open to information security & GRC roles

I turn security risk into decisions people can act on.

Ryan Guendjoian — Information Security & GRC analyst, CompTIA Security+ (SY0-701) certified. I run risk assessments, evaluate controls, and translate technical findings into remediation plans that stakeholders can actually execute.

01 / CAPABILITIES

Where I spend my time

Risk Assessment & Treatment

Structured internal risk assessments and security control evaluations that surface real gaps, prioritized into remediation plans stakeholders can execute.

Risk Assessment Remediation GRC

Framework Alignment

Mapping controls and evidence to ISO 27001, SOC 2, and PCI DSS concepts, keeping compliance monitoring grounded in what the framework actually requires.

ISO 27001 SOC 2 PCI DSS

Technical Control Validation

Hands-on validation of technical and administrative controls with Nessus, OpenVAS, Nmap, Wireshark, and Burp Suite to confirm posture matches policy.

Nessus Burp Suite Nmap

Security Reporting & Stakeholder Comms

Security questionnaires, audit support, and reporting that translates technical findings into business-relevant impact for technical and executive audiences.

Reporting Audits Stakeholder Comms
02 / SELECTED WORK

Five shipped systems, solo end to end

Auth / 2FA

Access — Firebase phone-based two-factor verification

rethy11.github.io/phone-verif

Integrated Firebase Phone Auth for a genuine, server-verified SMS one-time-passcode second factor, gated by a capture-phase allowlist check and reCAPTCHA-backed request validation. Identified and documented the trust boundary between client-enforced checks and server-verified auth, then defined the remediation path to close it.

Server-verified 2nd factor
Diagnostics

Load-Watt — browser performance & power diagnostics tool

rethy11.github.io/Load-Watt

Sandboxes and instruments untrusted code inside an isolated same-origin frame, using Performance Observer APIs to quantify long tasks, main-thread load, and dropped frames. Pulls repo data via the GitHub REST API with clear rate-limit handling, and cut a production app's measured resource consumption roughly 20x.

~20x lower resource use
Puzzle Generator

Owldoku — constraint-satisfaction puzzle generator

owldoku.com

Queens-style puzzle game shipped solo from domain registration through Terms of Service authorship and ad-network integration. Its "No Lines" mode layers a diagonal-exclusivity rule on top of standard placement constraints, validated through backtracking search over millions of candidate boards. Shared puzzles arrive as user-controlled URL codes, parsed through a dedicated validator and never trusted directly.

Millions of boards validated
Game Engine

Slime Sliders — ~12,000-line game engine

rethy11.github.io/Slime-Sliders

Canvas rendering, custom physics, and procedural level generation. Spatial hash grids handle collision detection at near-constant time, currency and state writes are batched to avoid frame stalls, and a token-based crossfading audio state machine prevents race conditions between overlapping transitions.

~12k lines, solo-built
Utility

Slopless — minimal, privacy-conscious search redirector

rethy11.github.io/Slopless

No analytics, telemetry, or third-party data collection anywhere in the code — the privacy stance is enforced by what's (and isn't) there. Detects iOS Safari versus the Chrome app to launch queries directly into Chrome, with screen-reader-visible labels and a fully keyboard-submittable form.

Zero analytics/telemetry
5 shipped projects, solo end to end
03 / CONTACT

Let's talk risk

Risk assessments, control validation, or a second set of eyes on your compliance posture — send a note and I'll reply within a day.