# Susan Shepard

Boston, MA  
Email: HireSusanShepard@pm.me  
LinkedIn: https://www.linkedin.com/in/xnasusx/  
GitHub: https://github.com/xnasusx  
Portfolio: https://xnasusx.github.io/portfolio/

## Summary

Veteran GRC engineer who builds platforms that scale compliance, architecting full-stack systems with React, Node.js/Express, and PostgreSQL that automate evidence collection, multi-framework compliance mapping, and FAIR-based quantitative risk scoring. Partners with product and engineering teams to embed AI into GRC workflows and translate technical risk into board-level decisions.

Focus areas: President and Founder of the Boston Chapter of the GRC Engineering Club, cyber risk quantification (FAIR), AI-driven security automation, RAG-based GRC tooling, and agentic workflow development.

## Experience

### Rapid7 - Boston, MA

Staff - Trust, Risk, and Compliance Analyst - Information Security, Feb 2026 - Present  
Lead Security Risk Analyst, Feb 2023 - Feb 2026  
Lead Security Compliance Analyst, Sep 2021 - Feb 2023

- Architected and engineered InsightGRC, an autonomous GRC and continuous control monitoring platform using React/Vite, Node.js/Express, and PostgreSQL on Cloud SQL.
- Automated evidence collection, multi-framework compliance mapping, third-party risk assessment, and executive audit reporting end to end.
- Built automated import engines, data models, and crosswalk parsers mapping 15+ frameworks including NIST SP 800-53 r5, ISO 27001/27017, PCI-DSS, FedRAMP, GovRAMP, TxRAMP, DORA, NIS2, Cyber Essentials, CSA CCM/CAIQ, and OSCAL.
- Developed a Node.js/Slack Bolt evidence-automation pipeline pulling continuous control evidence from GCP infrastructure, IdPs, EDRs, Google Drive, Jira, and Freshservice.
- Built two-way OneTrust sync scripts for treatment kickoffs and vendor assessments.
- Built AI Evidence Scout and rubric assessors to validate evidence sufficiency and score control health.
- Integrated a FAIR-based risk quantification model into an LLM application for contextual risk scoring at scale.
- Authored a Manifest V3 Chrome extension, cra-portal-assistant, for customer risk assessment questionnaire fulfillment across Archer, OneTrust, and Ombud.
- Built SCRM and vendor-intake workspaces for third-party risk profiling, cutting CRA response SLAs from weeks to days.
- Designed PostgreSQL schemas with immutable audit logging and dual-write state tracking for audit workspaces and User Access Review campaigns.
- Architected Rapid7's first Integrated IS Risk Management Framework and founded its first annual Security Risk Assessment.
- Built Incident Severity and Findings Management calculators, standardizing cyber-event classification and cutting triage time 40%.
- Led Rapid7's SEC Cyber Incident Disclosure program and directed audit readiness to 100% evidence submission with zero findings.

### Seven Bridges, Inc. - Boston, MA

Senior Risk and Compliance Analyst, Mar 2020 - Sep 2021

- Managed 650+ vendors and executed audits for HIPAA, ISO, NIST, SOC, and FedRAMP compliance.
- Negotiated and reviewed security and privacy contracts including BAA, ISA, and MSA agreements, enabling $1.5M+ in quarterly bookings.
- Drove 14+ audit assurance activities across security and privacy frameworks.

### Acquia, Inc. - Boston, MA

Senior Information Security Analyst, Nov 2019 - Mar 2020  
Senior Risk and Controls Analyst, Information Security, Aug 2018 - Mar 2019  
Risk and Controls Analyst, Information Security, Nov 2017 - Aug 2018

- Designed and implemented a global GDPR compliance program covering policies, vendor due diligence, lawful processing, breach response, and training.
- Managed 900+ vendors with audits against HIPAA, ISO, NIST, SOC, and FedRAMP standards.
- Delivered enterprise-wide audit readiness across security and privacy standards.

### Nuance Communications, Inc. - Burlington, MA

Healthcare IT GRC Analyst, Information Security, Jan 2017 - Nov 2017

- Built a formal security and privacy GRC program for the healthcare division, aligned to HIPAA, HITRUST, ISO, NIST, and SOC 2.
- Reviewed security and privacy contracts, enabling $1.2M+ in quarterly compliant revenue.

### iRobot - Bedford, MA

Program Coordinator - Information Security, Intern, May 2016 - Jan 2017

### Veritas, formerly Symantec

Backup and Recovery Testing Engineer - Intern, Nov 2015 - May 2016

## Education

- Boston University - M.S. Computer Information Systems, Concentration: Security
- University of Massachusetts Lowell - B.S. Information Technology, magna cum laude

## Certifications

- Certified Information Security Manager (CISM), ISACA
- Certified in Risk and Information Systems Control (CRISC), ISACA
- Advanced in AI Security Management (AAISM), ISACA
- Advanced in AI Risk (AAIR), ISACA
- Certified in Cybersecurity (CC), ISC2
- AWS Certified Cloud Practitioner (CLF-C02), AWS

## Skills

- Risk and compliance: Security Risk Management, FAIR Risk Quantification, CVSS, OWASP, GDPR, HIPAA, ISO 27001, NIST CSF, SOC 2/3, FedRAMP, HITRUST, EO-14028 Materiality Analysis
- AI and automation: LLM integration for automated risk scoring, prompt engineering, agentic workflow development, RAG-based GRC tooling
- GRC platforms: OneTrust, Archer, ServiceNow GRC, AuditBoard
- Programming and tools: React, Vite, Node.js, Express, PostgreSQL, Python, SQL, Excel, Slack Bolt, Chrome Extensions, Docker
- Cloud security: AWS, GCP, cloud risk assessment and controls, cloud GRC platform architecture

## Leadership And Contributions

- ISC2 Technical Guidance Paper Co-Author and Subject Matter Expert
- Medium article: "Hari Seldon Would've Made a Great CISO: What Cyber Risk Analysts Can Learn From Asimov's Foundation"
- Medium profile: https://medium.com/@xnasusx
- GRC Engineering Club - President and Founder, Boston Chapter: https://grcengclub.com/chapters/boston#join
- ISACA AAISM Beta Tester
- ISACA AAISM Exam Writing Development Group - Exam Writer
- Mentoring: Big Brothers Big Sisters, ISACA, and Boston University Admissions
- Military veteran
