Noor Shehub
I build and run the compliance programs that let cloud platforms sell into regulated markets — federal, financial services, and healthcare. Twelve years of turning control frameworks into something engineering teams can actually operate.
Compliance that holds up under audit
I'm a GRC and cloud security leader with 12+ years building and running compliance programs across multi-cloud environments — AWS, Azure, and GCP.
My work is hands-on: leading SOC 2 Type II, ISO 27001, FedRAMP, PCI DSS, HITRUST, and IRAP engagements with external auditors and assessors from planning all the way through certification. Authoring the security policies and standards underneath them. Fielding the customer security assessments and due-diligence reviews that gate enterprise deals. Supporting privacy obligations under GDPR and CCPA, and reviewing security and data-protection contract terms alongside Legal.
Right now I lead compliance for an enterprise AI/analytics platform, with growing involvement in AI governance and the controls needed to develop and deploy machine learning systems responsibly.
Programs I've built and run
Multi-year compliance programs, federal authorizations, and the internal tooling that keeps them moving. Select any card for the full case study.
Twelve years, one direction
Help desk to security analyst to federal assessor to cloud compliance lead. Every step added a layer to how I think about controls.
Twelve certifications, four disciplines
Security leadership, audit, cloud, and offensive/defensive practice — plus the degrees underneath them.
Notes from inside the program
Field notes on federal authorization, CMMC scoping, and what AI governance actually looks like when you have to enforce it.
Let's talk compliance
Whether you're heading into a first FedRAMP package, scoping CMMC, or trying to get five audit programs onto one evidence base — I'm happy to compare notes.