Post Job Free
Sign in

Information Security Cyber

Location:
Atlanta, GA
Posted:
December 01, 2023

Contact this candidate

Resume:

EDUCATION

South Carolina State University

Orangeburg, SC

Bachelor of Science in Marketing

CERTIFICATION

CompTIA Security +

AWS

CISA (In progress)

Georgia Grimes

404-***-****

**************@*****.***

GA USA

Team player and excellent communicator with a solid cyber security program development background and a broad set of compliance experience. Hopeful for an Information Security position to apply outstanding IT skills, security engineering experience and knowledge of security standards and best practices related to NIST, ISO27001, HIPAA, SOC2, GDPR, and HITRUST.

PROFESSIONAL EXPERIENCE

September 2019 – Present

Senior Information Security Lead

FedEx – USA

Interfaced with IT units and business partners to provide guidance and support;

Performed security and compliance assessments on new and existing systems, processes, technology;

Work with various business units to ensure controls are adequate, appropriate, and effective;

Collaborated to define IT security standards and develop supporting organizational policies;

Performed business impact analysis and assist with development of IT/InfoSec risk register;

Performed periodic gap assessments to validate compliance on an ongoing basis;

Support vendor due-diligence process and help to lead and define overall third party risk management efforts;

Support internal and external audit process for relevant compliance;

Coordinated and participated in disaster recovery and business continuity planning;

Stayed up to date and informed on developing regulatory concerns and changing IT and information security trends.

Liaised with Development teams to identify and remediate key information security defects, which if undetected could have led to more than $30M in legal fees, penalties, & fines by clients and federal agencies.

Developed and implemented new information security policies and standards which led to a 25% increase in successfully passed audits and compliance with various industry standards.

Working knowledge of NIST, ISO27001, SOC2, and GDPR

Identified gaps, develop remediation plan and train team and collogues on the ISO27001, NIST, GDPR, and SOC compliance activates and controls.

June 2011 – September 2019

Information Security Analyst

Centers of Disease Control – USA

Conducted kick-off meetings to collect systems information and categorize systems based on NIST SP800-60

Developed security control baseline and tested plan used to assess and implement security controls

Created and updated the following Security Assessment and Authorization (SA&A) artifacts; FIPS

199, Risk Assessments Report (RAR) Privacy Threshold Analysis (PTA), Privacy Impact Analysis• (PIA), Contingency Plan, Security Test and Evaluations (ST&Es), E-Authentication, Plan of Action and Milestones (POAMs).

Met with the system team to collect evidence, develop test plans and procedures and document test results.

Designed and Conducted walkthroughs, formulated test plans, tested results and developed remediation plans for each area of the testing.

Conducted FISMA complaint security control assessments to ascertain the adequacy of management, operational, technical privacy controls.

Examined events logs for irregularities. Identified irregularities are then reported as incidents. The incident response is then initiated to mitigate these irregularities.

Directed development of policies, procedures, standards, and version control

Planned and executed change control and activities, baseline identification, naming conventions, status accounting, and reporting

Developed documentation for government projects, including plans, project plans, test plans, risk mitigation plans, and RTMs

Performed QA: conducted process and work product audits and inspections; worked with project managers and leads to resolve discrepancies

Wrote quality, and management sections of proposals for business development

Managed change requests from field; prioritized and planned release sets for applicable code branches

Work effectively with other team members to complete required tasks.

Performing ongoing RMF/A&A/ATO projects in support of client security systems using NIST SP 800-37 as a guide.

Perform evaluations of internal controls, communications, risk assessments, and maintenance of documentations as it relates to SOC2 Type II, NIST, ISO27001, and PCI standards.

ADDITIONAL SKILLS

Compliance Maturity

Internal Audits

External Audits

Develop Security Awareness Training Program

Develop Risk Management Program

Develop Third Party Risk Management Program

Control Mapping

Policies & Procedures development



Contact this candidate