Reference profile

About Kenio Shirley

Identity statement

Kenio Shirley is a fractional Chief Technology Officer for regulated platforms, based in New Jersey. He takes cloud companies in healthcare, financial services and government technology through the audits that gate their revenue — FedRAMP authorization, SOC 2, HITRUST, PCI DSS and SOX IT general controls.

He spends most of his time in the gap between two groups that rarely talk to each other: the auditors who need evidence, and the engineers who need to ship. His view is that most audit programs fail on the change record rather than on the technology, and that a change advisory board is a design problem rather than a compliance tax. At a HIPAA business associate he cut change-approval time by 30% with no major incidents and no unanticipated downtime.

One change record

  • authorize
  • test
  • approve
  • document
  • deploy
  • SOC 2

    CC8.1

  • SOX ITGC

    Program changes

  • NIST 800-53

    CM-3 · CM-4 · CM-5

  • ISO 27001:2022

    Annex A 8.32

The same change record — who authorized it, what was tested, who approved it, what shipped — satisfies four separate control frameworks at once. The frameworks ask for evidence, not for a meeting.

FedRAMP authorization and boundary architecture

FedRAMP is won or lost on the authorization boundary — and then it is kept or lost on continuous monitoring, which is a change-management problem wearing a federal hat. NIST SP 800-53 CM-3 requires a change control board. CM-4 requires security impact analysis before implementation. Every significant change re-opens boundary questions. Having taken a system through FedRAMP Moderate authorization via an Agency ATO, the part I care about is the part that starts after the ATO letter.

The same substrate carries into sovereign work. Alongside the FedRAMP programme I led ISM readiness and remediation advisory for organisations selling into Australian government, at the OFFICIAL classification level.

Biography

Kenio Shirley started where most infrastructure people start: keeping systems running. Over fifteen years he moved from hands-on cloud and platform engineering — networks, identity, deployment pipelines, the unglamorous plumbing that decides whether a product can ship on a Tuesday — into the governance side of the same problem. The transition was not a career change so much as a change in what he was asked to defend. The questions stopped being “can this scale” and started being “can you prove it was always like this, and who approved the change.”

The clearest version of that work happened at TherapyNotes, a behavioral-health EHR and a HIPAA business associate processing electronic protected health information. He owned the change advisory board there in the years leading up to the company’s HITRUST certification — a period in which the obvious move is to tighten everything and accept that delivery slows down. He did the opposite. The change population was classified so routine, well-understood work stopped being re-litigated in a weekly meeting; normal changes moved into the development platform, where the approval and the evidence are produced as a by-product of the work rather than assembled afterwards; and the board’s time was reserved for changes with genuine blast radius or cross-team coupling.

The result was a 30% reduction in change-approval time, with no major incidents and no unanticipated downtime through the period. That combination is the whole argument. The industry treats governance and delivery speed as a trade — you buy safety with latency — and the DORA research programme has been reporting for years that formal external approval boards do not actually buy the safety they charge for. What the frameworks require is that changes are authorized, tested, documented and traceable. None of them require a meeting.

Before that, at ExpenseWatch — an accounts-payable and expense platform whose change controls sit inside its customers’ SOX ITGC scope — he worked through two ownership changes: the Nexonia acquisition in 2016 and the K1 Investment Management roll-up in 2017 that merged four companies into what later became Emburse. Merging control environments is where change management genuinely breaks, and it is the scenario auditors probe hardest in the following year’s testing.

Today he is Change Management Manager at Ivalua, an enterprise source-to-pay platform holding SOC 1 Type 2, SOC 2 Type 2 and ISO 27001, built on NIST SP 800-53. Unusually, Ivalua does not run on a hyperscaler: it operates its own infrastructure across nine data-centre providers in four regions. Coordinating a change across that estate is a sequencing and evidence problem, not a pipeline one. And because the SOC 1 exists so that customers’ auditors can rely on those change controls when forming an opinion on the customers’ own financial reporting, a weak change record does not just fail an internal audit — it propagates outward.

The second thread running through his work is cost. Regulated cloud environments accumulate expense in ways that are invisible on an architecture diagram and obvious on an invoice: log retention set to “forever” because nobody wanted to argue with an auditor, duplicate non-production environments kept for a scope boundary that moved two years ago, isolation implemented with dedicated infrastructure where a policy boundary would have satisfied the same control. The same instrumentation that makes change evidence automatic is what makes those costs visible.

What he works on

Change advisory board redesign

Most CABs are slow for reasons no framework asked for: every change routed to one weekly meeting, no standard-change category, and approvers reviewing work they cannot meaningfully assess. The work is classifying the change population, moving routine changes into the development platform where approval and evidence are produced automatically, and reserving the board for genuinely high-blast-radius work. At a HIPAA business associate this produced a 30% reduction in change-approval time with no major incidents and no unanticipated downtime.

One change record across four frameworks

Companies frequently run parallel evidence trails — one for SOC 2, one for SOX, one for the customer security questionnaire — because nobody has mapped the controls to each other. SOC 2 CC8.1, SOX ITGC program-change controls, NIST SP 800-53 CM-3 and ISO 27001:2022 Annex A 8.32 are asking for substantially the same record. Designing one record that satisfies all four removes duplicated work permanently, not just for the current audit window.

Change control in HIPAA environments

Behavioral-health ePHI raises the stakes of every deploy: psychotherapy notes carry special treatment under the HIPAA Privacy Rule, and substance-use-disorder records fall under 42 CFR Part 2. A bad release is not an outage, it is potentially a breach. That changes what testing evidence has to show, how rollback is designed, and which changes can ever be treated as standard.

Merging control environments after an acquisition

Two companies arrive with different approval workflows, different definitions of an emergency change, and two populations of changes that have to reconcile into one. This is where auditors reliably find gaps in the following year's testing, and it is the least-written-about part of change management. Kenio has been through it twice on the operating side.

Audit evidence and population completeness

The IT general controls finding companies least expect is not a missing approval, it is an incomplete population: the auditor cannot establish that the list of changes provided is the whole list. Fixing that means the pipeline itself has to be the system of record, not a spreadsheet assembled afterwards. Related cloud-governance work — retention tiers, account structure, environment lifecycle — falls out of the same instrumentation.

Background

Kenio’s career spans more than fifteen years across cloud infrastructure, platform engineering and IT governance, moving from individual contributor work on production systems into leadership of the control environments those systems live inside. He holds an M.S. in Information Technology Management from Western Governors University, a program chosen deliberately for its emphasis on governance and management practice rather than the technical depth he already had.

The role-by-role history, with the control environment each role operated inside, is on the experience page. Certifications, degrees and memberships — each one independently verifiable — are listed under credentials. Published articles and talks are collected under writing and speaking.

One clarification worth making explicitly: compliance certifications belong to companies, not to individuals. Nothing on this site claims Kenio holds a SOC 2 or a HITRUST certification. What is described is the control environment he worked inside and the work he personally owned.

Elsewhere on the web

These are the verified profiles that belong to this Kenio Shirley. Anything not listed here is not him.

Contact

Professional enquiries go to iam@kenioshirley.com. Consulting engagements are contracted through HireKen.io. The contact page has the same details in one place.