Ashley Pearce

Co-Founder

Wesley Chapel, Florida, United States10 yrs 4 mos experience
Most Likely To Switch

Key Highlights

  • Expert in modernizing risk management frameworks.
  • Founder of innovative GRC learning platform.
  • Strong background in compliance automation and DevSecOps.
Stackforce AI infers this person is a Cybersecurity and Compliance Automation expert with a focus on GRC Engineering.

Contact

Skills

Core Skills

Risk Management FrameworkContinuous Authorization

Other Skills

NISTNIST 800-53Ongoing AuthorizationPython (Programming Language)AutomationDevSecOps SecurityAutomation in ComplianceCompliance-as-CodePolicy-as-CodeGRC EngineeringProduct ManagementAgileAdministrationHiringJavaScript

About

Most people think RMF is slow, painful, and buried under a mountain of paperwork. I see it differently. To me, RMF is a living system, one that can evolve, automate, and actually help teams ship secure software faster instead of slowing them down. I work at the intersection of GRC, engineering, and automation, helping organizations modernize how they approach risk management and continuous authorization (cATO). My focus is on translating security and compliance requirements into scalable, engineering-friendly practices that integrate directly into modern DevSecOps environments. Over the past several years I’ve helped organizations: • Modernize RMF implementations • Embed NIST 800-53 and SSDF controls directly into CI/CD pipelines • Implement Policy-as-Code and Compliance-as-Code practices • Enable Continuous Authorization (cATO) for faster, safer delivery My philosophy is simple: explain everything like you're five, but make it technical enough to matter. That means translating GRC into things engineers actually understand, automation, pipelines, controls-as-code, and security practices that live inside delivery instead of blocking it. I currently hold CompTIA Security+ and an active Top Secret clearance, and I spend a lot of time exploring how governance and security evolve alongside modern software development. I’m also building GRC Playground (grcplayground.com) — a hands-on learning platform designed to turn traditional compliance analysts into GRC Engineers. Instead of memorizing frameworks, practitioners learn by building, breaking, and automating real controls in sandbox environments. Alongside the platform, I’m building a companion app and workbook to help practitioners experiment with automation, RMF implementation, and modern governance workflows. I regularly write about: • GRC Engineering • RMF modernization • Continuous ATO (cATO) • Compliance automation • DevSecOps security Usually in plain English. Occasionally with a little sarcasm. If you're working on modernizing security governance or making compliance work with engineering instead of against it, we’ll probably get along.

Experience

Grc playground

Founder | GRC Playground

Jun 2025Present · 9 mos

  • Building a hands-on learning platform designed to help the next generation of GRC Engineers learn by doing.
  • The platform focuses on practical labs that teach:
  • RMF implementation
  • Security control validation
  • Compliance automation
  • Policy-as-Code
  • DevSecOps security integration
  • Also developing a companion application and workbook that allow practitioners to experiment with governance workflows and automation in realistic environments.

Rise8

Senior InfoSec Analyst - Top Secret Clearance

Dec 2023Present · 2 yrs 3 mos · Remote

  • Lead governance modernization initiatives supporting cloud-native software delivery environments
  • Translate NIST 800-53 Rev.5 and NIST SSDF requirements into scalable controls embedded directly in CI/CD pipelines
  • Drive adoption of Policy-as-Code and Compliance-as-Code to automate evidence collection and reduce audit burden
  • Integrate security tooling including GitLab, ArgoCD, Trivy, SonarQube, Vault, OWASP ZAP, Cosign, and SD Elements
  • Advise leadership and Authorizing Officials on Continuous Authorization (cATO) strategies
  • Build governance frameworks aligning security requirements with agile development practices
  • Mentor analysts and engineers on RMF modernization and compliance automation
NISTRisk management frameworkNIST 800-53Ongoing AuthorizationContinuous AuthorizationRisk Management Framework

Amazon

3P Security Specialist

Aug 2022Dec 2023 · 1 yr 4 mos

  • Analyze security posture to determine risk for 3rd party vendors looking to work directly with Amazon
  • Provide risk analysis reports and findings after completing a full risk analysis assessment
  • Create findings from risk assessments and help the 3rd party develop remediation and mitigation plans by implementing compensating controls
  • Determine compliance with ISO27001 standards and issue findings accordingly
  • Work with vendors to remediate findings and develop solutions to create compensating controls when necessary

Pepsico

Security Exceptions Specialist

Oct 2021Aug 2022 · 10 mos · United States

  • Review security exceptions on daily basis
  • Follow up with requestors for more information
  • Work with requestors to create mitigating controls and develop remediation plan
  • Evaluate risk and develop standards to manage it
  • Analyze the impact to the PepsiCo network and company by understanding the risk associated
  • with each exception

Sev1tech llc

Cyber Security Analyst and Governance, Risk and Compliance Subject Matter Expert

Aug 2019Oct 2021 · 2 yrs 2 mos

  • Update security controls and support stakeholders on security controls covering internal
  • assessments, regulations, and protecting Personally Identifying Information (PII) and classified
  • data
  • Implement security controls and risk assessment frameworks that align to NIST standards and
  • regulatory requirements, ensuring documented and sustainable compliance for classified and
  • unclassified systems.
  • Perform risk assessments and execute tests of data processing system to ensure functioning of
  • data processing activities and security measures.
  • Evaluate risks and develop security standards, procedures, and controls to manage risks.
  • Document and report control failures and gaps to stakeholders.
  • Provide remediation guidance and prepare management reports to track remediation activities.
  • Train staff on processes and procedures.
  • Plan & engineer the requirements for future network architecture & migration
  • Experienced with DoD Risk Management Framework (RMF) Authority to Operate (ATO) process
  • and eMASS workflow.
  • Utilized eMASS for comprehensive management of security controls, risk assessments, and compliance documentation.
  • Configured eMASS to align with RMF (Risk Management Framework) requirements and organizational security policies.
  • Developed and maintained security control baselines, ensuring accurate implementation and documentation in eMASS.
  • Managed Continuous Integration/Continuous Delivery (CI/CD) pipelines and automated security assessments through eMASS.
NISTRisk management frameworkNIST 800-53Risk Management Framework

Uicgs / bowhead family of companies

Data Migration Technician and Tier 1-2 Help Desk Tech

Mar 2019Aug 2019 · 5 mos · Dahlgren, VA

  • Migrated/backed-up data to comply with disaster recovery policies.
  • Developed an audit process to track and monitor status of over 200 systems with recurring
  • backup requirements.
  • Created and implemented a new system of issuing loaner laptops and reimaging upon return.
  • Tier 1 and 2 helpdesk experience with desktop support.
  • Configuration Control Board meeting coordinator and asset manager.
NISTRisk management frameworkNIST 800-53Risk Management Framework

New horizons computer learning centers

Full Time Student

Nov 2018Mar 2019 · 4 mos · Greater Richmond Region

  • Completed CompTIA technical training for IT Fundamentals, including: A+, Network+, Security+,
  • Cisco Networking (CCENT), Certified Ethical Hacker (CEH), CompTIA Advanced Security
  • Practitioner (CASP).
  • Intense training in lab environments, including actual networking simulations and training.

United states air force

USAF Cyber Services Technician

Jan 2014Nov 2017 · 3 yrs 10 mos

  • Sharepoint administrator
  • Assisted users in resolving Tier 1 and Tier 2 desktop issues.
  • Developed continuous innovation plan to drive workplace efficiency and productivity.
  • Awarded the Presidential Volunteer Service Award

Education

Coursera

Google IT Automation with Python

Feb 2026Jun 2026

Full Sail University

Visual Arts Bachelor of Science — Graphic Design

Jul 2024Oct 2025

The Product School

Product Management

Apr 2025Apr 2025

Coursera

Google UX Design

Jul 2021Dec 2021

Stackforce found 38 more professionals with Risk Management Framework & Continuous Authorization

Explore similar profiles based on matching skills and experience