GRC-Focused Cybersecurity Professional · Northern Virginia / DC
I spent four years learning how to make complex ideas land for audiences who don't share your vocabulary. In GRC, that's not a soft skill — it's the job.
Let's ConnectAbout
I spent four years in art school teaching myself to make complex ideas land with people who don't share your vocabulary. Turns out, that's exactly what cybersecurity needs.
The moment I knew this field was it: I was designing the visual identity for my dad's cybersecurity training initiative — logos, mascots, the whole brand. To do the work right, I had to understand what I was designing for — red teams, blue teams, purple teaming. So I read everything. And somewhere in that research, something clicked. The skill I had spent four years building — translating technical complexity into something a non-expert can feel, not just understand — is the core skill of GRC. I wasn't changing directions. I was pointing my existing skills at a new problem.
I'm now a Cybersecurity Intern at Tysons Institute, working through their SOC Tier I Certificate program and getting real exposure to security operations every day. I hold my Google Cybersecurity Certificate and I'm actively studying for CompTIA Security+, targeting July 2026. I write a blog called Cyber Nerd Surf on Medium, where I document what I'm learning each week — because explaining something in writing is the best test I know for whether I actually understand it.
I'm a tactile learner. My favorite study moment so far was physically dissecting a Dell Optiplex — pulling out every component and touching the hardware I'd only ever seen in textbook diagrams. That's how I learn: hands in it.
My target role is GRC Analyst in the Northern Virginia / DC area. If you're building a team that needs someone who can translate technical risk into language executives and auditors can act on — let's talk.
Skills & Certifications
I organize my skills honestly — distinguished by what I'm actively using, actively studying, and what I have foundational knowledge of. No overclaiming.
Certifications
Security & GRC
Transferable Skills
Tools & Platforms
Blog
I document what I'm learning each week — in writing, because that's how I find out whether I actually understand it. Published on Medium.
Published on Medium · Weekly
@ApurvaCyberSec
Security operations, GRC concepts, learning in public — from someone a few steps behind you (or ahead).
Contact
I'm open to GRC Analyst roles and conversations in the Northern Virginia / DC area — hybrid or remote. If you're building a team that needs someone who can make technical risk make sense, I want to hear about it.
Actively looking · Open to hybrid and remote · Targeting full-time GRC Analyst role as Security+ completes (July 2026)