Aj Handy
Customer Trust & Security Executive | Governance, Risk & Compliance (GRC) | Customer Security Assurance, Due Diligence & Contract Reviews | Third-Party Risk (TPRM) | Enterprise SaaS & Cloud Platforms
- Role
- Senior Director - Customer Trust at Workiva
- Location
- Bozeman, MT, US
- LinkedIn followers
- 500 followers
About Aj Handy
Security & compliance executive with 15+ years building and scaling programs for global SaaS platforms. Proven leader in GRC modernization, complex audits, and embedding compliance into product and engineering. Trusted partner to execs, auditors, and cross-functional teams.I SPECIALIZE IN: SECURITY ENGINEERING: Built scalable compliance architectures for 80+ SaaS services & 65+ global regimes GRC MODERNIZATION: Unified FedRAMP, SOC 2, ISO, HIPAA, PCI, and others into streamlined frameworks AUDIT MANAGEMENT: Directed 100+ audits annually, ensuring readiness, evidence collection, & certification LEADERSHIP: Managed teams up to 27, collaborating cross-functionally with product, engineering, & execs PUBLIC SECTOR: Deep expertise in cloud security & compliance within hyperscaler & federal environmentsCAREER HIGHLIGHTS INCLUDE: Leading compliance and security engineering for 80+ cloud services supporting global SaaS platforms Building and operationalizing a unified control framework covering 65+ compliance regimes worldwide Reducing audit prep and execution times by 30% through automation of evidence collection and workflows Designing an enterprise-wide GRC platform to improve transparency and streamline audit cycles Managing 100+ audits annually, driving readiness, certification success, and cross-team start a conversation: a•••••••@gmail.comEDUCATION Bachelor of Science (BS), United States Naval AcademyMORE ABOUT ME: Corporate career CISSP, CRISC, and PMP certified with 15+ years in security, compliance, and risk leadership Designed and implemented Oracle’ SaaS in-house GRC platform and continuous monitoring solution Developed standardized control frameworks, audit workflows, evidence automation, and vuln mgmt portals Known for building scalable compliance systems and bridging engineering, product, and GRC teamsU.S. Navy officer Former Naval Officer (Information Professional) directing operations and security for classified networks Led global incident response efforts for DoD systems, coordinating with 64+ federal/military agenciesPersonal Based in Montana on a small farm, spending time outdoors and building things by hand Passionate about woodworking, welding, and working on cars — always learning something new
Experience
Senior Director - Customer Trust
Jan 2026 — Present · Bozeman, MT, US
Own the Customer Trust function, encompassing governance, risk management, compliance, third-party risk, and customer-facing security assurance for the Workiva platform- Lead enterprise GRC strategy, including governance structures, risk management, compliance programs, and policy frameworks- Own third-party risk management (TPRM), including vendor due diligence, risk assessments, and lifecycle oversight- Direct customer security assurance, including security questionnaires, audits, contract security reviews, and customer-facing due diligence- Partner with Sales, Legal, Product, and Security to support security reviews, sales cycles, and trust-driven customer outcomes- Serve as executive point of accountability for customer trust signals, regulatory alignment, and security posture transparency
Education
Naval Postgraduate School
Graduate Certificate, Information Systems Operations
2008 — 2009
United States Naval Academy
Bachelor of Science, Information Technology and National Security Affairs
2001 — 2005
Skills
- U.s. Department of Defense
- Soc
- Cloud Security
- Cloud Computing
- Security+
- Information Security
- Program Management
- Network Security
- Nist
- Cyber Security
- Computer Forensics
- Integration
- Regulatory Compliance
- Iaas
- Comptia Security+
- Payment Card Industry Data Security Standard (Pci Dss)
- C&a
- U.s. Federal Information Security Management Act (Fisma)
- Oracle Cloud
- Computer Security
- Paas
- Security Policy
- Nist 800-53
- Vulnerability Assessment
- Grc
- Risk Assessment
- IT Risk Management
- Cissp
- Hitrust
- Governance
- Vulnerability Management
- Defense
- Business Continuity
- Fisma
- Information Technology
- Security Clearance
- Security Audits
- Dod
- IT Audit
- Intrusion Detection
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.