EDUCATION
South Carolina State University
Orangeburg, SC
Bachelor of Science in Marketing
CERTIFICATION
CompTIA Security +
AWS
CISA (In progress)
Georgia Grimes
**************@*****.***
GA USA
Team player and excellent communicator with a solid cyber security program development background and a broad set of compliance experience. Hopeful for an Information Security position to apply outstanding IT skills, security engineering experience and knowledge of security standards and best practices related to NIST, ISO27001, HIPAA, SOC2, GDPR, and HITRUST.
PROFESSIONAL EXPERIENCE
September 2019 – Present
Senior Information Security Lead
FedEx – USA
Interfaced with IT units and business partners to provide guidance and support;
Performed security and compliance assessments on new and existing systems, processes, technology;
Work with various business units to ensure controls are adequate, appropriate, and effective;
Collaborated to define IT security standards and develop supporting organizational policies;
Performed business impact analysis and assist with development of IT/InfoSec risk register;
Performed periodic gap assessments to validate compliance on an ongoing basis;
Support vendor due-diligence process and help to lead and define overall third party risk management efforts;
Support internal and external audit process for relevant compliance;
Coordinated and participated in disaster recovery and business continuity planning;
Stayed up to date and informed on developing regulatory concerns and changing IT and information security trends.
Liaised with Development teams to identify and remediate key information security defects, which if undetected could have led to more than $30M in legal fees, penalties, & fines by clients and federal agencies.
Developed and implemented new information security policies and standards which led to a 25% increase in successfully passed audits and compliance with various industry standards.
Working knowledge of NIST, ISO27001, SOC2, and GDPR
Identified gaps, develop remediation plan and train team and collogues on the ISO27001, NIST, GDPR, and SOC compliance activates and controls.
June 2011 – September 2019
Information Security Analyst
Centers of Disease Control – USA
Conducted kick-off meetings to collect systems information and categorize systems based on NIST SP800-60
Developed security control baseline and tested plan used to assess and implement security controls
Created and updated the following Security Assessment and Authorization (SA&A) artifacts; FIPS
199, Risk Assessments Report (RAR) Privacy Threshold Analysis (PTA), Privacy Impact Analysis• (PIA), Contingency Plan, Security Test and Evaluations (ST&Es), E-Authentication, Plan of Action and Milestones (POAMs).
Met with the system team to collect evidence, develop test plans and procedures and document test results.
Designed and Conducted walkthroughs, formulated test plans, tested results and developed remediation plans for each area of the testing.
Conducted FISMA complaint security control assessments to ascertain the adequacy of management, operational, technical privacy controls.
Examined events logs for irregularities. Identified irregularities are then reported as incidents. The incident response is then initiated to mitigate these irregularities.
Directed development of policies, procedures, standards, and version control
Planned and executed change control and activities, baseline identification, naming conventions, status accounting, and reporting
Developed documentation for government projects, including plans, project plans, test plans, risk mitigation plans, and RTMs
Performed QA: conducted process and work product audits and inspections; worked with project managers and leads to resolve discrepancies
Wrote quality, and management sections of proposals for business development
Managed change requests from field; prioritized and planned release sets for applicable code branches
Work effectively with other team members to complete required tasks.
Performing ongoing RMF/A&A/ATO projects in support of client security systems using NIST SP 800-37 as a guide.
Perform evaluations of internal controls, communications, risk assessments, and maintenance of documentations as it relates to SOC2 Type II, NIST, ISO27001, and PCI standards.
ADDITIONAL SKILLS
Compliance Maturity
Internal Audits
External Audits
Develop Security Awareness Training Program
Develop Risk Management Program
Develop Third Party Risk Management Program
Control Mapping
Policies & Procedures development