Skip to content
View workmcg's full-sized avatar

Block or report workmcg

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
workmcg/README.md

Hi, I'm Mukul 👋

Cybersecurity GRC & Information Security Risk — I turn complex security findings into business-risk decisions leadership can act on.

Currently at EY, working on portfolio security compliance: risk-backlog remediation, real-time risk dashboards, and compliance-workflow automation. Background spans GRC, DFIR, and digital forensics across EY, a DFIR engineering team, and KPMG.

I'm especially interested in where regulation meets operations — ISO 27001, NIST CSF, NIS2, DORA, GDPR — and in building AI-powered tools that make compliance programmes actually run, not just pass an audit.


🔧 What I work with

GRC · ISO/IEC 27001 · NIST CSF 2.0 · NIS2 · DORA · GDPR · COBIT · PCI-DSS
Risk Management · Incident Response · MITRE ATT&CK · Digital Forensics
Python · Bash · Power Automate · Microsoft 365 · OpenAI API · Streamlit


📌 Pinned projects

  • grc-gap-ai — AI-powered compliance gap analyzer: upload a policy document, get a structured gap report mapped to ISO 27001, NIST CSF 2.0, NIS2, or DORA. Built with GPT-4o + Streamlit.
  • ir-playbook-gen — AI-powered IR playbook generator: specify incident type, sector, and framework → get a complete incident response playbook in markdown with containment steps, forensic checklists, and NIS2/DORA notification timelines.
  • control-crosswalk — dependency-free Python CLI that maps controls across ISO 27001:2022, NIST CSF 2.0, and NIS2, with coverage gap analysis and audit-ready CSV export.
  • risk-register-ai — AI risk register: paste audit findings, get a scored, framework-mapped register with inherent/residual scoring and audit-ready export. Streamlit + GPT-4o. Live demo
  • nis2-readiness-checker — dependency-free NIS2 readiness assessment CLI: answer questions mapped to Articles 20, 21(2) and 23, get a scored report and a prioritised remediation backlog.

📜 Certifications

GRCP (OCEG) · In progress: ISO/IEC 27001 Lead Auditor

🎓 Education

M.Sc. Digital Forensics & Information Security — National Forensic Sciences University
B.Sc. Computer Science — University of Delhi


📫 Reach me

LinkedIn · work.mukul.chauhan@gmail.com

Open to GRC / IT risk / information security roles, including opportunities across Europe.

Pinned Loading

  1. control-crosswalkcontrol-crosswalkPublic

    A dependency-free Python CLI that maps controls across ISO 27001:2022, NIST CSF 2.0 and NIS2, with coverage gap analysis and audit-ready CSV export.

    Python

  2. grc-gap-aigrc-gap-aiPublic

    AI-powered GRC gap analysis — paste a policy doc, get a structured gap report mapped to ISO 27001, NIST CSF 2.0, or NIS2

    Python

  3. ir-playbook-genir-playbook-genPublic

    AI-powered IR Playbook Generator -- incident type + sector + framework -> structured markdown playbook

    Python

  4. risk-register-airisk-register-aiPublic

    AI-powered risk register - turn audit findings into scored, framework-mapped risk entries. Streamlit + GPT-4o, ISO 27005 5x5 scoring.

    Python