Alexandria F. Seven, CISSP
Senior Information Security & GRC Professional
Senior Governance, Risk & Compliance (GRC) professional with 15+ years building and maturing enterprise compliance programs across financial services, healthcare, technology, and regulated cloud environments. I specialize in taking organizations from fragmented, undocumented processes to audit-ready, defensible operations — owning SOC 2, ISO 27001, NIST, and HITRUST readiness end to end, from control design and policy authorship through evidence collection and auditor coordination.
I bring program-level judgment — knowing which framework, control, or platform fits a given organization, and the discipline to mature a compliance function without losing sight of the business it serves. I have built GRC functions as a founding member and strengthened existing ones as an outside advisor, most recently through my own consulting practice, A3INFOSEC.
I am also the publisher of GRC PROS Blog, a GRC publication reaching more than 500,000 practitioners since 2023 with practical guidance on governance, audit readiness, and compliance automation.
I welcome connections with fellow GRC, security, and compliance professionals, as well as organizations building or strengthening their governance functions.
Core Expertise
Key Focus Areas
Alexandria's work spans critical domains, ensuring robust security frameworks that align with business objectives and regulatory demands.
Security Governance
Risk & Assurance
Audit Readiness
Establishing clear security expectations, ownership, oversight, and decision-making across complex organizations.
Evaluating business, technology, vendor, and control risk using structured and defensible methods.
Improving control operation, evidence quality, issue management, and coordination before formal audits.
Advanced GRC Capabilities
Extending beyond foundational security, Alexandria addresses complex challenges in vendor ecosystems, GRC tooling, and the evolving landscape of modern technology.
Third-Party Risk
GRC Technology
Cloud & Emerging Technology
Assessing vendor security, assurance documentation, dependencies, and ongoing risk exposure.
Supporting platforms and workflows that improve control management, evidence collection, issue tracking, and reporting.
Applying governance to cloud environments, AI systems, software supply chains, and rapidly changing technology operations.
Professional Outlook
Practical Security Governance
Strong information security depends on more than policies and audit preparation. It requires clear accountability, practical controls, reliable evidence, sound risk decisions, and consistent collaboration between business and technology teams.
