QR
Quentin Roberts
SOC 2 • Security Operations • AI Governance • Automation

IT Leader + Security & Compliance

I build security, compliance, and AI governance programs and run the automation that keeps them alive. Currently leading a SOC 2 audit engagement and governed enterprise AI adoption at Lotlinx, backed by 15+ years of IT leadership across automotive ad tech, offshore oil & gas, and professional services.

SOC 2 Built the program from first pitch; external audit engagement underway
AI Governance Led org-wide adoption of Claude, Cursor, and Gemini with controls built in
Team Leadership Hired and lead IT and security operations teams

About Me

I lead security, compliance, and IT operations at Lotlinx, where I built the security function from the ground up: a SOC 2 program now in external audit, a 20+ policy governance framework, a layered endpoint and cloud security stack, and organization-wide AI adoption with the controls and usage monitoring designed in from day one. Behind that sits 15+ years of owning entire technology estates across automotive ad tech, offshore oil & gas (including an IMO-mandated maritime cyber security plan), and professional services. My pattern is consistent: find the gap, make the business case, design the solution, run the rollout, then automate it so it scales.

Security & Compliance Leadership

Built a SOC 2 program from first internal pitch to external audit engagement: a 20+ policy framework, Secureframe GRC automation, penetration testing, tabletop exercises, and a security team I hired and lead. Vulnerability trends, audit progress, and risk reporting all run through me.

AI Governance & Enablement

Led organization-wide adoption of Claude, Claude Code, Cursor, and Gemini as both the governance owner and a heavy daily practitioner. Wrote the AI policy, built the security controls, spend caps, and usage monitoring, and built the dashboard leadership uses to steer AI investment.

Identity & Automation

Architected Okta SSO and MFA, BetterCloud lifecycle automations, and HRIS-driven identity with Rippling as the source of truth, keeping access accurate from onboarding through offboarding across the entire SaaS estate over SCIM and SAML.

Featured Projects

Highlighted initiatives spanning SOC 2 compliance, AI governance, security operations, identity, and automation.

SOC 2 Program

Compliance

Directed a ground-up SOC 2 program from first pitch through external audit engagement: policy framework, gap assessments, Secureframe implementation, penetration testing, tabletop exercises, and the auditor relationship. Evidence collection runs on automation, not spreadsheets.

SOC 2 Secureframe Audit GRC

AI Governance & Rollout

AI Governance

Wrote the AI acceptable-use policy and led the phased rollout of Gemini, Claude, Claude Code, and Cursor with controls built in from the start: risk assessments, OpenTelemetry usage monitoring, spend caps, and Okta-governed provisioning. Extended governance to MCP servers with an SOP, inventory tooling, and a request intake process.

Claude Code Cursor Gemini Policy OpenTelemetry

AI Usage & Adoption Dashboard

AI Governance

Built the dashboard leadership uses to steer AI investment, covering per-user adoption, usage depth, and spend across Claude, Cursor, and Gemini. Data collection is automated, including a PowerShell exporter written against Cursor's analytics API.

Analytics PowerShell BigQuery Reporting

Orca Security CNAPP

Cloud Security

Ran the cloud security platform selection, choosing Orca while retiring native AWS and GCP security tooling. Baselined cloud-native Kubernetes container CVE exposure in production, including VM instances in EC2 and Azure, and stood up malicious-package alerting. Utilized DSPM capabilities and secrets detection.

Orca AWS GCP CNAPP Vulnerability Management

Security Policy Library

Compliance

Built the company's information security policy framework from zero into a versioned library of 20+ documents, each carried through legal, HR, and executive approval with employee attestation. Every policy is backed by a working control, so the framework holds up under audit.

Policy Governance SOC 2 Risk

Arctic Wolf MDR

Detection & Response

Led evaluation, procurement, and rollout of managed detection and response, integrated across the SaaS estate, cloud infrastructure, and every endpoint. Vulnerability counts have trended down since deployment, reported quarterly to leadership.

Arctic Wolf MDR SOC 2 Monitoring

Supply Chain Threat Mitigation

Detection & Response

Built and led supply chain threat mitigation across the engineering estate: scripted GitLab exposure sweeps, malicious-package alerting, post-event analysis for leadership, and automation that shortens detection and response when upstream threats appear.

Supply Chain GitLab Threat Mitigation Automation

Incident Response & Tabletop Program

Resilience

Established tabletop exercises as standing controls: incident response scenarios with DevOps, legal, compliance, and executives, plus annual business continuity and disaster recovery testing. Designed and ran a company-wide security tabletop at the product and technology summit.

Incident Response BC/DR SOC 2 Training

Built the CCPA and data-subject request process with defined SLAs and automated intake, drove privacy policy and MSA updates with legal, implemented consent management on the website, and managed the Privacy Impact Assessment for the company's Canadian market launch with external privacy counsel.

CCPA CPRA PIPEDA Privacy Consent

Jamf macOS Management

Endpoint Management

Selected and led the Jamf and Jamf Connect deployment for the macOS fleet: zero-touch enrollment, policy and script architecture, local admin removal, and Okta-connected login. Closed the MDM gap alongside Intune on Windows.

Jamf macOS MDM Okta

Built automated identity management with Okta as definitive source of truth, integrating Rippling HRIS, SCIM, SAML, and BetterCloud API automations.

Okta BetterCloud Rippling SCIM API

Engineered automated user lifecycle management using APIs, SCIM, webhooks, and custom JavaScript BetterCloud extensions.

BetterCloud JavaScript SCIM Webhooks

SentinelOne EDR Implementation

Endpoint Security

Delivered Endpoint Detection and Response across all end-user devices to meet SOC 2 security controls and strengthen incident response.

SentinelOne EDR SOC 2 Endpoint

Microsoft Intune MDM

Endpoint Management

Deployed Intune MDM for centralized device management, compliance policies, and remote wipe across the mobile fleet.

Intune MDM Compliance SOC 2

Migrated all passwords from shared spreadsheets to 1Password with employee training for secure password management.

1Password Training Password Management

Upgraded network infrastructure with FortiGate firewalls, FortiAP access points, FortiSwitch managed switches, and FortiManager across all offices.

FortiGate FortiAP FortiManager Network Security

DMARC Policies

Email Security

Audited email-enabled systems and implemented DMARC to improve deliverability and mitigate spoofing and spam.

DMARC Email Security

Architected and deployed Okta as a foundational security platform, migrating all applications to centralized SSO and MFA.

Okta SSO MFA SAML SCIM

Cyber Security Plan (IMO)

Maritime Compliance

Developed vessel cyber security plan per IMO MSC-FAL.1/Circ.3 using the NIST Cybersecurity Framework for process control and safety systems.

IMO NIST CSF Maritime Risk Assessment

Document Management System

Development

Built a PHP/LAMP document management system with SMB replication via FTP to remote sites and intranet integration.

PHP LAMP FTP WordPress

Experience

Career spanning IT leadership, offshore vessel operations, accounting, and public sector work terms.

Lotlinx Inc • April 2022 to Present

IT Manager

Automotive ad tech leader serving US dealerships with roughly 200 employees across six offices in Canada and the US. First dedicated IT Manager; built the IT and security operations function from the ground up and lead the company's SOC 2 program.

  • Lead the SOC 2 program end to end: 20+ policy framework, gap assessments, Secureframe implementation, penetration testing, tabletop exercises, and the external audit engagement.
  • Led organization-wide AI adoption (Gemini, Claude, Claude Code, Cursor) with governance, security controls, spend caps, and usage reporting built in from day one.
  • Implemented the endpoint security stack: NinjaOne RMM, SentinelOne EDR, Arctic Wolf MDR, Intune and Jamf MDM, and 1Password.
  • Selected and deployed Orca Security as the cloud security platform, consolidating and replacing native AWS and GCP tooling.
  • Architected the identity platform: Okta SSO and lifecycle management with Rippling as the source of truth, provisioning the full SaaS estate over SCIM and SAML with automated onboarding and offboarding.
  • Hired and lead IT and security operations teams, including job design, 90-day plans, career ladders, and performance management.
  • Run ITSM against defined SLAs and KPIs through a Jira Service Management helpdesk rebuilt as the company's operational intake layer.
  • Designed and delivered network and physical infrastructure (Fortinet, AWS VPN, access control, AV) for office builds and moves in five cities.
Sea1 Offshore • September 2013 to April 2022

IT Coordinator

Marine transportation company with 160 employees, two offices, and six seagoing vessels. Administered marine ERP (ABS Nautical Systems) and vessel IT infrastructure.

  • Implemented company-wide Cyber Security Plan per IMO guidelines.
  • Managed servers, networks, VSAT satellite internet, backups, and disaster recovery.
  • Developed WordPress intranet with Azure AD and custom document management system.
  • Built applications and custom reports interfacing with fleet management ERP.
  • Provided 24/7 on-call support for shore and seagoing users.
Noseworthy Chapman Chartered Professional Accountants • June 2011 to September 2013

Network Administrator

Full-service accounting firm with 70 staff. Sole IT resource at an Atlantic Canada's Top Employer.

  • Oversaw servers, networking, desktop support, backups, security, and budgeting.
  • Standardized IT documentation, naming conventions, and CaseWare templates.
  • Delivered security and application training; built MediaWiki intranet.
  • Implemented remote access, BYOD/MDM, AD policies, and virtualization.
Canada-Newfoundland and Labrador Offshore Petroleum Board • September 2010 to December 2010

Computer Support Specialist (work term)

  • Managed IT help desk for software, AD, hardware, and troubleshooting requests.
  • Coordinated server backups and maintained Access database of backup tapes.
  • Documented procedures and built IT asset tracking database.
Office of the Chief Information Officer, Government of NL • January 2010 to April 2010

Computer Support Specialist (work term)

  • Promoted to computer support specialist for internal and external IT services.
  • Handled computer setup, data recovery, and remote workstation troubleshooting.
Office of the Chief Information Officer, Government of NL • May 2009 to August 2009

Application Analyst (work term)

  • Created video tutorials and web pages for HP OpenView service pages.
  • Built technical, team, and communication skills in a service-oriented workplace.

Skills and Tools

No fake progress bars. Just the stuff I’ve actually used or built with.

Security & Compliance

SOC 2 PCI DSS CCPA CPRA PIPEDA GLBA NIST CSF IMO MSC-FAL.1 Orca Security Secureframe SentinelOne EDR Arctic Wolf MDR KnowBe4 DMARC 1Password Penetration Test Management Tabletop Exercises Incident Response

AI & Automation

Claude / Claude Code Cursor Gemini MCP Servers OpenTelemetry AI Policy & Governance Usage Analytics Zapier n8n Prompt & Agent Workflows

Identity & SaaS

Okta BetterCloud Microsoft Intune Jamf Google Workspace Azure AD Office 365 Rippling Slack Zoom 1Password SCIM SAML OIDC

Infrastructure & Networking

Fortinet FortiManager VMware ESXi Nagios NinjaOne RMM Veeam VSAT/Satellite Cisco Ubiquiti SonicWall Active Directory AWS VPN GCP

ITSM & Platforms

Jira Service Desk Confluence Secureframe PDQ Deploy Zapier Salesforce ABS Nautical Systems Sage 300 ERP BlueTally GitLab PagerDuty BetterCloud Track

Development & Scripting

JavaScript Node.js PHP Python PowerShell Bash MySQL MSSQL BigQuery Google Cloud Run GAM REST/GraphQL APIs Crystal Reports HTML/CSS

Core Competencies

Project Management Cyber Security IT Budgeting Policy Development Disaster Recovery Network Architecture Process Improvement Vendor Management Team Leadership Executive Reporting Risk Management

Education and Certifications

Education, certifications, conferences, and professional community.

Ongoing

Cyber Security and Technology Conferences and Community Engagement

  • Atlantic Security Conference (AtlSecCon): 2018, 2019, 2024, 2026
  • BSides St. John's: 2025, 2026
  • Rock Solid Technology Conference (Triware): annual attendee for over 10 years
  • Fortinet Anti-Ransomware Crisis Room: 2025
  • IT-ISAC Technical Committee: ongoing

Contact

Reach out via the contact form or LinkedIn.

Let’s Connect

I'm interested in security operations, compliance, and IT leadership roles, and in opportunities where I can keep building real technical depth: SOC 2 and GRC automation, governed AI adoption, cloud and endpoint security, and identity. If any of that matches what you're working on, reach out.