Summary
Karl Nilsen is a Senior IT Risk & Compliance Specialist with 11 years of experience helping organizations reduce cyber and technology risk while enabling business objectives. A CISSP and CISA, he combines deep GRC expertise—including FAIR-based cyber risk quantification, cloud/SaaS security, third-party risk, and vulnerability management—with hands-on controls monitoring and audit readiness. He has led risk programs across regulated sectors and scales, from high-growth digital health at Optum to global life sciences at Danaher and research-focused environments at HHMI. Karl is adept at translating complex technical risk into clear metrics and board-ready communications, and he’s proven at influencing stakeholders across legal, engineering, and executive teams. His background in information science and earlier career in data governance and content/communications gives him an uncommon blend of technical rigor and narrative skill. Currently based in Washington, DC, he focuses on pragmatic, measurable risk reduction that aligns security with strategic priorities.
11 years of coding experience
2 years of employment as a software developer
Master's degree Information Science/Studies, Master's degree Information Science/Studies at University of Toronto