About risk.engineer
A public learning publication and working laboratory by Ahmed Mohamed.
GRC establishes the practice. GRC engineering makes parts of that work executable. Risk engineering explores how those capabilities can support the risk lifecycle as systems and business context change.
Read the thinking, run the labs, and challenge the conclusions. The first lab focuses on identification—not scoring, treatment, or automated risk acceptance.
Experiments remain experiments. Evidence, assumptions, and limitations should be visible alongside every result.
About Ahmed Mohamed
I’m a senior GRC practitioner with nearly eight years of experience across enterprise and high-growth environments. My background spans IT, information security, cloud compliance, enterprise risk management, third-party risk, and GRC program delivery.
I’ve worked on ServiceNow IRM implementations, risk intake and assessment workflows, control monitoring, and AI-assisted evidence review. A recurring part of that work is translating technical findings into something business owners and executives can use.
My experience includes building enterprise risk operating models, leading risk and compliance work, coordinating SOC 2 readiness, and connecting TPRM with procurement. I’ve assessed more than 300 SaaS, cloud, and professional-services vendors, working with evidence ranging from SOC 2 reports to architecture documentation.
That work crosses organizational boundaries: engineering, security, legal, procurement, and business leadership. The goal is not just a completed assessment, but a process people can use and decisions they understand.
That practical experience shapes risk.engineer: build the pipeline, make the reasoning visible, and explain why the result matters. I hold the Certified in Risk and Information Systems Control (CRISC) certification.
-
Ahmed Mohamed Exploring GRC engineering and the risk lifecycle through writing, executable labs and evidence-backed experiments.