GRC Engineer · Compliance Automation · Lansing, MI
Hey, I'm Zahid Kamil.
I automate my way out of manual compliance work. For the last 3+ years I've administered and modernized a SaaS GRC platform for the State of Michigan — mapping NIST 800‑53 controls, wiring up API integrations, and replacing "stare-and-compare" review with Python and Playwright. I also teach AWS and Python part-time, because explaining things out loud is the fastest way to find the gaps in your own understanding.
What I actually do
Most "GRC" work is still spreadsheets, screenshots, and manual cross-checking. I build the automation that makes that toil unnecessary: Python scripts that pull evidence and sync CMDB/audit data through APIs, crosswalks that map NIST 800‑53 controls to CJIS, IRS 1075, PCI, and ARC-AMPE, and validation tooling that verifies a platform migration actually moved every table, field, and workflow correctly — instead of trusting a human to eyeball it.
Skills
Featured projects
View all →ComplyZombie — Multi-Cloud Compliance Scanner
A serverless AWS compliance scanner with a live React dashboard, mapping real findings across SOC 2, ISO 27001, NIST CSF, PCI-DSS, and HIPAA.
GitHub Actions Job Scout
A Python + Claude-powered job search agent that runs weekly on GitHub Actions for free and emails a curated shortlist.
GRC Platform Migration Validator
A Python/Playwright + Flask tool that verifies tables, fields, workflows, and rules migrated correctly between GRC platform instances.
Currently
Working toward the Certified GRC Engineer – Practitioner (CGE‑P), and extending a Flask migration-validation tool with retrieval-augmented (RAG) querying so teammates can just ask "what didn't migrate?" instead of digging through logs.