Mark Weflen

GRC Program and Content Operations Leader

I help enterprise and defense-sector cloud providers get through FedRAMP, CMMC, DoD, GovRAMP, IRAP, and DISP authorizations. I also build the team and tools behind that work: I grew a one-person, contract tech writing role into a team of five, turned scattered document examples into a comprehensive template library, and created an AI tool to operationalize our IP and do much of the writing for us.

Photo of Mark Weflen
Mark Weflen Me
Currently
Manager, Technical Content Operations — 38North Security

Based in
Chicago, IL — open to remote & hybrid

Experience
15 years total — last 5 in GRC/compliance program leadership

Focus areas
GRC/compliance program leadership · content systems & documentation ops · AI-assisted tooling

01 · Focus

Two disciplines, one underlying skill set

I'm seeking new opportunities in GRC and compliance, where I can take on broader program leadership, but I remain open to content operations and documentation leadership roles in other domains if it's the right fit. Both draw on the same core skills: information architecture, process standardization, and team leadership.

Compliance & GRC

FedRAMP 20x & Rev 5 (NIST 800-53) CMMC (NIST 800-171) DoD IL4/IL5, NSS & Privacy Controls IRAP / DISP GovRAMP SSP & POA&M Authorship Policy & Procedure Development Gap Assessments Continuous Validation Client Advisory GRC Platforms (Diligent, Paramify)

Content Operations & Documentation

AI-Assisted Content Tooling Content Strategy & Information Architecture Documentation Systems & Template Libraries Self-Serve & Help Content Design Process Standardization Team Leadership & Training Design Style Guides & Editorial Standards Cross-Functional Stakeholder Collaboration

02 · Experience

What I've been up to

Jul 2021 – Present

38North Security

Washington, D.C. (Remote)
Manager, Technical Content Operations (Sep 2024–present) · Cloud Security Tech Writing Lead (Jul 2022–Sep 2024) · Cloud Security Technical Writer, Contract (Jul 2021–Jul 2022)
  • Delivered compliance, engineering, and advisory consulting engagements with over 15 industry-leading cloud service providers.
  • Lead a team of up to 5 (currently 3) cloud security analysts and technical writers, developing FedRAMP, CMMC, DoD, FISMA, GovRAMP, IRAP, and DISP compliance artifacts.
  • Designed and built an AI-powered automation tool that drafts high-quality security and privacy control implementation statements across FedRAMP, DoD, and CMMC frameworks, driven by structured JSON control mappings, standardized response templates, and sanitized training examples; validated in production on FedRAMP and DoD engagements, cutting documentation costs by an estimated 30%.
  • Author and edit system security plans, POA&Ms, policies/procedures, and gap assessments against NIST SP 800-53 Rev 5, NIST SP 800-171, and DoD Cloud Computing SRG IL4/IL5 requirements.
  • Spearhead development of documentation practices and templates for FedRAMP 20x CR26 machine-readable compliance package delivery.
  • Provide compliance advisory and project-management support directly to client security, engineering, and compliance stakeholders, translating control requirements and assessor findings into actionable, remediation-ready guidance.
  • Founded and drove adoption of a Template Library on SharePoint, replacing scattered and uncontrolled company assets with a centralized, governed resource that became one of the company's most widely used internal tools.
  • Hired and trained nearly all team members from junior level; built a video-based training library and standardized quarterly performance evaluation metrics from scratch.
Aug 2021 – Jan 2023

Mischa Communications (Freelance)

Cleveland, OH (Remote)
Cybersecurity Content Writer (Part-time)
  • Researched and wrote weekly marketing-oriented blog articles on trending cybersecurity topics for a cybersecurity services client, translating technical subject matter into audience-ready thought leadership content.
Jul 2020 – Mar 2021

Huntington National Bank (Contract)

Columbus, OH
Business Systems Analyst Lead
  • Led sprint planning and requirements-gathering sessions as lead BSA of a multimillion-dollar project to migrate all Huntington bill pay operations to BillGO, a bill payment services provider.
  • Led and coordinated requirements development among 20+ business systems analysts, maintaining consistency of documented requirements across every application in scope.
  • Developed data mapping and conversion process documentation governing migration of all active bill-payer records and two years of historical transaction data to the vendor platform.
  • Wrote Agile user stories for updated service-oriented architecture services and APIs.
Mar 2019 – Jan 2020

OhioHealth (Contract)

Columbus, OH
Technical Writer / Security Analyst
  • Authored 40+ information security policies and standards, documenting OhioHealth's information security program from the ground up.
  • Developed cross-departmental procedures for incident response, data forensics investigations, lab draw site network installations, and formal risk acceptance.
  • Researched and drafted documentation to satisfy HIPAA and PCI DSS compliance requirements.
Feb 2018 – Jan 2019

Huntington National Bank (Contract)

Columbus, OH
Business Systems Analyst
  • Led requirements-gathering and process flowcharting sessions for seven use cases supporting a multimillion-dollar IT risk controls improvement program.
  • Wrote corporate IT standards for capacity management and configuration management.
  • Partnered with IT architects to design and document an infrastructure capacity management system for tracking and forecasting asset allocation, utilization, and purchasing.
Jul 2017 – Dec 2017

JPMorgan Chase & Co. (Contract)

Columbus, OH
Application Support Analyst / Technical Writer
  • Led a project to successfully develop technical support runbooks for 23 software applications.
Mar 2016 – Jul 2017

Health Services Advisory Group

Columbus, OH
Senior Technical Writer/Editor
  • Collaborated with subject matter experts to revise and edit three comprehensive, annual health plan reports.
  • Edited and formatted the auditing tools used to conduct administrative reviews on behalf of the Ohio Department of Medicaid for Aetna, Buckeye Health Plan (Centene), CareSource, Molina, Paramount, and UnitedHealthcare.
  • Performed regulatory research to align audit practices with federal and state Medicaid standards.
Jan 2013 – Feb 2016

Infor

Columbus, OH
Information Developer
  • Developed and maintained integrated online help for an enterprise manufacturing, time and attendance, and inventory management application deployed across desktops, touch-screen consoles, and mobile scanners.
  • Trained international teams in the use of a DITA content management system and developed supporting training guides and video tutorials.
  • Developed XML templates for configuration and integration guides used across nearly all Infor product lines.
Jul 2010 – Jan 2013

Konecranes

Springfield, OH
Technical Writer
  • Collaborated with international colleagues to develop the corporate ISO 9001 quality manual intended for implementation at all major equipment production facilities.
  • Designed and implemented a documentation production error-tracking system that reduced documentation warranty claims by 70% in 2011.
2011
MA, Technical and Scientific Communication — Miami University · GPA 4.0
2008
BA, English — University of Cincinnati · GPA 3.6

03 · Selected Work

Stuff I've built and written

A set of samples from my past work, not a full archive. As a security and privacy specialist, most of my professional work is covered by NDAs. All examples are either public publications or presented in sanitized, de-identified form.

System · Built & shipped

AI-Powered Compliance Documentation System

Designed and built solo in 2025 · deployed in production at a DC-based cybersecurity compliance consultancy · now being expanded across additional frameworks and deliverables by the company's engineering team

A compliance documentation accelerator that pairs writing prompt libraries, framework-specific templates, and diverse examples with an LLM to draft SSP control implementation statements, which the content operations team then reviews, revises, and validates before client delivery.

~30%
Est. documentation cost reduction, early engagements
3
Frameworks covered: FedRAMP, DoD, CMMC
Watch the demo A walkthrough of the system in action, recorded on Loom.
System · Founded & led

Compliance Template Library

Founded the library in 2023 · directed the team that built it out

A version-controlled template library spanning domestic and international security frameworks, giving compliance teams client-ready starting points instead of scattered, uncontrolled company assets. Built on a centralized taxonomy and information architecture, it became one of the company's most widely used internal resources. Screenshots below are sanitized of client- and company-identifying details.

Writing samples

Technical & Policy Writing

One public report; three recreated samples standing in for real client/employer work

The SFY2016 report is real and public. The other three are "shadow" samples, recreated from scratch around a fictional company or product, matching the type, structure, and depth of documents I actually wrote, so nothing proprietary from a real employer or client is exposed. Happy to speak to the real underlying work directly.

On the SFY2016 report: I wrote sections 1 (Executive Summary) and 9 (Conclusions & Recommendations) and edited the full document; the excerpt above includes those two sections plus the cover page. It was published by the Ohio Department of Medicaid. On the three recreated samples: the fictional company/product names, dates, and every sentence are original; only the document type and structure reflect real work.
Night view of the Chicago skyline and lakefront from above.
Chicago, IL

04 · Contact

Let's talk

I'd love to connect for partnership, networking, and employment opportunities.