PROFILE
Terry Afram-Kumi

Terry Afram-Kumi

CISA · PMP · MSc · AI Security & Governance (Securiti)
Security Engineering · Cybersecurity · AI Security Engineering · GRC Engineering · IT Audit · AI Governance

I engineer, secure and audit technology and AI systems — combining cybersecurity engineering, AI security, GRC engineering, IT audit and governance to build controls that are practical, measurable and accountable.

VIEW PROJECTS ↘

Selected engineering, security and governance work

SECURITY ENGINEERING

Security Engineering

Engineering security controls and applications across identity, access, cloud infrastructure, threat prevention, monitoring, automation and secure AI systems.

View on GitHub ↗
AI SECURITY & GOVERNANCE

AI Security & Governance

AI GRC application with incident workflows based on the OpenAI Misalignment Reporting Framework, mapped to NIST AI RMF, NIST CSF and ISO/IEC 42001.

View on GitHub ↗
IT AUDIT & GRC

IT Audit & GRC

Control design, testing and documentation across IT, technology risk and cybersecurity engagements.

View on GitHub ↗
HIPAA RISK ASSESSMENT

HIPAA Risk Assessment Application

Python-based privacy and security risk assessment application supporting assessments against the HIPAA Security Rule.

View on GitHub ↗
CYBER THREAT PREVENTION

Cyber Threat Prevention Applications

Security engineering applications supporting threat identification, prevention, detection, investigation, response and remediation.

View on GitHub ↗
AI SECURITY APPLICATIONS

AI Security Applications

Applications that automate regulatory compliance and risk engineering workflows to support secure and accountable AI systems.

View on GitHub ↗
OWASP & MITRE ATT&CK

OWASP & MITRE ATT&CK GRC

GRC application capabilities for documenting security risks, threats, controls and attack techniques using OWASP and MITRE ATT&CK concepts.

View on GitHub ↗

Security Engineering

Engineering security controls, identity and access, least privilege, monitoring, threat prevention and secure infrastructure.

AI Security Engineering

Designing applications and controls for AI security, AI risk, incident management, governance and secure AI deployment.

Cybersecurity

Threat prevention, detection, investigation, response, remediation and security monitoring.

GRC Engineering

Turning governance, regulatory and security requirements into practical applications, workflows and measurable controls.

IT Audit & Technology Risk

IT controls, control design, testing, evidence, risk assessment and audit documentation.

Python & Automation

Python applications and automation supporting cybersecurity, AI security, risk and governance workflows.

Cloud & Infrastructure Security

Cloud security controls, IAM governance, infrastructure security and secure deployment.

Linux & Bash

Linux administration, command-line security workflows, scripting and infrastructure troubleshooting.

Security Engineering AI Security Engineering GRC Engineering IT Audit AI Governance NIST AI RMF NIST CSF ISO/IEC 42001 OWASP MITRE ATT&CK HIPAA Cloud Security IAM Python Linux & Bash

I approach cybersecurity and AI security as a closed loop: preventive controls reduce risk first, while detection, investigation, response and remediation feed lessons learned back into the preventive control layer.

01 Prevention — least privilege, permissions, guardrails and monitoring
02 Detection — identify security and AI-related events
03 Triage & Investigation — determine scope, severity and impact
04 Response — escalation, reporting and remediation
05 Lessons Learned — improve monitoring and preventive controls

Let's connect.

For opportunities involving Security Engineering, Cybersecurity, AI Security Engineering, AI Governance, IT Audit, Technology Risk or GRC Engineering.