Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 55 additions & 0 deletions engineers/janitam.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
---
name: "Janita Madramootoo"
github: "janitam"
specializations:
- "Cloud Security"
- "Compliance Automation"
- "Risk Management"
- "Security Architecture"
- "Solutions Architecture"
title: "Product Architect, Payments & Compliance"
location: "Melbourne, FL"
linkedin: "https://www.linkedin.com/in/janitam/"
blog: "https://janita.me"
frameworks:
- "HIPAA"
- "NIST 800-53"
- "NIST CSF"
- "PCI-DSS"
languages:
- "Bash"
- "JavaScript"
- "Python"
- "SQL"
- "Terraform"
- "TypeScript"
- "Java"
available_for:
- "mentoring"
- "consulting"
- "freelance"
- "collaboration"
---

## About Me

My GRC experience comes from the engineering side rather than the audit side. For four years I was a Product Architect in payments, designing billing, authentication, and systems that had to live inside PCI-DSS and HIPAA constraints, where compliance was not a review at the end but a constraint on every design decision.

Working closely with our GRC team is what pulled me toward GRC engineering specifically. The part I like is the translation work: turning undocumented practices into controls a team can actually execute against. The engineering team is not being negligent on purpose, we just don't know better.

I hold the CGE-AUD and AWS Solutions Architect Associate certs. I am working through the CGE-P.

Before tech I coordinated commercial construction projects for six years, running 5-7 at a time across eight stakeholder groups. Different industry, same job: keeping a lot of moving parts aligned when the requirements are non-negotiable and everyone wants something different.

## Experience Highlights

- Co-designed a centralized billing gateway serving 12-15 internal consumers, and led pre-launch threat modeling with identified risks driven to remediation before release.
- Wrote automation using Claude to review threat models for completeness and test code and AWS environments against PCI-DSS requirements and common vulnerability patterns.
- Led technical discovery for secure financial document workflows, partnering with engineering, compliance, and customer success to balance user experience against PCI-DSS requirements.
- Led design and delivery of a self-service KYC compliance platform enabling customers to meet regulatory requirements without interrupting payment processing.
- Served on the Architecture Governance Board evaluating technical feasibility of new systems against security, reliability, cost efficiency, and business objectives.
- Mapped data for a migration of 20,000+ subscriptions onto new billing infrastructure, untangling an undocumented legacy service along the way.

## Get in Touch

DM me on LinkedIn at linkedin.com/in/janitam