I'm focused on improving my Python skillset and building practical GRC engineering projects. I learn by shipping small, useful tools and documenting what works (and what doesn't).
- Building small Python tools that solve real security/GRC problems
- Turning governance and compliance processes into code and automation
- Sharing progress openly to help others on the same path
- Data parsing and normalization (CSV/JSON/YAML, pandas basics)
- APIs and automation (requests, authentication, rate-limits, retries)
- CLI tooling and packaging (argparse/Typer, virtualenv/poetry, publishing)
- Secure coding habits (secrets handling, logging, error handling, tests)
- [Policy-as-Code Starter]
- [Controls Automation]
- [Risk Register CLI]
- [Evidence Pipeline]
- [Vendor Risk Helper]
- Python for security automation (APIs, CLIs, packaging)
- GRC engineering patterns (policy-as-code, evidence automation)
- Data handling and lightweight analytics for security
- Building repeatable, small tools and documenting the process
