Security GRC Engineer focused on building and scaling compliance automation programs. I design systems that leverage consolidated control frameworks, build automations for any use case, automate evidence collection, and integrate AI into security operations.
- Security GRC Engineering
- Security Control Inventory (Frontend)
- AI-Compliance-Agent
- AWS Cloud Resume
- Security Control Inventory (Full-Stack)
- Risk & Control Matrix
- AWS Serverless Web Application
- Vulnerability Scanner
- API Data Display With Search
- Controls Assessment - Google Apps Script
- Review and Approvals - Google Apps Script
Architecture and implementation details for building a mature enterprise GRC program — control frameworks, maturity assessments, evidence automation, and third-party risk management.
Client-side security controls app with local storage using HTML, Bootstrap, JavaScript, and CSS. Live demo.
An AI-powered AWS compliance auditor that scans IAM, S3, and EC2, then reasons about each finding with Claude (via Amazon Bedrock tool use), mapping it to CIS v8 / NIST 800-53 / SOC 2 controls and scoring its contextual risk. A deterministic, auditable policy then routes each finding by escalating critical ones to GitHub Issues with masked identifiers, and acknowledging the rest. It runs locally as a CLI and as a hardened, scheduled CronJob on Kubernetes, exposing run metrics to Prometheus/Grafana.
Python-based Risk & Control Matrix application with multiple views and backend endpoint routing.
Python-based web vulnerability scanner with Flask server for HTTP/network traffic analysis.
Full-stack serverless resume hosted on AWS: S3 (static hosting), CloudFront (CDN), Route 53 (DNS), ACM (SSL), Lambda (Python API), DynamoDB (visitor counter). Managed with Terraform and GitHub Actions CI/CD.
Live at miguelhorta.com
CRUD web app for managing security controls — DynamoDB backend, Lambda functions, API Gateway, deployed at app.miguelhorta.com.
Express-based Node.js API server for CRUD operations on security controls. Backend handles API requests with CORS and JSON body parsing middleware.
Python script to fetch, parse, and search data from API endpoints.
Google Apps Script automation for assessment management — consolidates responses from multiple tabs into a summary database.
Google Apps Script for review and approval workflows — approval tracking, file organization, and URL generation.





