Ashley Pearce — Co-Founder
Most people think RMF is slow, painful, and buried under a mountain of paperwork. I see it differently. To me, RMF is a living system, one that can evolve, automate, and actually help teams ship secure software faster instead of slowing them down. I work at the intersection of GRC, engineering, and automation, helping organizations modernize how they approach risk management and continuous authorization (cATO). My focus is on translating security and compliance requirements into scalable, engineering-friendly practices that integrate directly into modern DevSecOps environments. Over the past several years I’ve helped organizations: • Modernize RMF implementations • Embed NIST 800-53 and SSDF controls directly into CI/CD pipelines • Implement Policy-as-Code and Compliance-as-Code practices • Enable Continuous Authorization (cATO) for faster, safer delivery My philosophy is simple: explain everything like you're five, but make it technical enough to matter. That means translating GRC into things engineers actually understand, automation, pipelines, controls-as-code, and security practices that live inside delivery instead of blocking it. I currently hold CompTIA Security+ and an active Top Secret clearance, and I spend a lot of time exploring how governance and security evolve alongside modern software development. I’m also building GRC Playground (grcplayground.com) — a hands-on learning platform designed to turn traditional compliance analysts into GRC Engineers. Instead of memorizing frameworks, practitioners learn by building, breaking, and automating real controls in sandbox environments. Alongside the platform, I’m building a companion app and workbook to help practitioners experiment with automation, RMF implementation, and modern governance workflows. I regularly write about: • GRC Engineering • RMF modernization • Continuous ATO (cATO) • Compliance automation • DevSecOps security Usually in plain English. Occasionally with a little sarcasm. If you're working on modernizing security governance or making compliance work with engineering instead of against it, we’ll probably get along.
Stackforce AI infers this person is a Cybersecurity and Compliance Automation expert with a focus on GRC Engineering.
Location: Wesley Chapel, Florida, United States
Experience: 10 yrs 4 mos
Skills
- Risk Management Framework
- Continuous Authorization
Career Highlights
- Expert in modernizing risk management frameworks.
- Founder of innovative GRC learning platform.
- Strong background in compliance automation and DevSecOps.
Work Experience
GRC Playground
Founder | GRC Playground (9 mos)
Rise8
Senior InfoSec Analyst - Top Secret Clearance (2 yrs 3 mos)
Amazon
3P Security Specialist (1 yr 4 mos)
PepsiCo
Security Exceptions Specialist (10 mos)
Sev1Tech LLC
Cyber Security Analyst and Governance, Risk and Compliance Subject Matter Expert (2 yrs 2 mos)
UICGS / Bowhead Family of Companies
Data Migration Technician and Tier 1-2 Help Desk Tech (5 mos)
New Horizons Computer Learning Centers
Full Time Student (4 mos)
United States Air Force
USAF Cyber Services Technician (3 yrs 10 mos)
Education
Google IT Automation with Python at Coursera
Visual Arts Bachelor of Science at Full Sail University
Product Management at The Product School
Google UX Design at Coursera