Portrait of Spencer Sheehan

Hi, I’m Spencer. I build

GRC systems like an engineer.

I’m an IAM security engineer (1st line of defense) who came up through audit (3rd line of defense) and GRC (2nd line of defense) - a unique intersection of audit depth and hands-on engineering. I can run an audit end to end, then write the code that makes the next cycle smaller or unnecessary.

I build homegrown automation, infrastructure-as-code, and continuous controls that keep systems secure while respecting engineering’s need for speed and quality. I’m equally comfortable below the abstraction layer and across the table from an auditor.

MY JOURNEY ACROSS FOUR LINES OF DEFENSE

01

Build & operate

2025–Present
IAM & Infrastructure Security, Instacart

02

Govern & challenge

2020–2025
Salesforce GRC → Instacart GRC

03

Internal assurance

2017–2020
Salesforce Security Assurance → Stitch Fix IT SOX

04

External audit

2015–2017
PwC Risk Assurance

Slayer of audit fatigue.

Slayer of audit fatigue.

Four UARs made unnecessary

Four UARs made unnecessary

Replaced Instacart’s four largest User Access Reviews with JIT access and time-bound entitlements. The automated control enforces least privilege continuously instead of merely streamlining a review.

A week of reconciliation to an hour

A week of reconciliation to an hour

Built a script reconciling ConductorOne logs against Okta, alongside evidence automation spanning around 200,000 GitHub pull requests and more than 30 systems.

Continuous cloud assurance

Continuous cloud assurance

Built Terraformed Datadog entitlement monitors, preventative IaC controls, and AWS IAM attack-path tooling with observable guardrails; locked down the highest-risk roles using AWS trust policies.

Engineering credibility in the auditor room

Engineering credibility in the auditor room

Led major certifications, drafted assurance reports, mapped technical controls across frameworks, and regularly defends innovative automated controls directly to auditors.

POINT OF VIEW

Automate execution, not only evidence collection

Automate execution, not only evidence collection

The best control enforces itself. JIT access is the model: least privilege happens continuously, and audit evidence becomes a byproduct rather than a scramble.

The best control enforces itself. JIT access is the model: least privilege happens continuously, and audit evidence becomes a byproduct rather than a scramble.

Build and buy, deliberately

Build and buy, deliberately

Use a focused third-party interface where it helps, but keep critical logic in owned Terraform and code so the system stays adaptable and avoids unnecessary lock-in.

Use a focused third-party interface where it helps, but keep critical logic in owned Terraform and code so the system stays adaptable and avoids unnecessary lock-in.

AI in GRC needs guardrails

AI in GRC needs guardrails

LLMs can help risk-rank reviews and analyze evidence, but generated code must be rigorously tested before it touches a control or high-stakes workflow.

LLMs can help risk-rank reviews and analyze evidence, but generated code must be rigorously tested before it touches a control or high-stakes workflow.

Continuous assurance over compliance theater

Continuous assurance over compliance theater

Prefer observable controls, drift detection, and ongoing risk signals over point-in-time screenshots that prove a process happened once.

Prefer observable controls, drift detection, and ongoing risk signals over point-in-time screenshots that prove a process happened once.

EXPERIENCE

I've been both the auditor requesting evidence, and the engineer automating it away.

I've been both the auditor requesting evidence, and the engineer automating it away.

03/2025 — Present

Los Angeles

Senior Engineer II, Infrastructure Security

Senior Engineer II, Infrastructure Security

Instacart

Instacart

First-line infrastructure security engineering focused on IAM and cloud controls. Built JIT access and 90-day maximum entitlements across AWS, Stripe, and high-risk platforms, removing four major UARs without slowing operations. Authors Python, Terraform, and YAML mapped to Workday data; operates ConductorOne workflows backed by in-house Terraform; wrote a ConductorOne-to-Okta reconciliation that reduced a week-long task to about an hour; uses OPA for policy checks; deploys Wiz-driven Lambda remediation and Terraformed Datadog monitoring; patched an AWS Terraform provider to resolve drift; and defends the resulting controls to auditors.

First-line infrastructure security engineering focused on IAM and cloud controls. Built JIT access and 90-day maximum entitlements across AWS, Stripe, and high-risk platforms, removing four major UARs without slowing operations. Authors Python, Terraform, and YAML mapped to Workday data; operates ConductorOne workflows backed by in-house Terraform; wrote a ConductorOne-to-Okta reconciliation that reduced a week-long task to about an hour; uses OPA for policy checks; deploys Wiz-driven Lambda remediation and Terraformed Datadog monitoring; patched an AWS Terraform provider to resolve drift; and defends the resulting controls to auditors.

04/2021 — 03/2025

Los Angeles

Senior Engineer II, Risk and Compliance

Senior Engineer II, Risk and Compliance

Instacart

Instacart

Built reusable, audit-defensible control architecture across applications and infrastructure during Instacart’s transition from private to public. Drove IT SOX, SOC 2, ISO 27001, HIPAA, and security compliance mapping across roughly 30 systems; automated evidence for around 200,000 GitHub pull requests; and consolidated secrets reviews. Helped grow compliance engineering from two to seven and established entity models, requirements, and runbooks.

Built reusable, audit-defensible control architecture across applications and infrastructure during Instacart’s transition from private to public. Drove IT SOX, SOC 2, ISO 27001, HIPAA, and security compliance mapping across roughly 30 systems; automated evidence for around 200,000 GitHub pull requests; and consolidated secrets reviews. Helped grow compliance engineering from two to seven and established entity models, requirements, and runbooks.

05/2020 — 04/2021

San Francisco

Manager, Security Governance, Risk & Compliance

Manager, Security Governance, Risk & Compliance

Salesforce

Salesforce

Led SOC 1, SOC 2, PCI, and ISO 27001/27017/27018 certifications across five audit firms, published assurance reports, mentored GRC staff, and standardized controls to reduce engineering workload.

Led SOC 1, SOC 2, PCI, and ISO 27001/27017/27018 certifications across five audit firms, published assurance reports, mentored GRC staff, and standardized controls to reduce engineering workload.

03/2019 — 05/2020

San Francisco

Manager, Technology / IT SOX

Manager, Technology / IT SOX

Stitch Fix

Stitch Fix

Oversaw IT audits for more than 80 systems in a cloud-first environment, remediated a significant change-management deficiency, documented compensating controls, and reported outcomes to executive leadership.

Oversaw IT audits for more than 80 systems in a cloud-first environment, remediated a significant change-management deficiency, documented compensating controls, and reported outcomes to executive leadership.

06/2017 — 03/2019

San Francisco

IT Security Assurance Senior Analyst

IT Security Assurance Senior Analyst

Salesforce

Salesforce

Built self-service evidence tools that saved about 170 engineering hours annually, completed audits for seven SaaS subsidiaries, and reviewed approximately 130 control and interface workpapers.

Built self-service evidence tools that saved about 170 engineering hours annually, completed audits for seven SaaS subsidiaries, and reviewed approximately 130 control and interface workpapers.

08/2015 — 05/2017

San Jose

IT Risk Assurance Associate

IT Risk Assurance Associate

PwC

PwC

Improved testing methods with audit and IT teams, reduced audit budgets by 20%, mentored junior auditors, and strengthened testing across interfaces, key reports, general controls, and automated controls.

Improved testing methods with audit and IT teams, reduced audit budgets by 20%, mentored junior auditors, and strengthened testing across interfaces, key reports, general controls, and automated controls.

ENGINEERING IN PRACTICE

Judge App

Judge App

I built Judge, a continuous access assurance prototype that checks whether sensitive Snowflake role assignments still match business policy. On each evaluation, a deterministic Python engine compares access and employee attributes against role-specific YAML policies—turning a manual access review into a repeatable, explainable check.

I built Judge, a continuous access assurance prototype that checks whether sensitive Snowflake role assignments still match business policy. On each evaluation, a deterministic Python engine compares access and employee attributes against role-specific YAML policies—turning a manual access review into a repeatable, explainable check.

Every check records PASS, FAIL, or ERROR in an append-only DynamoDB audit trail, including the reason and policy version. Unavailable data produces ERROR, never a silent PASS.

Every check records PASS, FAIL, or ERROR in an append-only DynamoDB audit trail, including the reason and policy version. Unavailable data produces ERROR, never a silent PASS.

Python · Streamlit · Snowflake · YAML policies · DynamoDB · Terraform · ECS Fargate + ALB · Secrets Manager

PASSION PROJECT

Outside work, I’m building OnlyCeliacs, a restaurant finder shaped by my own experience with celiac disease and the stress of finding safe places to eat with friends. It is also a deliberate solo-builder experiment in what tools like Claude Code make possible when a personal problem becomes a useful community product.

Founder

Solo builder

CAPABILITIES

Audit depth, infrastructure security, and controls engineered to run continuously.

Audit depth, infrastructure security, and controls engineered to run continuously.

GRC & Assurance

GRC & Assurance

IT SOX · SOC 1 · SOC 2 · ISO 27001 · ISO 27017/27018 · PCI · HIPAA · Audit scoping · Control architecture · Auditor defense

IT SOX · SOC 1 · SOC 2 · ISO 27001 · ISO 27017/27018 · PCI · HIPAA · Audit scoping · Control architecture · Auditor defense

Infrastructure & Control Engineering

Infrastructure & Control Engineering

AWS · Python · Terraform · YAML · GitHub API · Workday · ConductorOne · Open Policy Agent · Datadog · Wiz · Okta · IAM governance · JIT access · Continuous control monitoring · Cloud posture remediation

AWS · Python · Terraform · YAML · GitHub API · Workday · ConductorOne · Open Policy Agent · Datadog · Wiz · Okta · IAM governance · JIT access · Continuous control monitoring · Cloud posture remediation

EDUCATION & CREDENTIALS

The University of Montana

B.S. Management Information Systems & Accounting · 2011–2015

CISA · CPA

Certified Information Security Auditor · 2022 · Certified Public Accountant · 2016, inactive