing
View on GitHub
🔐

IAM MFA Auditor

Identifies IAM users without MFA enabled to enforce security best practices.

IAM MFA Security
View on GitHub
🛡️

EC2 Security Group Auditor

Detects risky security group rules exposing sensitive ports to the internet.

EC2 Network Security Auditing
View on GitHub

Key Achievements

Measurable impact through security automation and compliance engineering

⚡ 95% Time Reduction

Reduced audit preparation time from 40 hours to 2 hours per quarter through automated Security Hub reporting and Excel pipeline

🎯 100% Compliance

Achieved 100% S3 bucket compliance across multi-account AWS environment within 24 hours of deployment using automated remediation

💰 $2,400/Month Saved

Identified and eliminated $2,400 in monthly costs through automated detection and cleanup of unattached EBS volumes

🔒 60% Risk Reduction

Discovered 47 high-risk IAM policies in production environment, reducing privilege escalation attack surface by 60%

📊 446 Findings Processed

Aggregated and analyzed 446+ Security Hub findings across 10+ AWS accounts with centralized reporting and prioritization

⚙️ 10+ Tools Deployed

Built and deployed 10+ production-ready AWS security automation tools using Python, boto3, Lambda, and CloudFormation

Technical Skills

Cloud & Security

  • AWS (Lambda, Security Hub, S3, IAM, EC2, SNS, STS, Organizations)
  • Infrastructure as Code (CloudFormation, Terraform)
  • Multi-account architecture & cross-account access
  • Security automation & compliance frameworks

Programming & Tools

  • Python (boto3, pandas, openpyxl)
  • Git/GitHub
  • AWS CLI
  • Serverless architecture

GRC & Compliance Frameworks

  • ISO 27001:2022 (Lead Auditor Certified)
  • SOC 2 Type II
  • NIST Cybersecurity Framework (CSF)
  • CIS Controls
  • Security auditing & ISMS implementation
  • Risk assessment & mitigation
  • Compliance automation & reporting

Resume

Download my complete professional resume

Terence Webster - GRC Professional

Comprehensive resume highlighting 10+ AWS security automation projects, ISO 27001 Lead Auditor certification, and 8+ years of enterprise experience. Includes detailed project accomplishments, technical skills, and certifications.

10+ Security Projects
ISO 27001 Lead Auditor
8+ Years Experience
Download Resume (PDF)

Last Updated: October 2025

Get In Touch

Let's connect and discuss cloud security and GRC opportunities!

LinkedIn

Connect with me

Location

San Diego, CA, USA

Send Me a Message