Hunter Glass

Cybersecurity professional · Lenexa, KS

GRC control assessment, plus hands-on identity and application security.

Bridging GRC control assessment with hands-on identity and application security. 12+ client environments audited against ISO 27001, SOC 2, and TISAX with a 100% audit pass rate, including two implementations recommended for ISO 27001 certification. On the side, working hands-on with identity and application security patterns on a tool that tracks the NCAA transfer portal.

Experience

CBIZ Technology

Cybersecurity Consultant

June 2024 – Present

  • Led security control assessments across 12+ client environments against ISO 27001, ISO 27701, SOC 2 Type II, and TISAX, with 100% client audit pass rate, and all implementations recommended for ISO 27001 certification.
  • Reviewed access control, change management, SDLC, and configuration management processes to surface drift between documented policy and operational reality, remediating gaps with IT and DevOps throughout the process.
  • Built audit-ready evidence packages and led clients through control implementation ahead of ISO 27001, SOC 2, and TISAX certification assessments.
  • Authored 40+ security policies and procedures spanning access management, change management, incident response, and SDLC, each tailored to the specific client environment with defined control ownership.

CBIZ Technology

Intern, IT / Internal Audit

Jan 2024 – Jun 2024

  • Evaluated cybersecurity and IT general controls against FDICIA and SOX requirements.
  • Authored audit findings reports prioritizing the highest-risk control weaknesses for client remediation.

Projects & early experience

PortalVision

Personal project

2025 – Present

portalvision.io

  • Built out the identity, access control, and application security architecture end to end.
  • Designed the authentication and authorization layer on Auth0 with JWT-based session handling and database-backed role claims driving every authorization decision.
  • Enforced role-based access control across all API endpoints with tiered separation of admin, authenticated user, and public routes.
  • Shipped the privileged admin console for user and organization lifecycle management, isolating administrative actions behind elevated role checks via the Auth0 Management API.
  • Hardened the production deployment with CORS policy, bearer-token enforcement on all API calls, environment-scoped secrets management, and multi-stage container builds.

University of Kansas

MeshMapper — Master’s Research Project

May – Dec 2023

  • Implemented BLE link-layer encryption via custom ESP32 firmware, defeating sniffing and man-in-the-middle attacks across Bluetooth Mesh topologies.
  • Built the GIS-based auto-provisioning layer on Google Cloud and the Google Maps API to deploy encrypted mesh nodes across a mapped region.

Satcom Direct

Information Security / Software Engineering Intern

Summer 2020, 2021

  • Prototyped an OWASP Dependency-Track integration for the CI/CD pipeline to surface vulnerable third-party components in the software supply chain.
  • Contributed backend and frontend enhancements to a SaaS flight-planning platform used by corporate and private aviation customers.

Education

  • M.S., Computer Science — University of Kansas, Dec 2023
  • B.S., Computer Science — University of Kansas, May 2022

Certifications

  • CompTIA Security+, Oct 2025
  • ISO/IEC 27001 Implementer, Jan 2025
  • ISACA member

Technical skills

Security Domains

Vulnerability Management, Identity & Access Management, Application Security, Cloud Security, GRC.

Control Frameworks

ISO 27001, ISO 27701, ISO 27017, SOC 2 Type II, TISAX, NIST CSF, FDICIA, SOX.

Identity & Access

OAuth 2.0 / OIDC, JWT, Auth0, Spring Security, Role-Based Access Control (RBAC).

Tools & Platforms

Google Cloud Platform, Docker, PostgreSQL, Git, Render.

Programming

Python, Java, SQL, JavaScript / ReactJS, Bash, C, C++.