Samuel Jacobs (COMPTIA Security+)
Gaithersburg, MD
Tel: 240-***-****
*************@*****.***
PROFESSIONAL SUMMARY:
Results-driven GRC Analyst with 6 years of experience specializing in governance, risk management, and compliance. Proficient in developing and executing comprehensive strategies to minimize risks, enhance operational resilience, and ensure compliance with industry standards and regulations. Adept at evaluating internal controls, conducting risk assessments, and streamlining GRC frameworks (ISO 27001, PCI DSS, NIST 800-53, SOC 2) to meet organizational objectives. Collaborative team player with a proven ability to communicate complex concepts effectively across various levels of the organization. Seeking to contribute my expertise to a forward-thinking company dedicated to achieving excellence in GRC practices and mitigating risks proactively.
Cybersecurity and GRC Skills
Skills Category
Key Skills
Governance
- Policy Development and Management
- Compliance Oversight and Reporting
- Board and Stakeholder Communication
Risk Management
- Risk Assessment and Mitigation
- Business Impact Analysis
- Risk Framework Implementation
Compliance
- Regulatory Compliance (GDPR, HIPAA)
- Industry Standards (ISO 27001, NIST, CIS, PCI DSS)
- Compliance Auditing and Reporting (SOC 2 type 2)
- Penetration Testing Report review.
- FIPS 199, FIPS 200, NIST 800-37, 800-53, 800-53A
Technical Proficiency
- GRC Software Tools (RSA Archer, ServiceNow, Jira)
- Monitoring – Splunk, IDS/IPS, Nessus Vulnerability Scan.
WORK EXPERIENCE:
Cyber Security Specialist (GRC). Pacific Cyber Solutions. 05/2018 – Present
●Responsible for maintaining, reviewing, and updating Information System Security
documentations to include but not limited to System Security Plan (SSP), POA&M, Audit reports, policies and procedures, and industry security control baselines/benchmarks.
●Conduct risk and vulnerability assessments of planned and installed information systems
to identify vulnerabilities, risks, and protection needs using SIEM tools McAfee and Splunk.
●Promoting awareness of security issues among management and ensuring sound security principles are reflected in organization’s visions.
●Perform tasks related to compliance of Continuous Monitoring (ConMon), audit logs
review, security patching, software, and hardware configuration management.
●Ensure implementation of appropriate security control for Information System based on
NIST Special Publication 800-53 control catalogue, CIS framework, and ISO 27001.
●Coordinate remediation plans after Nessus vulnerability scans.
●Develop and implement programs to ensure that systems, network, and data users.
are aware of, understand, and adhere to systems security policies and procedures.
●Experience with using ServiceNow and Jira ticketing systems to resolve issues or escalate.
●Designed, reviewed, and monitored internal controls to mitigate risks and enhance operational efficiency.
●Conducted control testing and assessed control deficiencies, recommending corrective actions and improvements following the guidance of NIST 800-53A.
●Coordinated internal and external audits, providing documentation, and facilitating audit processes (SOC 2, PCI Attestation).
GRC/Cybersecurity Analyst Pacific Cyber Solutions. 09/2016 – 05/2018
Conducted periodic routine security assessments that adhered to the company’s security guidelines.
Worked with the risk and vendor management to design, implement, and manage Third-Party Risk Management (TPRM) processes to monitor, mitigate and report on risk from on-going third-party relationships, especially vendors and clients.
Conduct vendor risk assessments reviewing vendor provided reports like SOC2/ISO27001/PCI attestation report, and other third-party assessment reports to comply with contractual and regulatory requirements.
Maintained continuous monitoring of vendors between periodic due diligence reviews for issues and reported on risk issues to the vendor risk manager.
Categorize vulnerabilities based on their risk, focusing on critical and high-severity issues first. Consider the business impact and the ease of exploitation when setting priorities.
Review the results to identify false positives, which are instances where Nessus incorrectly flagged something as a vulnerability. Investigate and confirm the validity of each finding to avoid unnecessary remediation efforts.
Evaluated various SOC 2 reports to ensure it covered the specific services and controls relevant to the organization. Confirmed that the report addressed the systems and relevant time periods.
Examine the results of the auditor's testing of controls and address any control weaknesses or exceptions identified.
EDUCATION AND CERTIFICATIONS
NIST RMF and Security + Training - Immersion Tech Cyber Training Academy
Bachelor of Science in Business Admin. - Cape Coast University, Ghana.
CompTIA Security +