Alexandria F. Seven, CISSP

Senior Information Security & GRC Professional

Senior Governance, Risk & Compliance (GRC) professional with 15+ years building and maturing enterprise compliance programs across financial services, healthcare, technology, and regulated cloud environments. I specialize in taking organizations from fragmented, undocumented processes to audit-ready, defensible operations — owning SOC 2, ISO 27001, NIST, and HITRUST readiness end to end, from control design and policy authorship through evidence collection and auditor coordination.

I bring program-level judgment — knowing which framework, control, or platform fits a given organization, and the discipline to mature a compliance function without losing sight of the business it serves. I have built GRC functions as a founding member and strengthened existing ones as an outside advisor, most recently through my own consulting practice, A3INFOSEC.

I am also the publisher of GRC PROS Blog, a GRC publication reaching more than 500,000 practitioners since 2023 with practical guidance on governance, audit readiness, and compliance automation.

I welcome connections with fellow GRC, security, and compliance professionals, as well as organizations building or strengthening their governance functions.

Core Expertise

Key Focus Areas

Alexandria's work spans critical domains, ensuring robust security frameworks that align with business objectives and regulatory demands.

Security Governance

Risk & Assurance

Audit Readiness

Establishing clear security expectations, ownership, oversight, and decision-making across complex organizations.

Evaluating business, technology, vendor, and control risk using structured and defensible methods.

Improving control operation, evidence quality, issue management, and coordination before formal audits.

Advanced GRC Capabilities

Extending beyond foundational security, Alexandria addresses complex challenges in vendor ecosystems, GRC tooling, and the evolving landscape of modern technology.

Third-Party Risk

GRC Technology

Cloud & Emerging Technology

Assessing vendor security, assurance documentation, dependencies, and ongoing risk exposure.

Supporting platforms and workflows that improve control management, evidence collection, issue tracking, and reporting.

Applying governance to cloud environments, AI systems, software supply chains, and rapidly changing technology operations.

Professional Outlook

Practical Security Governance

Strong information security depends on more than policies and audit preparation. It requires clear accountability, practical controls, reliable evidence, sound risk decisions, and consistent collaboration between business and technology teams.