I've spent my career working across external audit, enterprise internal audit, technology controls, cybersecurity risk, and GRC technology: evaluating how controls are designed, testing whether they actually work, and translating technical or regulatory requirements into something teams can realistically operate day to day.

Working in external audit gave me my foundation in controls, evidence, testing, documentation, and audit methodology. I worked across client environments and industries, evaluating technology controls, reviewing evidence, identifying gaps, communicating findings, and seeing firsthand what organizations need to demonstrate when an independent auditor is examining their environment.
I then moved inside a large global enterprise and saw the other side of the audit relationship. My work covered IT audit, IT general controls, cybersecurity, technology risk, and security-focused areas of the organization. That meant understanding not only whether a control could pass a test, but how it operated within real systems, teams, processes, ownership structures, and competing business priorities.
Working with a GRC software company gave me another perspective: what happens after an organization decides it needs a formal GRC program and has to make the technology support the work. I saw how teams use platforms day to day, where implementations become unnecessarily complicated, and the gap between a technically capable platform and a program people can realistically maintain.
Nomixa Global brings those perspectives together into independent advisory work. I work directly with organizations on the problems that sit between audit expectations, security requirements, business operations, and the reality of actually maintaining a program, and, through the partnership with Voreli AI, on adopting AI in a way that will pass the next audit.
That progression has given me a practical view of the entire lifecycle. I understand what an external auditor is looking for, how an internal audit team evaluates risk, how controls have to operate inside the business, how evidence and documentation hold up under review, how teams interact with GRC technology, and where theoretically sound programs start to break down in day-to-day operations.
I created Nomixa Global because I wanted a way to work directly with organizations on the problems that do not always fit neatly into a job description, an audit request list, or a software implementation.
Across external audit, internal audit, cybersecurity, controls, and GRC technology, I kept seeing versions of the same problem. Knowing what a framework, auditor, customer, or regulator expects is one thing. Turning those expectations into clear ownership, workable controls, useful documentation, reliable evidence, and processes people can actually maintain is much harder.
That is the kind of work I want Nomixa to help with. Sometimes that means preparing for an audit. Sometimes it means untangling a control environment, assessing risk, improving an existing GRC program, helping a team make better use of its technology, or bringing an experienced outside perspective to a problem that has become difficult to solve internally.
It's demanding, occasionally humbling, and about as far from a laptop as I can get, which is exactly the point.
I'm available for consulting projects, advisory engagements, fractional support, and situations where a team simply needs additional expertise or capacity.