Post Job Free
Sign in

Information Security Risk Management

Location:
Lawrenceville, GA
Posted:
November 05, 2024

Contact this candidate

Resume:

SUMMARY

Talented GRC Analyst with **+ years of experience from Automotive and Document sectors. Implemented security measures and protected valuable data worth billions of dollars. Contributed technical skills in conducting several IT risk managements, security frameworks, and cybersecurity. Proven ability to manage complex technical systems, assess risks, and recommend security solutions.

PROFESSIONAL EXPERIENCE

Senior GRC Analyst

Toyota September 2019 – Present

●Lead Security in compliance maturity assessments and systems audits.

●Send and review security questionnaires tailored to different IT departments and kickoff the controls assessment and testing.

●Kickoff meeting with stakeholder, system and application owners to review the scope of control testing.

●Evaluates IT systems involving software, hardware, configuration, and proposed changes to ensure IT security posture in compliance with existing information security policies and regulations.

●Collect evidence to support implementation of system baseline security controls and perform analysis on evidence to ensure compliance with the System Security Plan (SSP) and risk management framework.

●Develop Security Assessment Plan (SAP) to conduct security assessment.

●Review the FIPS 199 Security Categorization of the overall impact level of systems using NIST SP 800-60.

●Identify gaps, develop remediation plans and trained on the HITRUST-CSF, SOX, GDPR, NIST,

HIPAA, ISO27001, PCI-DSS, COBIT, ITIL, TISAX and compliance activities and controls.

●Perform security assessment by testing information security controls.

●Develop Security Assessment Reports (SAR) to support accreditation packages.

●Subject matter expert to provide GRC guidance and interpretation of rules, regulations, risks, and best practices. Create and implement policies, procedures.

●Identify gaps, develop remediation plans, action plans and track findings until closing leveraging our risk register.

●Oversee risk assessment and due diligence processes and ensure they are properly performed in selecting new vendors.

●Assist in preparation of vendor assessment report and review security vendor questionnaire.

●Report all vendor findings in RSA Archer and track progress.

●Monitor Policies & Procedures and responsible for maintenance of the vendor risk management system.

●Provide support to various security teams and SMEs in various areas to ensure the risk management process is effective and generate compliance and risk metrix.

Information Security Analyst

XEROX June2013 – August 2019

●Conducted in-depth analysis of cybersecurity incidents, contributing to risk mitigation strategies.

●Performed the day-to-day security operations of systems and assessed the security controls employed within and inherited by the organization.

●Assisted with our company’s vulnerability management and reviewed vulnerability report.

●Reported all vulnerabilities on the risk register and communicated all findings to the appropriate owners.

●Oversaw the design, installation and monitoring of IT computing infrastructure.

●Conducted security awareness training and expected rules of behavior for end-users.

●Participated in security team meetings, rendered other support to IT Security office.

●Managed application tracking using Azure

●Conducted periodic gap analysis reviews of the internal Information Security program using industry standards such as National Institute of Standards (NIST).

●Understood and followed existing policies, procedures, work instructions, standards and made recommendations for continuous improvement.

●Researched, identified, and mitigated security threats to information systems.

EDUCATION

University of Lagos, Nigeria

Bachelor of Science, Computer Science

American InterContinental University

Master of Business Administration, Marketing

CERTIFICATIONS

●COMPTIA Security+

●Certified in Cybersecurity

●CISM

SKILLS

●Risk Management

●Internal and External Audit

●Vulnerability Management

●Third-Party Risk Management (TPRM)

●Compliance Maturity Assessment

●GRC (RSA Archer)

●POA&M

●Problem-solving

●Project Management

Teamwork



Contact this candidate