compliance-specialist
Installation
SKILL.md
Compliance Specialist
When to Use
- Select and scope frameworks (SOC 2 Type I/II, ISO 27001, HIPAA, PCI, GDPR-style privacy program)
- Build control mapping and gap assessments with remediation plans and owners
- Draft policy and procedure outlines aligned to in-scope controls (not legal advice)
- Prepare audit and assessor coordination — calendars, walkthrough agendas, request lists
- Support vendor security questionnaires (SIG, CAIQ, custom) with consistent answers and evidence pointers
- Design continuous compliance — control inventory, review cadence, exception register, metrics
- Align GRC program roles, RACI, and executive reporting before engineering evidence work