QR
Quentin Roberts
SOC 2 • Security Operations • AI Governance • Automation

IT Leader + Security & Compliance

I build security, compliance, and AI governance programs and run the automation that keeps them alive. Currently leading a SOC 2 audit engagement and governed enterprise AI adoption at Lotlinx, backed by 15+ years of IT leadership across automotive ad tech, offshore oil & gas, and professional services.

SOC 2 Built the program from first pitch; external audit engagement underway
AI Governance Led org-wide adoption of Claude, Cursor, and Gemini with controls built in
Team Leadership Hired and lead IT and security operations teams

About Me

I lead security, compliance, and IT operations at Lotlinx, where I built the security function from the ground up: a SOC 2 program now in external audit, a 20+ policy governance framework, a layered endpoint and cloud security stack, and organization-wide AI adoption with the controls and usage monitoring designed in from day one. Behind that sits 15+ years of owning entire technology estates across automotive ad tech, offshore oil & gas (including an IMO-mandated maritime cyber security plan), and professional services. My pattern is consistent: find the gap, make the business case, design the solution, run the rollout, then automate it so it scales.

Security & Compliance Leadership

Built a SOC 2 program from first internal pitch to external audit engagement: a 20+ policy framework, GRC platform automation, penetration testing, tabletop exercises, and a security team I hired and lead. Vulnerability trends, audit progress, and risk reporting all run through me.

AI Governance & Enablement

Led organization-wide adoption of Claude, Claude Code, Cursor, and Gemini as both the governance owner and a heavy daily practitioner. Wrote the AI policy, built the security controls, spend caps, and usage monitoring, and built the dashboard leadership uses to steer AI investment.

Identity & Automation

Architected the identity platform (SSO, MFA, SAML, OIDC) and lifecycle automation with the HRIS as source of truth, keeping access accurate from onboarding through offboarding across the entire SaaS estate over SCIM.

Featured Projects

Highlighted initiatives spanning SOC 2 compliance, AI governance, security operations, identity, and automation.

SOC 2 Program

Compliance

Directed a ground-up SOC 2 program from first pitch through external audit engagement: policy framework, gap assessments, GRC platform implementation, penetration testing, tabletop exercises, and the auditor relationship. Evidence collection runs on automation, not spreadsheets.

SOC 2 GRC Compliance Automation Audit

AI Governance & Rollout

AI Governance

Wrote the AI acceptable-use policy and led the phased rollout of Gemini, Claude, Claude Code, and Cursor with controls built in from the start: risk assessments, OpenTelemetry usage monitoring, spend caps, and IdP-governed provisioning. Extended governance to MCP servers with an SOP, inventory tooling, and a request intake process.

Claude Code Cursor Gemini AI Policy MCP

AI Usage & Adoption Dashboard

AI Governance

Built the dashboard leadership uses to steer AI investment, covering per-user adoption, usage depth, and spend across Claude, Cursor, and Gemini. Data collection is automated, including a PowerShell exporter written against a vendor analytics API.

Analytics PowerShell BigQuery Reporting

Cloud Security Platform (CNAPP)

Cloud Security

Ran the cloud security platform selection, choosing a CNAPP while retiring native AWS and GCP security tooling. Baselined cloud-native Kubernetes container CVE exposure in production, including VM instances in EC2 and Azure, and stood up malicious-package alerting. Utilized DSPM capabilities and secrets detection.

CNAPP CSPM AWS GCP Vulnerability Management

Security Policy Library

Compliance

Built the company's information security policy framework from zero into a versioned library of 20+ documents, each carried through legal, HR, and executive approval with employee attestation. Every policy is backed by a working control, so the framework holds up under audit.

Policy Governance SOC 2 Risk

Managed Detection & Response

Detection & Response

Led evaluation, procurement, and rollout of an MDR service integrated across the SaaS estate, cloud infrastructure, and every endpoint. Vulnerability counts have trended down since deployment, reported quarterly to leadership.

MDR SIEM SOC 2 Monitoring

Supply Chain Threat Mitigation

Detection & Response

Built and led supply chain threat mitigation across the engineering estate: scripted exposure sweeps of the source control estate, malicious-package alerting, post-event analysis for leadership, and automation that shortens detection and response when upstream threats appear.

Supply Chain Security Incident Response CI/CD Automation

Incident Response & Tabletop Program

Resilience

Established tabletop exercises as standing controls: incident response scenarios with DevOps, legal, compliance, and executives, plus annual business continuity and disaster recovery testing. Designed and ran a company-wide security tabletop at the product and technology summit.

Incident Response BC/DR SOC 2 Training

Built the CCPA and data-subject request process with defined SLAs and automated intake, drove privacy policy and MSA updates with legal, implemented consent management on the website, and managed the Privacy Impact Assessment for the company's Canadian market launch with external privacy counsel.

CCPA CPRA PIPEDA Privacy Consent

Cross-Platform Device Management (UEM)

Endpoint Management

Selected and led UEM/MDM deployments for both Windows and macOS fleets: zero-touch enrollment, policy and script architecture, application whitelisting, local admin removal, and identity-connected login. Closed the MDM gap across both operating systems.

UEM MDM macOS Windows Zero Touch

Identity Platform & SSO

Identity

Architected and deployed the company's identity provider as the foundational security platform, migrating the full SaaS estate to centralized SSO, MFA, SAML, and OIDC, including modifying an internally hosted application to authenticate over OIDC.

IAM SSO MFA SAML OIDC

HRIS as Source of Truth

Automation

Built automated identity management with the HRIS as the source of truth, pushing employee metadata through the identity provider to every connected application over SCIM and SAML, so job changes and terminations propagate without manual work.

SCIM Lifecycle Management HRIS API

User Lifecycle Automation

Automation

Engineered joiner-mover-leaver workflows using APIs, SCIM, webhooks, and a SaaS management platform, consolidating roughly twenty workflows into five with conditional logic. Ten simultaneous onboardings became a routine morning.

Lifecycle Management Automation SCIM Webhooks

EDR Deployment

Endpoint Security

Evaluated competing EDR platforms, selected one, and deployed it silently to the full Windows fleet with zero support tickets, followed by macOS. Detections route to chat and ticketing for triage; the deployment satisfied cyber insurance requirements and SOC 2 endpoint controls.

EDR XDR Endpoint Security SOC 2

RMM & Patch Management

Endpoint Management

Built the business case for an RMM platform twice (first deferred, then approved on quantified cost of manual work), rolled it out to 95%+ of the fleet, and wrote a PowerShell automation library including a two-ring patching model with an expedited path for critical CVEs.

RMM Patch Management PowerShell Vulnerability Management

Enterprise Password Management

Security

Replaced spreadsheet credential storage with an enterprise password manager: IdP-integrated SSO and SCIM provisioning, agents pushed through RMM, shared vault architecture, and admin training sessions.

Password Management IAM SCIM Training

Network Security Across Six Offices

Networking

Deployed next-generation firewalls and access points across all offices with centralized, declarative management, site-to-cloud VPN with segmented zones, and complete IT builds for office moves in five cities.

NGFW VPN Network Security Office Buildouts

DMARC Policies

Email Security

Audited email-enabled systems and implemented DMARC to improve deliverability and mitigate spoofing and spam.

DMARC Email Security

Cyber Security Plan (IMO)

Maritime Compliance

Developed vessel cyber security plan per IMO MSC-FAL.1/Circ.3 using the NIST Cybersecurity Framework for process control and safety systems.

IMO NIST CSF Maritime Risk Assessment

Document Management System

Development

Built a PHP/LAMP document management system with SMB replication via FTP to remote sites and intranet integration.

PHP LAMP FTP WordPress

Experience

Career spanning IT leadership, offshore vessel operations, accounting, and public sector work terms.

Lotlinx Inc • April 2022 to Present

IT Manager

Automotive ad tech leader serving US dealerships with roughly 200 employees across six offices in Canada and the US. First dedicated IT Manager; built the IT and security operations function from the ground up and lead the company's SOC 2 program.

  • Lead the SOC 2 program end to end: 20+ policy framework, gap assessments, GRC platform implementation, penetration testing, tabletop exercises, and the external audit engagement.
  • Led organization-wide AI adoption (Gemini, Claude, Claude Code, Cursor) with governance, security controls, spend caps, and usage reporting built in from day one.
  • Implemented the endpoint security stack: RMM, EDR, MDR, cross-platform UEM/MDM, and enterprise password management.
  • Selected and deployed a CNAPP for cloud security posture across AWS and GCP, consolidating and replacing native cloud tooling.
  • Architected the identity platform: SSO and lifecycle management with the HRIS as source of truth, provisioning the full SaaS estate over SCIM and SAML with automated onboarding and offboarding.
  • Hired and lead IT and security operations teams, including job design, 90-day plans, career ladders, and performance management.
  • Run ITSM against defined SLAs and KPIs through a service management platform rebuilt as the company's operational intake layer.
  • Designed and delivered network and physical infrastructure (NGFW, cloud VPN, access control, AV) for office builds and moves in five cities.
Sea1 Offshore • September 2013 to April 2022

IT Coordinator

Marine transportation company with 160 employees, two offices, and six seagoing vessels. Administered marine ERP (ABS Nautical Systems) and vessel IT infrastructure.

  • Implemented company-wide Cyber Security Plan per IMO guidelines.
  • Managed servers, networks, VSAT satellite internet, backups, and disaster recovery.
  • Developed WordPress intranet with Azure AD and custom document management system.
  • Built applications and custom reports interfacing with fleet management ERP.
  • Provided 24/7 on-call support for shore and seagoing users.
Noseworthy Chapman Chartered Professional Accountants • June 2011 to September 2013

Network Administrator

Full-service accounting firm with 70 staff. Sole IT resource at an Atlantic Canada's Top Employer.

  • Oversaw servers, networking, desktop support, backups, security, and budgeting.
  • Standardized IT documentation, naming conventions, and CaseWare templates.
  • Delivered security and application training; built MediaWiki intranet.
  • Implemented remote access, BYOD/MDM, AD policies, and virtualization.
Canada-Newfoundland and Labrador Offshore Petroleum Board • September 2010 to December 2010

Computer Support Specialist (work term)

  • Managed IT help desk for software, AD, hardware, and troubleshooting requests.
  • Coordinated server backups and maintained Access database of backup tapes.
  • Documented procedures and built IT asset tracking database.
Office of the Chief Information Officer, Government of NL • January 2010 to April 2010

Computer Support Specialist (work term)

  • Promoted to computer support specialist for internal and external IT services.
  • Handled computer setup, data recovery, and remote workstation troubleshooting.
Office of the Chief Information Officer, Government of NL • May 2009 to August 2009

Application Analyst (work term)

  • Created video tutorials and web pages for HP OpenView service pages.
  • Built technical, team, and communication skills in a service-oriented workplace.

Skills and Tools

No fake progress bars. Just the stuff I’ve actually used or built with.

Security & Compliance

SOC 2 GRC NIST CSF PCI DSS CCPA CPRA PIPEDA GLBA IMO MSC-FAL.1 Secureframe SentinelOne EDR Arctic Wolf MDR Orca Security KnowBe4 DMARC 1Password Penetration Test Management Tabletop Exercises Incident Response

AI & Automation

Claude / Claude Code Cursor Gemini MCP Servers OpenTelemetry AI Policy & Governance Usage Analytics Zapier n8n Prompt & Agent Workflows

Identity & SaaS

Okta BetterCloud Microsoft Intune Jamf Google Workspace Azure AD Office 365 Rippling Slack Zoom SCIM SAML OIDC

Infrastructure & Networking

Fortinet FortiManager VMware ESXi Nagios NinjaOne RMM Veeam VSAT/Satellite Cisco Ubiquiti SonicWall Active Directory AWS VPN GCP

ITSM & Platforms

Jira Service Desk Confluence Secureframe PDQ Deploy BlueTally GitLab PagerDuty BetterCloud Track Salesforce ABS Nautical Systems Sage 300 ERP

Development & Scripting

JavaScript Node.js PHP Python PowerShell Bash MySQL MSSQL BigQuery Google Cloud Run GAM REST/GraphQL APIs Crystal Reports HTML/CSS

Core Competencies

Project Management Cyber Security IT Budgeting Policy Development Disaster Recovery Network Architecture Process Improvement Vendor Management Team Leadership Executive Reporting Risk Management

Education and Certifications

Education, certifications, conferences, and professional community.

Ongoing

Cyber Security and Technology Conferences and Community Engagement

  • Atlantic Security Conference (AtlSecCon): 2018, 2019, 2024, 2026
  • BSides St. John's: 2025, 2026
  • Rock Solid Technology Conference (Triware): annual attendee for over 10 years
  • Fortinet Anti-Ransomware Crisis Room: 2025
  • IT-ISAC Technical Committee: ongoing

Contact

Reach out via the contact form or LinkedIn.

Let’s Connect

I'm interested in security operations, compliance, and IT leadership roles, and in opportunities where I can keep building real technical depth: SOC 2 and GRC automation, governed AI adoption, cloud and endpoint security, and identity. If any of that matches what you're working on, reach out.