Internal Audit & Certification Program

In April 2025, took over as Compliance Program Manager and Internal Auditor for Protos Labs' ISO/IEC 27001 program — certified October 2024 — and carried it through two live surveillance audit cycles while expanding it into a second framework.

Role
Compliance Program Manager & Internal Auditor
Scope
Company-wide — ISO/IEC 27001:2022, expanded to SOC 2
Certification
Achieved Oct 2024 · maintained through 1st & 2nd surveillance audits
External interface
Main point of contact for audit consultants & external auditors, both cycles

Surveillance audit leadership

Led preparation for Protos Labs' 1st and 2nd ISO/IEC 27001 surveillance audits — policy and procedure maintenance, regular reviews with management, and ongoing monitoring, sustained without a lapse in certification.

Register & inventory management

Owned asset, access, and software registers on an ongoing basis — the evidence base auditors draw from, kept current rather than reconstructed under deadline.

Control testing via simulation

Designed and ran tabletop exercises testing resiliency against ransomware and data-loss scenarios — testing incident response controls that don't leave a natural evidence trail to sample.

Access governance

Ran access control reviews across company-wide software and critical infrastructure, including GitHub, Confluence, and Entra ID/Intune.

Framework expansion — SOC 2

Mapped existing ISO 27001 controls to SOC 2 criteria, identified gaps in controls, policies, and procedures, and closed them — extending the program from one framework to two.

GRC tooling migration

Led the migration from manual tracking to an automated GRC platform, consolidating records across both frameworks and multiple source systems into one operating picture.

Security-aligned IAM & offboarding

Owned onboarding/offboarding identity access management; rebuilt the offboarding checklist to match ISO 27001 and SOC 2 requirements, implemented background checks — closing a notable SOC 2 gap — and built evidence-collection forms for equipment returns.

Training & awareness

Ran company-wide security training and awareness programs as part of the certification's ongoing operating requirements.

Certification sustained across two live surveillance audits, with zero major or minor non-conformities, while scope doubled from one framework to two.

Carried Protos Labs' ISO/IEC 27001 certification through a full audit cycle under new ownership, then extended the program into SOC 2 and consolidated it onto a single automated platform — without a gap in coverage or a lapse in certification status.

Certification continuity through leadership transition Live audit management, two surveillance cycles Framework expansion (ISO 27001 → SOC 2) GRC tooling migration & consolidation Security-aligned HR/IAM operations