Samantha Mueller
Remote · Available now
Open to GRC & compliance roles
Samantha Mueller
Governance, Risk & Compliance
Security Policy Author
Compliance Documentation & Audit Support
Technical Writer, Regulated Industries
What I bring on day one
Policy & procedure writingScope, roles, enforcement, review cadence
Documentation built for auditWritten to survive review
Several requirements at onceWithout contradicting any of them
Technical made readableFor people who aren't technical
Third-party oversightVerify, collect, monitor, stay accountable
Detail discipline at scaleA $12M+ portfolio doesn't forgive sloppy records
Compliance areas
01Data privacy & security
02Business continuity & disaster recovery
03Acceptable AI use & AI governance
04Anti-malware & endpoint policy
05Risk management
06Incident response
07Access controls
08Data classification & retention
09Backup & recovery
10Federal, state & local grant standards
11Civil rights & affirmative action compliance
12Third-party & subrecipient oversight
Self-directed policy library
Anti-Malware PolicyIS-POL-005 · Weyland-Yutani
Data Privacy PolicyIS-POL-011 · Weyland-Yutani
Business Continuity & DRInGen
Acceptable AI Use & GovernanceCyberdyne
FrameworksNIST CSF 2.0 primary · ISO 27001 & PCI DSS applied, depth developing
In progressISC2 CC · Cybersecurity diploma, Nicolet College
The value
A control nobody reads
is a control nobody follows.
Most compliance documentation is technically correct and almost impossible to get through. Closing that gap is a writing problem, and it's the one I'm good at. Ten years of writing under federal, state, and local requirements, now aimed at security.