AJ Yawn
Director of GRC Engineering at Aquia
Specialities
Cloud Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
AJ Yawn is currently the Director of GRC Engineering at Aquia, a digital services firm specializing in cloud infrastructure, cybersecurity, and compliance automation. Before joining Aquia, AJ served as the Partner-in-Charge of Product & Innovation at Armanino and was a Founding Board Member of the National Association of Black Compliance and Risk Management Professionals (NABCRMP).
AJ has earned six AWS certifications, including the AWS Solutions Architect – Professional and AWS Security – Specialty. Prior to co-founding ByteChek, AJ spent over a decade in the cybersecurity industry, serving both in the U.S. Army and as a consultant. He is a regular speaker for SANS Cloud Security curriculum events, such as the BIPOC in Cloud Forum and the CloudSecNext Summit, and was a co-chair of the New2Cyber Summit in 2022
AJ speaks on/at information security podcasts and events while also contributing to blogs and articles including publications in CISOMag, InfosecMag, HackerNoon, and ISC2. He holds the following industry certifications:
In his spare time, AJ enjoys golf, watching basketball, and enjoying the beautiful weather and beaches of San Juan.
Speaker / Contributor: This individual participates in SANS events, presentations, written content, or other community resources as an external contributor. They are not a SANS employee, instructor, or affiliate.
Explore content featuring this instructor’s insights and expertise.
The evolving field of Governance, Risk, and Compliance (GRC) is increasingly intersecting with engineering, giving rise to a pivotal discipline known as GRC Engineering. This 45-minute webinar explores this emerging practice, clearly defining GRC Engineering and highlighting its critical role within modern enterprises.

Join SANS Instructors AJ Yawn and Zenable Founder/CEO Jon Zeolla as they introduce the core concepts of GRC Engineering and explore how Policy as Code can bridge the gap between regulatory demands and the flexibility required in cloud-native environments.

In the dynamic realm of cloud security, organizations are in constant pursuit of innovative solutions to shield their cloud environments from the ever-growing array of threats. The SANS CloudSecNext Solutions Summit stands as a pivotal platform that brings to the forefront the latest trends, challenges, and solutions pivotal to cloud security.

The NIST cybersecurity framework (CSF) is a well-known and respected framework for buildingcybersecurity programs. The NIST CSF organizes the framework beginning with functions that organizebasic cybersecurity activities at their highest level. These functions are Identify, Protect, Detect, Respondand Recover. The NIST CSF functions can help cloud organizations express their management ofcybersecurity risk by organizing information, enabling risk management decisions, addressing threats,and improving by learning from previous activities.

Join this SANS Cloud Security Solutions Summit as we explore various cloud security topics through invited speakers while showcasing today's current capabilities. Presentations will focus on technical case studies and thought leadership using specific examples relevant to helping companies improve the security of their cloud environment through automation.

Review relevant educational resources made with contribution from this instructor.