Skip to content
View garynair's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report garynair

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
garynair/README.md

Hi, I'm Girish (Gary) Nair

Senior Manager leading Cyber GRC, AI governance, TPRM, SecOps, IAM and program management across banking and financial services, insurance, healthcare, SaaS, manufacturing, federal government and technology consulting, with a focus on Responsible AI and compliance automation.

Flagship: Vendor Tierline

vendor-tierline · Live demo (one-click read-only login)

Engagement-level third-party risk tiering. A weighted questionnaire scores each vendor engagement, a reviewer confirms or overrides the computed tier with a recorded reason, and tier-specific due diligence follows. Includes an Insights dashboard (tier mix, pipeline, override audit trail, follow-up aging) and org-scoped row-level security. Designed around NIST CSF 2.0 GV.SC and ISO/IEC 27001:2022 A.5.19 to A.5.22. Next.js, Supabase, Vercel.

Vendor Tierline insights dashboard

More builds

Project What it shows
ai-risk-triage Turns an AI use-case intake form into an auditable risk-register entry: an LLM drafts the analysis and deterministic rules apply EU AI Act tiers, NIST AI RMF and ISO/IEC 42001 Annex A, followed by human-in-the-loop review
grc-case-studies Team-based GRC exercises with task sheets, capstones and answer keys, starting with a five-week simulation of the 2014 JPMorgan Chase breach
windows-log-analysis A local Windows event-log monitoring stack (Grafana Alloy → Loki → Grafana on WSL/Docker) with an optional AI digest through Python or n8n

What I build

  • GRC applications that turn a governance process into a working system with human review and an audit trail, e.g. vendor-tierline
  • Governance workflows that separate deterministic control rules from model judgment and keep a human approval step
  • Data and analytics agents with read-only data access, e.g. data-analyst-agent (n8n, Supabase Postgres, Gemini) and eCom-data-agent (four-agent pipeline with a deployment approval gate)
  • Security monitoring stacks that run locally on Docker and summarize events for review
  • Training material that turns frameworks into exercises teams can practice on

Governance domains

Cyber GRC · AI governance (NIST AI RMF, ISO/IEC 42001, EU AI Act) · Third-party risk management · Identity governance (IAM) and control assurance · SOX/ITGC · Audit-ready evidence and executive reporting

GRC Atlas: reference libraries

Curated, practitioner-oriented guides to the frameworks behind this work, with primary sources and starter templates.

Also: finserv-compliance · insurance-compliance · healthcare-compliance · federal-compliance · privacy · cloud-security · IR-BC-DR · vapt

Credentials and contact

PMP · CompTIA Security+ · Certified ScrumMaster · SAFe Advanced Scrum Master. See more on Credly.

In progress: CISSP · ISO/IEC 42001

LinkedIn

Pinned Loading

  1. vendor-tierline vendor-tierline Public

    Engagement-level third-party risk tiering with reviewer override and tier-based follow-up questionnaires. Next.js + Supabase.

    TypeScript

  2. ai-risk-triage ai-risk-triage Public

    An n8n workflow that turns an AI use-case intake form into a risk-triaged, auditable register entry in Notion — LLM draft + deterministic governance rules (EU AI Act tiers, NIST AI RMF, ISO/IEC 420…

    JavaScript

  3. windows-log-analysis windows-log-analysis Public

    Windows event log stack: Grafana Alloy → Loki → Grafana on WSL/Docker, with an optional AI digest via Python or n8n.

    Python

  4. ai-governance ai-governance Public

    A curated, deduplicated list of AI governance resources — regulation, standards, and runtime controls for autonomous agents

    HTML 1

  5. it-audit-controls it-audit-controls Public

    A curated list of COBIT, COSO, and ITGC/ITAC — standards, implementation guidance, and tooling for IT and SOX audits

    HTML

  6. grc-case-studies grc-case-studies Public

    Open, team-based GRC case studies with task sheets, capstones and answer keys. Starting with the 2014 JPMorgan Chase breach.