Professional Timeline

Security Experience Across Complex Environments

Alexandria’s career spans financial services, healthcare, SaaS, and cloud infrastructure. Her work centers on evaluating risk, strengthening controls, improving security governance, and helping teams operate effectively within complex regulatory environments.

Clean modern dashboard showing security compliance metrics, soft blue and teal interface, shallow depth of field, professional lighting
Clean modern dashboard showing security compliance metrics, soft blue and teal interface, shallow depth of field, professional lighting
a computer screen with a cloud shaped object on top of it
a computer screen with a cloud shaped object on top of it
Active Engagements

Recent Leadership

2022 – Present

A3INFOSEC

**Security GRC Consultant.** Leading practical security and GRC initiatives across vendor risk, compliance readiness, and AI governance. Conducts third-party risk assessments and supports structured vendor intake. Leads SOC 2 readiness activities and control evaluations. Develops operational governance approaches for AI systems and control automation.

2019 – 2022

Enterprise Client Engagements

**Senior Security Professional & GRC Engineer.** Supporting enterprise security governance, cloud assurance, control management, and audit readiness. Configured ServiceNow IRM workflows for policies, controls, and evidence reporting. Mapped and rationalized over 1,000 security controls. Reviewed system security plans and cloud controls supporting NIST 800-53.

woman in white button up shirt and blue stethoscope
woman in white button up shirt and blue stethoscope
white and red wooden house miniature on brown table
white and red wooden house miniature on brown table
Established Governance

Enterprise Impact

2017 – 2019

Blue Shield of California

**IT Security Policy Lead.** Managing enterprise security policy governance and connecting security requirements with operational processes. Managed the lifecycle of security policies, standards, and control baselines. Built ServiceNow workflows supporting policy approvals and exceptions. Coordinated security governance across Security, Privacy, Legal, and Audit teams.

2016 – 2017

Move Inc. / Realtor.com

**GRC Principal.** Integrating security governance into cloud engineering, product development, and post-acquisition technology operations. Supported post-acquisition security integration and consistent data-protection expectations. Partnered with engineering teams to incorporate security controls into AWS workflows. Performed threat modeling and security evaluations for cloud changes.

city buildings during night time
city buildings during night time
stock market chart displayed on laptop screen
stock market chart displayed on laptop screen
Foundational Years

Security Assurance

2013 – 2016

Fintech Client Engagements

**Security Risk & Compliance Consultant.** Evaluating security risk across financial technology, infrastructure, software development, and regulated payment environments. Conducted risk assessments for software releases and vendor technologies. Performed post-acquisition security gap analysis. Reviewed technical controls and vulnerability findings with technology teams.

2008 – 2013

E*TRADE Financial

**Security Assurance Specialist.** Building an early foundation in security assurance, vendor risk, identity governance, and financial-services security. Conducted high-volume vendor security reviews using regulatory criteria. Managed access provisioning and recertification across banking applications. Developed internal tools that improved access reviews and audit preparation.

Versatility

Proven Across Sectors

Finance

Financial Services

Health

Healthcare Systems

Cloud

SaaS & Infrastructure

Regs

Complex Environments