Mark Weflen
GRC Program and Content Operations Leader
I help enterprise and defense-sector cloud providers get through FedRAMP, CMMC, DoD, GovRAMP, IRAP, and DISP authorizations. I also build the team and tools behind that work: I grew a one-person, contract tech writing role into a team of five, turned scattered document examples into a comprehensive template library, and created an AI tool to operationalize our IP and do much of the writing for us.
- Currently
- Manager, Technical Content Operations — 38North Security
- Based in
- Chicago, IL — open to remote & hybrid
- Experience
- 15 years total — last 5 in GRC/compliance program leadership
- Focus areas
- GRC/compliance program leadership · content systems & documentation ops · AI-assisted tooling
01 · Focus
Two disciplines, one underlying skill set
I'm seeking new opportunities in GRC and compliance, where I can take on broader program leadership, but I remain open to content operations and documentation leadership roles in other domains if it's the right fit. Both draw on the same core skills: information architecture, process standardization, and team leadership.
Compliance & GRC
Content Operations & Documentation
02 · Experience
What I've been up to
38North Security
- Delivered compliance, engineering, and advisory consulting engagements with over 15 industry-leading cloud service providers.
- Lead a team of up to 5 (currently 3) cloud security analysts and technical writers, developing FedRAMP, CMMC, DoD, FISMA, GovRAMP, IRAP, and DISP compliance artifacts.
- Designed and built an AI-powered automation tool that drafts high-quality security and privacy control implementation statements across FedRAMP, DoD, and CMMC frameworks, driven by structured JSON control mappings, standardized response templates, and sanitized training examples; validated in production on FedRAMP and DoD engagements, cutting documentation costs by an estimated 30%.
- Author and edit system security plans, POA&Ms, policies/procedures, and gap assessments against NIST SP 800-53 Rev 5, NIST SP 800-171, and DoD Cloud Computing SRG IL4/IL5 requirements.
- Spearhead development of documentation practices and templates for FedRAMP 20x CR26 machine-readable compliance package delivery.
- Provide compliance advisory and project-management support directly to client security, engineering, and compliance stakeholders, translating control requirements and assessor findings into actionable, remediation-ready guidance.
- Founded and drove adoption of a Template Library on SharePoint, replacing scattered and uncontrolled company assets with a centralized, governed resource that became one of the company's most widely used internal tools.
- Hired and trained nearly all team members from junior level; built a video-based training library and standardized quarterly performance evaluation metrics from scratch.
Mischa Communications (Freelance)
- Researched and wrote weekly marketing-oriented blog articles on trending cybersecurity topics for a cybersecurity services client, translating technical subject matter into audience-ready thought leadership content.
Huntington National Bank (Contract)
- Led sprint planning and requirements-gathering sessions as lead BSA of a multimillion-dollar project to migrate all Huntington bill pay operations to BillGO, a bill payment services provider.
- Led and coordinated requirements development among 20+ business systems analysts, maintaining consistency of documented requirements across every application in scope.
- Developed data mapping and conversion process documentation governing migration of all active bill-payer records and two years of historical transaction data to the vendor platform.
- Wrote Agile user stories for updated service-oriented architecture services and APIs.
OhioHealth (Contract)
- Authored 40+ information security policies and standards, documenting OhioHealth's information security program from the ground up.
- Developed cross-departmental procedures for incident response, data forensics investigations, lab draw site network installations, and formal risk acceptance.
- Researched and drafted documentation to satisfy HIPAA and PCI DSS compliance requirements.
Huntington National Bank (Contract)
- Led requirements-gathering and process flowcharting sessions for seven use cases supporting a multimillion-dollar IT risk controls improvement program.
- Wrote corporate IT standards for capacity management and configuration management.
- Partnered with IT architects to design and document an infrastructure capacity management system for tracking and forecasting asset allocation, utilization, and purchasing.
JPMorgan Chase & Co. (Contract)
- Led a project to successfully develop technical support runbooks for 23 software applications.
Health Services Advisory Group
- Collaborated with subject matter experts to revise and edit three comprehensive, annual health plan reports.
- Edited and formatted the auditing tools used to conduct administrative reviews on behalf of the Ohio Department of Medicaid for Aetna, Buckeye Health Plan (Centene), CareSource, Molina, Paramount, and UnitedHealthcare.
- Performed regulatory research to align audit practices with federal and state Medicaid standards.
Infor
- Developed and maintained integrated online help for an enterprise manufacturing, time and attendance, and inventory management application deployed across desktops, touch-screen consoles, and mobile scanners.
- Trained international teams in the use of a DITA content management system and developed supporting training guides and video tutorials.
- Developed XML templates for configuration and integration guides used across nearly all Infor product lines.
Konecranes
- Collaborated with international colleagues to develop the corporate ISO 9001 quality manual intended for implementation at all major equipment production facilities.
- Designed and implemented a documentation production error-tracking system that reduced documentation warranty claims by 70% in 2011.
03 · Selected Work
Stuff I've built and written
A set of samples from my past work, not a full archive. As a security and privacy specialist, most of my professional work is covered by NDAs. All examples are either public publications or presented in sanitized, de-identified form.
AI-Powered Compliance Documentation System
A compliance documentation accelerator that pairs writing prompt libraries, framework-specific templates, and diverse examples with an LLM to draft SSP control implementation statements, which the content operations team then reviews, revises, and validates before client delivery.
Compliance Template Library
A version-controlled template library spanning domestic and international security frameworks, giving compliance teams client-ready starting points instead of scattered, uncontrolled company assets. Built on a centralized taxonomy and information architecture, it became one of the company's most widely used internal resources. Screenshots below are sanitized of client- and company-identifying details.
Technical & Policy Writing
The SFY2016 report is real and public. The other three are "shadow" samples, recreated from scratch around a fictional company or product, matching the type, structure, and depth of documents I actually wrote, so nothing proprietary from a real employer or client is exposed. Happy to speak to the real underlying work directly.
04 · Contact
Let's talk
I'd love to connect for partnership, networking, and employment opportunities.