Cybersecurity GRC • AI Governance • Risk & Compliance

América Trujillo

Legal-trained cybersecurity professional building practical tools for risk, compliance, audit readiness, and responsible AI governance.

I combine legal reasoning, cybersecurity graduate studies, GRC documentation, Python automation, and hands-on portfolio projects to support security governance, vendor risk analysis, compliance workflows, and business-focused cyber risk decisions.

Best starting point: TrustShield GRC — my Python + Streamlit vendor risk and evidence engine.

Open to remote GRC / Cybersecurity roles

Target Roles

  • GRC Analyst
  • Cybersecurity Risk Analyst
  • Compliance Analyst
  • AI Governance Analyst
  • Security Controls / Audit Readiness Analyst

Professional Story

From law to cybersecurity governance.

About Me

I am building a career at the intersection of cybersecurity, governance, risk, compliance, and responsible AI. My legal background helps me analyze requirements, structure evidence, document controls, and translate complex risk issues into clear business decisions.

My current portfolio focuses on practical GRC tools, risk assessment frameworks, AI governance, vendor risk review, digital forensics, and Python-based automation.

Professional Positioning

My strongest value is connecting legal/compliance thinking with cybersecurity execution. I am especially focused on roles where security teams need documentation, risk analysis, audit readiness, framework mapping, control evidence, and clear reporting.

Experience

Operational discipline, documentation, and risk-focused experience.

Availability Administrator — Kawahara Nurseries

Manage time-sensitive availability and inventory data using PICAS, validate field inputs, identify discrepancies, update system records, and support accurate product visibility. This role strengthens my attention to detail, data validation, documentation, quality control, and operational accountability.

Retail Fulfillment Team Leader — Lowe’s

Led daily fulfillment operations, tracked order status, resolved workflow issues, coordinated across departments, documented operational gaps, and managed multiple priorities under time-sensitive conditions. This experience supports my ability to follow procedures, escalate issues, and maintain reliable records.

Underwriting Assistant / Remote Support — Sigo Seguros

Supported remote insurance underwriting operations by reviewing, correcting, and validating customer data, policy information, identification details, addresses, and risk-related documentation. Processed support tickets and handled compliance-sensitive information with accuracy and discretion.

Bilingual Customer Support — Zipcar / Teleperformance

Provided remote support, documented customer interactions, followed structured procedures, escalated complex cases, and supported users in account, billing, reservation, and service-related issues. Built foundational help desk skills in issue intake, troubleshooting, documentation, and escalation.

Legal Assistant / Trademark Registration Support — Mexico

Prepared, reviewed, and organized legal and administrative documentation for trademark registration processes. Developed transferable skills in research, regulatory interpretation, evidence organization, procedural accuracy, and compliance documentation.

Cybersecurity GRC Portfolio Builder

Building practical cybersecurity projects focused on vendor risk, AI governance, risk scoring, incident response documentation, data validation, anomaly identification, governance documentation, and Python-based automation.

Featured Projects

Practical cybersecurity, GRC, risk and AI governance work.

AI Governance Risk Compliance Framework

AI governance and compliance framework focused on risk exposure, bias considerations, institutional controls, and responsible AI documentation.

AI Governance Compliance Risk

Mobile Forensics Analysis

Digital forensics project analyzing an iOS backup in a data exfiltration scenario, demonstrating investigative documentation and evidence-based reasoning.

Digital Forensics Incident Response Evidence

FinTech Cybersecurity Risk Assessment

Cybersecurity risk assessment project focused on fintech environments, sensitive data, financial systems, and security control considerations.

FinTech Risk Assessment Security Controls

Cybersecurity Risk Assessment Framework

Risk assessment framework demonstrating structured thinking around assets, threats, vulnerabilities, impact, likelihood, and remediation planning.

Cyber Risk Frameworks Documentation

AI Credit Risk Governance Framework

Governance framework exploring AI-enabled credit risk, model oversight, compliance exposure, and responsible decisioning considerations.

AI Risk Credit Risk Governance
GRC Risk Assessment Case Study

SoFi Technologies Cybersecurity Risk Assessment Case Study

Independent cybersecurity GRC case study analyzing fintech risk areas, asset inventory, risk register, risk matrix, control mapping, remediation roadmap, and executive reporting.

FinTech Risk Assessment Control Mapping
GitHub Repo
Audit Readiness Project

Audit Readiness Evidence Binder

Cybersecurity GRC documentation project demonstrating audit readiness, control evidence organization, access control policy documentation, vendor risk review, gap analysis, and remediation planning.

Audit Readiness Evidence Tracking GRC Documentation
GitHub Repo

Skills

Cybersecurity, GRC, documentation, and technical foundations.

GRC & Risk

Risk identification, vendor risk review, audit-ready documentation, control mapping, compliance support, remediation prioritization, evidence organization, and governance workflows.

SOC Support Concepts

Alert triage concepts, incident response concepts, false positive analysis, escalation logic, playbook-based response, case documentation, ticket handling, and security monitoring workflows.

Frameworks & Security Concepts

NIST Cybersecurity Framework, NIST AI Risk Management Framework, access control, MFA, vulnerability awareness, endpoint security concepts, phishing awareness, malware awareness, DNS, TCP/IP, VPN, firewall and IDS/IPS concepts.

Technical Tools

Python, Streamlit, Pandas, GitHub, Markdown, Excel, Microsoft 365, Google Workspace, Windows 10/11, CSV analysis, dashboards, structured documentation, and remote support environments.

Documentation & Operations

Ticket management, SOP compliance, timestamped documentation, quality control, data validation, sensitive information review, record accuracy, workflow coordination, and operational escalation.

Professional Strengths

Bilingual English/Spanish communication, legal reasoning, structured thinking, research, coachability, attention to detail, common sense, persistence, and clear written communication.

Professional Focus

Where my work, projects, and career direction connect.

GRC Portfolio

Evidence-driven GRC work

I build practical cybersecurity projects that show risk analysis, compliance documentation, control mapping, audit readiness, vendor risk review, and structured decision-making.

Technical Proof

Functional cybersecurity tools

My portfolio includes Python, Streamlit, GitHub, and documentation-based projects that turn cybersecurity concepts into usable workflows, dashboards, reports, and review processes.

Target Roles

Remote cyber & GRC roles

I am focused on remote Junior GRC Analyst, Cybersecurity Risk Analyst, SOC Support, Compliance Analyst, Vendor Risk, Security Documentation, and Audit Readiness roles.

Long-Term Direction

AI Governance & Cyber Risk

My long-term direction is to grow in responsible AI governance, cyber risk, compliance, regulatory mapping, security controls, and business-focused cybersecurity decision-making.

Behind the Work

A personal note on purpose, values, and how I work.

Read the personal note Law • Cybersecurity • GRC • Animal Welfare

From Mexico City to Cybersecurity

I was born and raised in Mexico City. From an early age, I felt drawn to systems, logic, and technology. My original dream was to study systems engineering, but at that time my economic reality required me to take a different path.

Instead of stopping, I built with what I had. I studied English, pursued a law degree, and developed strong analytical, documentation, and research skills. Law trained me to organize evidence, interpret complex rules, communicate clearly, and think with structure.

Why GRC Feels Like the Right Place

That journey eventually brought me to the United States, where I am now building my career in cybersecurity and legal tech. GRC, risk, compliance, and AI governance feel like the place where my legal background, technical curiosity, and risk-focused mindset connect.

I do not pretend to know everything. What I bring is persistence, coachability, common sense, discipline, and the ability to research, follow direction, document clearly, and keep improving until I understand the problem and can help solve it.

Beyond the Screen 🐈‍⬛

Outside of cybersecurity, I care about animal welfare and community-based rescue efforts such as TNR. I value patience, structure, empathy, and long-term responsibility.

Those values also shape the way I approach GRC work: protect what is vulnerable, document what matters, reduce risk, and help build systems that are safer, clearer, and more accountable.

My Working Philosophy

I believe the most valuable professionals are not the ones who pretend to know everything. They are the ones who can listen, follow instructions, ask better questions, research carefully, learn fast, document their work, and keep going until the result is clear and useful.

Resume

Junior Cybersecurity & GRC Analyst | SOC Support | Risk & Compliance

I am seeking fully remote junior cybersecurity, SOC support, GRC, risk, compliance, security documentation, audit readiness, or incident response support roles. My background combines legal analysis, remote support, ticket handling, data validation, structured documentation, cybersecurity fundamentals, and Python-based portfolio projects.

Download Resume

Contact

Let’s connect.

I am focused on remote cybersecurity GRC, SOC support, risk, compliance, AI governance, audit readiness, security documentation, and incident response support roles.