Skip to content

Operator File // Marjean Mayo-Baker

Governance that survives contact with reality.

I work where cybersecurity operations, identity, risk, audit evidence, and human behavior collide—and turn that mess into controls people can understand and use.

Open to OpportunityGRC // IAM // Cybersecurity Governance

What I Do

I’m Marjean Mayo-Baker, a cybersecurity practitioner and builder of realistic governance simulations. Under the Digital Ruins banner, I use simulated and academic environments to show the work behind sound security decisions: defining risk, gathering evidence, mapping controls, writing policy, planning remediation, and communicating with the people accountable for the outcome.

My focus includes:

  • Governance, risk, compliance, and audit readiness
  • Identity and access management, including Entra ID and Active Directory
  • Least privilege, MFA, Conditional Access, and Zero Trust
  • Vendor, contractor, and fourth-party risk
  • AI governance and data-handling boundaries
  • Executive-ready documentation and technical-to-business translation

How I Work

The strongest control is not the one with the longest policy. It is the one that has a clear owner, fits the operating environment, produces usable evidence, and can be explained when something goes wrong.

My portfolio emphasizes four habits:

  1. Name the risk clearly. Connect cause, event, and business impact.
  2. Make the evidence explicit. A control claim should be demonstrable.
  3. Design for humans. Friction, incentives, and operating reality matter.
  4. Close the decision loop. Findings need ownership, priority, and follow-through.

Professional Snapshot

Technology Center Analyst Lead — PNC Bank

Identity and access enforcement, endpoint triage, incident escalation, and operational awareness of vendor-risk issues.

SIM Architect — Digital Ruins

Created scenario-based governance work including MFA Ghost, Shiny Trust Breach, Trust Betrayal, and Human Failure Vector.

Work Products

  • Enterprise risk registers and treatment plans
  • Executive risk and incident briefs
  • Control mappings and evidence plans
  • Policies, standards, and operating procedures
  • Audit and investigation playbooks
  • Lessons-learned and remediation records

Education

  • M.S. Cybersecurity, Southern New Hampshire University — expected 2027
  • B.S. Cybersecurity, Southern New Hampshire University — 2025
  • Google Cybersecurity Professional Certificate
  • Advanced labs in IAM, Zero Trust, governance, and automation