Open to Opportunities

Lazaro Denis

GRC Analyst & Cybersecurity Professional

Cyber insurance underwriting background meets hands-on governance, risk, and compliance — bridging risk quantification with real security outcomes.

Portfolio

All Projects

Hands-on labs and tools spanning GRC, vulnerability management, automation, and threat intelligence.

📋

Vendor/Supplier Qualification Questionnaire

Interactive, self-scoring 40-question VSQ covering Labor, Forced Labor (UFLPA), Environmental, Quality, Cybersecurity, and Ethics. Auto-scores and returns Approved / Conditional / Declined with action items.

TPRM UFLPA Risk Scoring HTML/JS
⚙️

TPRM Automation Toolkit

4 Python scripts automating the full TPRM lifecycle — inherent risk scoring, NIST CSF 2.0 gap analysis, ISO 27001 control gap detection, and vendor POA&M tracking with color-coded HTML dashboards.

Python NIST CSF ISO 27001 Automation
🛡️

Tenable Vulnerability Management Lab

End-to-end vulnerability management on Azure Windows 10 VM — baseline, post-misconfiguration, and post-remediation scan cycles with STIG tables and PowerShell remediation scripts.

Tenable Nessus Azure STIG PowerShell
🗺️

MITRE ATT&CK Threat Mapping

Custom ATT&CK maps built from real-world threat intelligence scenarios, visualizing adversary tactics, techniques, and procedures for incident analysis.

MITRE ATT&CK Threat Intel Mermaid
🤖

Auto Application Script

Automation tool for streamlining LinkedIn and Indeed job applications, reducing manual effort in the application process.

Automation Python LinkedIn
Expertise

Skills & Frameworks

Core competencies across GRC, security operations, and cloud platforms.

DomainTools & Frameworks
GRC FrameworksNIST CSF 2.0 · ISO 27001:2022 · NIST RMF · SOC 2
Risk ManagementTPRM · Vendor Risk · Risk Register · POA&M
Incident ResponseIR Planning · Tabletop Exercises · ISO 27035 · MITRE ATT&CK
CompliancePCI DSS · HIPAA · CIS Controls · GDPR
SIEM / DetectionMicrosoft Sentinel · KQL · Defender XDR
Vuln ManagementTenable Nessus · Qualys VMDR
CloudMicrosoft Azure · Entra ID
ScriptingPowerShell · Python
Credentials

Certifications

Industry-recognized certifications validating security and compliance expertise.

🔴

CompTIA Security+

Earned

🔵

Microsoft SC-200

Earned

🟣

NIST RMF

Earned

🟢

Google Cybersecurity

Earned

🟠

Qualys VMDR & PCI

Earned

🟡

CISA (ISACA)

In Progress

Get in Touch

Let's Connect

Open to GRC Analyst, TPRM, and cybersecurity compliance roles. Based in Denver, CO.