Brian Tomasetti
Senior cybersecurity and governance leader specializing in GRC program design, cloud security architecture, compliance automation, and enterprise risk management for regulated AWS environments.
Governance, Risk & Compliance
Scalable GRC programs spanning SOX, PCI-DSS, GDPR, HIPAA, ISO 27001, and NIST — transforming compliance from audit-driven exercises into risk-based programs that enable business growth.
Cloud Security Architecture
AWS security strategy, multi-account governance, SCPs, and compliance automation using CloudFormation, Lambda, and DevSecOps pipelines for regulated workloads.
Cybersecurity Assurance
Partnering with auditors, regulators, executives, and enterprise customers to demonstrate control effectiveness and translate regulatory requirements into scalable cloud security controls.
Professional Experience
Cloud security, governance, and compliance across enterprise environments.
Certifications
Skills & Technologies
Blog
Writing on cloud security, AI risk, and governance strategy.
AWS Solutions
Reusable architecture patterns, automation templates, and governance frameworks.