Lilith R
Los Angeles, United States
Lilith R
GRC Analyst | Cybersecurity Professional
Category : Cybersecurity
I am Lilith, a cybersecurity professional specializing in Governance, Risk, and Compliance (GRC). I help small to medium businesses strengthen their security posture, prepare for audits, and build practical compliance programs that actually work.
What I do:
Security Control Assessments: I review your current IT environment against NIST CSF, ISO 27001, and SOC 2 frameworks. I deliver a gap analysis, risk register, and prioritized remediation roadmap so you know exactly where you stand and what to fix first.
GRC Policy Development: I write clear, enforceable security policies tailored to your business: access control, data retention, incident response, change management, acceptable use, and business continuity. These are ready for compliance audits and built from real operational experience—not templates.
Virtual CISO (vCISO) Services: I act as your part-time security leader. Monthly strategy calls, risk register management, policy maintenance, compliance guidance, vendor security reviews, and incident response support. You get executive-level expertise without the full-time cost.
Why work with me:
I bring 5+ years of hands-on infrastructure experience on different types of companies (from smaller businesses to international ones) plus pentesting certifications that let me see security from both sides defender and attacker. I don't just check boxes. I help you build programs that reduce real risk and keep your business moving.
Timeline & investment depends on scope. Hourly, project-based, and monthly retainers available. Let's talk about what you need.
What I do:
Security Control Assessments: I review your current IT environment against NIST CSF, ISO 27001, and SOC 2 frameworks. I deliver a gap analysis, risk register, and prioritized remediation roadmap so you know exactly where you stand and what to fix first.
GRC Policy Development: I write clear, enforceable security policies tailored to your business: access control, data retention, incident response, change management, acceptable use, and business continuity. These are ready for compliance audits and built from real operational experience—not templates.
Virtual CISO (vCISO) Services: I act as your part-time security leader. Monthly strategy calls, risk register management, policy maintenance, compliance guidance, vendor security reviews, and incident response support. You get executive-level expertise without the full-time cost.
Why work with me:
I bring 5+ years of hands-on infrastructure experience on different types of companies (from smaller businesses to international ones) plus pentesting certifications that let me see security from both sides defender and attacker. I don't just check boxes. I help you build programs that reduce real risk and keep your business moving.
Timeline & investment depends on scope. Hourly, project-based, and monthly retainers available. Let's talk about what you need.
Working hours
- Monday:08h00 To 18h00
- Tuesday:08h00 To 18h00
- Wednesday:08h00 To 18h00
- Thursday:08h00 To 18h00
- Friday:08h00 To 18h00
- Saturday:Not available
- Sunday:Not available
- I act as your part-time Chief Information Security Officer—providing strategic guidance, risk oversight, and compliance management without the cost of a full-time executive. You retain full control; I ...
- I write or update your information security policies to meet compliance requirements (ISO 27001, SOC 2, GDPR, HIPAA) and establish clear governance for your organization. My policies are built from ...
- I conduct a comprehensive review of your current IT security controls against established frameworks (NIST CSF, ISO 27001, SOC 2) and deliver a clear, actionable report that tells you exactly where ...
- Provide Tier 1–2 IT support to business clients across the world, reporting, troubleshooting and resolving advanced
technical issues for a SaaS product with a resolution of 100% of issues under SLA.
- Manage customer inquiries, plan and schedule operations for resolutions that require an on-site technician
technical issues for a SaaS product with a resolution of 100% of issues under SLA.
- Manage customer inquiries, plan and schedule operations for resolutions that require an on-site technician
- Managed identity and access controls for 60+ users across 20+ clients, provisioning accounts per security requirements.
- Maintained IT asset documentation supporting internal controls and audit trails.
- Resolved 90% of tickets independently using an independent ticketing system.
- Maintained IT asset documentation supporting internal controls and audit trails.
- Resolved 90% of tickets independently using an independent ticketing system.
- Administered secure VPN access for 100+ users, enforcing authentication policies.
- Achieved 95%+ SLA compliance through systematic tracking in Jira.
- Documented issue resolutions contributing to knowledge base for consistent control application.
- Achieved 95%+ SLA compliance through systematic tracking in Jira.
- Documented issue resolutions contributing to knowledge base for consistent control application.
- Implemented security controls across 50+ workstations and 30+ servers, reducing vulnerabilities 40% through patch management.
- Partnered with cybersecurity teams to support control implementation during AWS migration.
- Participated in change management, documenting infrastructure updates and assessing security impact.
- Maintained asset inventories and configuration baselines supporting audit readiness.
- Automated provisioning with Terraform/Ansible, saving 20+ hours/month.
- Partnered with cybersecurity teams to support control implementation during AWS migration.
- Participated in change management, documenting infrastructure updates and assessing security impact.
- Maintained asset inventories and configuration baselines supporting audit readiness.
- Automated provisioning with Terraform/Ansible, saving 20+ hours/month.
- AWS Cloud Practitioner 02/05/2025
![AWS Cloud Practitioner]()
- Certified Red Team Lead 05/10/2023
![Certified Red Team Lead]()
- Practical Network Penetration Tester (PNPT) 14/05/2023
![Practical Network Penetration Tester (PNPT)]()
- Certified Red Team Lead 10/05/2023
![Certified Red Team Lead]()
- 🇬🇧 English
- 🇫🇷 French
Please sign in as a customer to give your feedback


