Skip to content
View HaDoyle12's full-sized avatar
:shipit:
Working like Detective Squirrel
:shipit:
Working like Detective Squirrel
  • GitHub
  • Nashville
  • 11:20 (UTC -05:00)

Block or report HaDoyle12

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HaDoyle12/README.md

Hunter Doyle

GRCC Department

GRC Audit and Compliance is a product‑focused audit and continuous testing team.
We meet our audit obligations to customers and external stakeholders and give leadership clear insight into GitHub’s control posture.
We also support go‑to‑market efforts by treating customer‑facing assurance reports as product features.

Current audit scope:

  • SOC 1, SOC 2, SOC 3 – GHEC and Actions
  • ISO 27001 – GHEC and Actions
  • FedRAMP Low Tailored – GHEC
  • PCI DSS – GHEC
  • Microsoft non‑financial disclosures – GitHub NFD metrics (Developers, MAC, MEU)
  • Microsoft internal audits – Security Governance, Trade Compliance, and others
  • GHAE – compliance and risk management
  • Azure DevOps – compliance, privacy, and risk programs

Learn more in the Security GRC Compliance repo.

Future Compliance State:

  • ISO 27018
  • ISO 27701
  • ISO 22301
  • ISO 42001
  • FedRamp High

Current Role

GitHub – GRC Security Analyst (Remote, USA)

Policy Lifecycle Management

  • Oversee the end-to-end lifecycle of policies, from development and approval to implementation and review.
  • Collaborate with stakeholders to ensure policies are up-to-date, relevant, and compliant with current regulations and best practices.
  • Lead the formation and execution of steering committee structures to ensure strategic alignment and governance oversight.
  • Facilitate regular meetings and communications with committee members to drive governance initiatives.
  • Develop and document clear roles and responsibilities using RACI (Responsible, Accountable, Consulted, Informed) matrices to ensure accountability and clarity in governance processes.
  • Ensure alignment of roles with organizational goals and governance objectives.

Policy Exception Management Workflow

  • Design and implement a robust policy exception management workflow to handle deviations effectively.
  • Ensure exceptions are documented, reviewed, and approved in a timely manner, with appropriate risk assessments conducted.
  • Oversee processes for review and approval of security exception requests.

Defining KPIs and Metrics

  • Identify and define key performance indicators (KPIs) and metrics to measure the effectiveness of governance policies and programs.
  • Develop dashboards and reporting tools to track and communicate performance metrics.
  • Support the development of dashboards and audit tools to monitor IT risk indicators and internal control health.

Data Gathering, Analysis, and Reporting

  • Collect and analyze data related to policy adherence and governance program performance.
  • Prepare comprehensive reports and presentations for leadership, highlighting insights, trends, and areas for improvement.
  • Drive key Technology, Security, and Data compliance programs in support of the Digital Technology (corporate IT) organization.
  • Partner closely with Legal, Privacy, and Data Security & Governance teams to develop corresponding GRC programs.

Leadership and Collaboration

  • Work closely with cross-functional teams, including legal, compliance, IT, and operations, to align governance initiatives with business objectives.
  • Act as a governance advisor to leadership, providing expert guidance on best practices and emerging trends.
  • 9+ years of related experience, with at least 4+ years of hands-on leadership experience in the Technology Governance Risk and Compliance field.
  • Strong leadership skills, strategy, analytical, problem solving, decision-making; and ability to work under minimum direction.
  • Build and expand relationships with key stakeholders.
  • Ability to evangelize and influence company IT compliance and governance efforts.
  • Build productive customer partnerships and repair strained relationships.
  • Assign work, track progress, and deliver semester and annual performance reviews for team members.

Cloud, AI, and Emerging Technology Architecture

  • Develop and execute a strategic roadmap for advanced Technology & Security architecture, controls, and solutions.
  • Lead efforts to establish governance policies and standards for cloud, AI, and other emerging technologies.
  • Collaborate with technology teams to integrate governance into cloud and AI architecture.
  • Stay informed about emerging technology trends.
  • Experience integrating AI into workflows and decision-making.

Risk Management

  • Implement and manage risk management activities aligned with the GitHub program.
  • Identify, establish, and maintain strategic relationships with key stakeholders.
  • Lead GitHub ISO risk management programs using GitHub Projects and ZenGRC.
  • Partner with executive leadership to respond to security evidence requests.
  • Guide risk-based decisions focused on mitigating identified risks.
  • Provide leadership and oversight for M&A due diligence efforts.
  • Represent GitHub in strategic planning, budgeting, and prioritization.
  • Collaborate with GitHub leaders for program consistency.
  • Integrate GRC requirements into the risk management framework.
  • Architect and deploy controls for GRC emerging priorities.
  • Drove consistency and visibility of risk activities.
  • Oversaw control assessments and leadership remediation.
  • Understanding of frameworks like ISO 27001, ISO 27018, ISO 27701, ISO 42001, ISO 22301, SOC, NIST 800-53 and FedRAMP.
  • Interpret and apply controls from ISO 27001, ISO 27018, ISO 27701, ISO 42001, ISO 22301, SOC, and FedRAMP.
  • Implement optimized, risk-reducing controls.
  • Identify and assess complex business and technology risks; advise management on mitigation.

Issues Tracking and Resolution

  • Manage operational processes that monitor and respond to security threats.
  • Partner with IT to mature operational controls.
  • Lead follow-up education for policy-violating or risky behaviors.
  • Oversaw assessment of controls and ensured deficiencies are addressed.
  • Integrate issue management programs into the GRC framework.

Execution

  • Round on leadership to influence decisions and educate on risk.
  • Lead and coordinate implementation of process and technology changes.
  • Execute technical audits across infrastructure and security environments.
  • Develop and apply audit procedures to test IT controls.
  • Design and execute risk-based audits.
  • Perform control testing and data validation.
  • Conduct walkthroughs and testing for SOC and ISO controls.
  • Define and prioritize strategic projects.
  • Lead major cross-functional initiatives.
  • Contribute to system architecture decisions.
  • Review audit project plans, work papers, and reports; discuss issues with management; confirm quality controls.
  • Plan, schedule, and execute IT audits within budget and deadlines; supervise audit staff and coach for improvement.

Vendor Systems Security

  • Ensure vendor contracts include proper security terms.
  • Work with IT and business leadership to assess and onboard vendor systems securely.
  • Maintain controls for vendor-maintained solutions.
  • Deploy technical controls for Third Party Risk and Resiliency programs.
  • Advise stakeholders on TPRM and vendor-related risk issues.

Communication

  • Coordinate with HR and training teams for GitHub content delivery.
  • Lead proactive communication and awareness campaigns.
  • Create audit reports for technical and non-technical audiences.
  • Exhibit strong written and verbal communication skills.
  • Champion customer security needs internally.
  • Effectively communicate standards and best practices.

Staff Development

  • Recruit and manage contractor staff.
  • Ensure team training and development supports internal audits.
  • Participate in succession planning.
  • Perform other assigned duties.
  • Uphold the “Code of Conduct” and “Mission and Value Statement.”
  • Mentor team members on frameworks and best practices.
  • Assess compliance candidates in hiring processes.
  • Guide others on design, processes, and standards.

Previous Experience

UKG – Weston, FL

Sr. IT Control Analyst

  • Designed, implemented, and tested controls for ISO 27001, ISO 27018, AICPA, and NIST.
  • Built an SDLC audit plan that streamlined controls for 1,500 developers.
  • Managed external SSAE‑18 and ISO 27018 audits and internal assessments.
  • Completed customer due‑diligence questionnaires quickly.
  • Advised stakeholders on changing compliance requirements.
  • Identified risk and guided remediation.

IT Control Analyst

  • Supported compliance, external, and internal audit work.
  • Streamlined internal processes by improving tooling.
  • Maintained risk and control matrices, test plans, and status trackers.
  • Assessed ITGC design and implementation against policies.
  • Verified control evidence for completeness, accuracy, and precision.

RSM US LLP – Miami, FL

Risk Advisory Services Consultant

  • Performed general computer control reviews on UNIX, Windows, AS/400, and Oracle systems.
  • Tested automated application controls for financial reporting software.
  • Evaluated and improved client operational efficiency.
  • Reviewed the design, build, and operation of client business processes.
  • Led cyber‑security risk assessments and audits.
  • Supported financial audit and SOX teams with control design and testing.
  • Assessed security issues and recommended remediation.
  • Managed the IT Audit SharePoint knowledge repository, boosting productivity.

Certifications

License / Certification Effective Date
Certified Information Systems Auditor (ISACA) Dec 2018
Information Security Management Systems v2.1 (BSI) Jun 2017
Management Systems Auditing v2.0 (BSI) Jun 2017
ISO/IEC 27001:2013 Internal Auditor (BSI) Jun 2017

Notable Projects

  • IT design and consulting for Standing Stone Nursery.
  • Intake and review of GitHub bugs reported in HackerOne.

Hobbies

  • Exotic plants 🌴
  • 4‑wheeling 🚴‍♂️
  • Hiking 🥾
  • Travel ✈️
  • Time with the dogs 🐕🐕🐕

Social Media

Popular repositories Loading

  1. SmartThingsPublic SmartThingsPublic Public

    Forked from SmartThingsCommunity/SmartThingsPublic

    SmartThings open-source DeviceTypeHandlers and SmartApps code

    Groovy 1

  2. HaDoyle12 HaDoyle12 Public

    Config files for my GitHub profile.

  3. github-slideshow github-slideshow Public

    A robot powered training repository 🤖

    Ruby

  4. hello-github-actions hello-github-actions Public

    Dockerfile

  5. markdown-portfolio markdown-portfolio Public

  6. github-pages-with-jekyll github-pages-with-jekyll Public