BRAD EGLOFF
Lewisville, NC ***** 540-***-**** **********@*******.***
COMPLIANCE PROGRAM LEADER SOC 2 • ISO 27001 • CMMC SAAS/CLOUD AI-ENABLED GRC
PROFESSIONAL SUMMARY
Compliance and information security leader with 25+ years of experience, including building and scaling compliance and audit-readiness programs from the ground up for SaaS, cloud, healthcare, and financial services organizations. Owns the full compliance lifecycle scoping, gap assessment, control documentation, third-party assessor management, and continuous monitoring across SOC 1/SOC 2, ISO 27001, CMMC, NIST CSF, and HIPAA/GLBA. Regularly operates cross-functionally with Engineering, Product, Legal, and Sales to drive certification outcomes without slowing the business, and serves as the authoritative internal voice on security and compliance posture for customer due diligence, RFPs, and enterprise sales cycles. Recruits, mentors, and leads compliance and GRC teams, and has directed the selection and oversight of third-party assessors and advisory firms across dozens of client engagements. Actively applies AI-enabled tooling to improve evidence automation, gap analysis, and continuous monitoring efficiency.
CORE COMPLIANCE & LEADERSHIP SKILLS
Compliance Program Strategy & Road mapping SOC 1 & SOC 2 ISO 27001 / 27701 CMMC Level 2 NIST CSF & AI RMF ISO 42001 (AI Governance) Gap Assessments & Maturity Baselines Third-Party Assessor & Advisory Firm Management Audit Readiness & Evidence Automation Continuous Controls Monitoring Customer Security Reviews, RFPs & Due Diligence Cross-Functional Influence (Engineering, Product, Legal, Sales) Team Building, Hiring & Mentoring AI-Enabled GRC Tooling GRC Platforms (OneTrust)
PROFESSIONAL EXPERIENCE
Compliance Consultant / Advisor / GRC / vCISO Risk Compliant Solutions, Remote 7/2018 – Present
Builds and scales compliance programs from the ground up for SaaS, technology, and enterprise clients, including iCIMS, AAA, Abira Security, Grant Thornton, Truist, Thermo Fisher Scientific, Sage Bionetworks, and ABM, spanning strategy, certification sequencing, and day-to-day program execution.
●Build the business case and roadmap for compliance investments, sequencing certifications (SOC 2, ISO 27001, CMMC) against client market and regulatory expansion goals, and presenting ROI and prioritization to executive leadership.
●Lead gap assessments and compliance readiness evaluations across SOC 2, ISO 27001, DORA, CMMC, NIST CSF, and HIPAA, producing maturity baselines and prioritized remediation roadmaps for engineering and security teams.
●Select, onboard, and manage third-party assessors, C3PAOs, and compliance advisory partners across concurrent client engagements, holding partners accountable to timelines and escalating risk early.
●Design, build, and implement the OSCAL (Key Security Indicators/KSI) framework to support FedRAMP compliance automation for federal government clients
●Drive audit readiness end-to-end, coordinating evidence collection, continuous monitoring, and audit documentation with engineering and security teams through successful certification.
●Serve as the authoritative voice on client compliance posture in customer security reviews, RFP/RFI responses, and due diligence conversations supporting enterprise sales cycles.
●Advise and mentor TPRM and GRC professionals, shaping team structure, vendor tiering frameworks, and program metrics as client compliance functions scale.
●Apply AI and automation tooling to streamline evidence collection, gap analysis, and continuous control monitoring, reducing manual audit-prep effort across engagements.
●Collaborate directly with engineering and DevOps teams to embed compliance controls into CI/CD pipelines (GitHub Actions) rather than bolting them on post-development.
Chief Information Security Officer (CISO) Lumeris Healthcare Solutions, St. Louis, MO 10/2017 – 7/2018
Recruited to build and lead the security and compliance function for a health plan technology organization, managing a team of 8 analysts and engineers.
●Set the strategic roadmap for the security and compliance program, prioritizing initiatives and timelines in partnership with Compliance, Privacy, and Technology leadership.
●Served as the primary internal authority on security and compliance posture for customer and prospect due diligence, leading RFP, RFQ, and RFI responses that directly supported enterprise sales.
●Owned regulatory reporting and audit-readiness documentation for CMS and state regulators, maintaining evidence and driving continuous compliance maturity.
●Recruited, developed, and led a security team, building internal capability while managing external vendor and assessor relationships, including contract negotiation.
Head of IT Compliance (2LOD) Citizens Financial Group, Providence, RI 6/2015 – 10/2017
●Drove compliance outcomes across Technology, Security, and Business Unit stakeholders as advisor to executive management, bridging first- and third-line-of-defense functions without slowing regulatory-exam timelines.
●Owned continuous monitoring and audit readiness for SOC 1, SOC 2, GLBA, NYDFS 23 NYCRR 500, and PCI requirements across the CFG enterprise, including the annual FFIEC CAT process.
●Selected and managed vendor risk platforms and third-party assessments (OneTrust) to identify and monitor supplier compliance risk.
Senior Privacy Officer (2LOD) Citizens Financial Group, Providence, RI 6/2015 – 6/2016
●Drove the annual GLBA risk assessment program end-to-end, including data integrity, board/committee reporting, and cross-functional milestone management.
●Served as subject matter expert on SOC 1, SOC 2, and Safeguards Rule compliance at the enterprise level, advising business units directly and shaping remediation plans.
Compliance Advisor / Manager KPMG, Charlotte, NC 6/2014 – 6/2015
Led client engagements addressing security, privacy, and compliance risks, managing teams of up to 60 across vendors, contractors, and employees.
●Served as engagement lead for security audit reviews, building sustainable gap-remediation frameworks, and reducing repeat findings year over year.
●Crafted compliance and risk responses to RFI, RFQ, and RFP submissions for clients across financial services, healthcare, and government sectors.
ADDITIONAL EXPERIENCE
15+ years supporting compliance, security, and audit-readiness programs (NIST 800-53/171, DFARS, ITAR, CMMC) for Aerospace & Defense primes Lockheed Martin, Northrop Grumman, Boeing, General Dynamics, and federal/intelligence customers including CIA, DIA, NRO, FBI, DoD, CMS, and HHS (11/2001–3/2023).
EDUCATION & CERTIFICATIONS
Master of Public Administration (MPA) City University of Seattle
Bachelor of Arts, Criminal Justice, North Carolina Wesleyan College
CISSP/CISM MITRE ATT&CK Modules 1–5 Project Management Institute