Terry Afram-Kumi
I engineer, secure and audit technology and AI systems — combining cybersecurity engineering, AI security, GRC engineering, IT audit and governance to build controls that are practical, measurable and accountable.
VIEW PROJECTS ↘Selected engineering, security and governance work
Security Engineering
Engineering security controls and applications across identity, access, cloud infrastructure, threat prevention, monitoring, automation and secure AI systems.
View on GitHub ↗AI Security & Governance
AI GRC application with incident workflows based on the OpenAI Misalignment Reporting Framework, mapped to NIST AI RMF, NIST CSF and ISO/IEC 42001.
View on GitHub ↗IT Audit & GRC
Control design, testing and documentation across IT, technology risk and cybersecurity engagements.
View on GitHub ↗HIPAA Risk Assessment Application
Python-based privacy and security risk assessment application supporting assessments against the HIPAA Security Rule.
View on GitHub ↗Cyber Threat Prevention Applications
Security engineering applications supporting threat identification, prevention, detection, investigation, response and remediation.
View on GitHub ↗AI Security Applications
Applications that automate regulatory compliance and risk engineering workflows to support secure and accountable AI systems.
View on GitHub ↗OWASP & MITRE ATT&CK GRC
GRC application capabilities for documenting security risks, threats, controls and attack techniques using OWASP and MITRE ATT&CK concepts.
View on GitHub ↗Security Engineering
Engineering security controls, identity and access, least privilege, monitoring, threat prevention and secure infrastructure.
AI Security Engineering
Designing applications and controls for AI security, AI risk, incident management, governance and secure AI deployment.
Cybersecurity
Threat prevention, detection, investigation, response, remediation and security monitoring.
GRC Engineering
Turning governance, regulatory and security requirements into practical applications, workflows and measurable controls.
IT Audit & Technology Risk
IT controls, control design, testing, evidence, risk assessment and audit documentation.
Python & Automation
Python applications and automation supporting cybersecurity, AI security, risk and governance workflows.
Cloud & Infrastructure Security
Cloud security controls, IAM governance, infrastructure security and secure deployment.
Linux & Bash
Linux administration, command-line security workflows, scripting and infrastructure troubleshooting.
I approach cybersecurity and AI security as a closed loop: preventive controls reduce risk first, while detection, investigation, response and remediation feed lessons learned back into the preventive control layer.
Let's connect.
For opportunities involving Security Engineering, Cybersecurity, AI Security Engineering, AI Governance, IT Audit, Technology Risk or GRC Engineering.