Rilwan Adigun
Newark, NJ * 917-***-**** * **********@*****.***
Senior Risk Assessment Analyst
Profile
Risk Professional with over 6 years’ experience in risk management, vendor governance and project management
Good Risk Assessment Knowledge
Familiarity with Risk & Control Frameworks (COBIT, ISO 27001, NIST)
Strong knowledge of risk policies in a regulated environment (OCC, FDIC, OFAC, FRB, CFPB, FFIEC, NYDFS)
Extensive experience in Process and control design, remediation, or improvement initiatives
Support and monitor employees on efforts to ensure compliance with all legal and policy requirements.
Technical Skills
Basic: MS Excel (Advanced), MS Word, MS PowerPoint, MS Visio
Other: SharePoint
Work Experience
Morgan Stanley. March 2022 - Present
New York, NY
Risk Consultant
Work with team to conduct impactful reviews (Audits, process evaluations, gap assessments etc.).
Supports Privacy Impact Assessment ("PIA") process (responsible for conducting end to end PIAs across Bank applications and Bank Vendors, leading/coordinating PIA conversations with stakeholders, ensuring PIA cases and results/finding are tracked properly).
Provides support in the Privacy Incident Management space.
Supports in creating Privacy related metrics for Management reporting purpos
Verizon Jul 2020 – Feb 2022
Basking ridge, NJ
Third Party Risk Analyst
•Completed operational risk assessments, and compliance risk assessments as a priority in my role.
•Assisted Businesses and coordinating with Subject Matter Specialist (SMS) risk teams to facilitate risk identification via the IRQ, assessment and documentation activities for Third Party products/services during the on-boarding process
•Oversaw Business and SMS team on-going monitoring activities including refreshing risk assessments, re-completion of due diligence activities and continued compliance with TPRM policies and procedures.
•Managed the enterprise TPRM policy, procedures, technology, reporting, tools and templates.
•Providing stakeholder guidance throughout the lifecycle and facilitating escalations regarding identified third party related risks or events.
•Cultivated strong ties with business and technology operations teams to manage software asset management activities, while closely collaborating with operations teams on key issues of accurate license entitlement data for software audits, worked closely with software vendors.
•Worked with Business Owners to ensure that Third Parties are classified based on inherent and residual risk for the products/services provided.
•Worked with SMS teams to facilitate due diligence risk activities and ensure coordination of efforts in a timely manner.
•Oversaw completion of Business on-going risk management activities and report on instances of non- compliance or other areas of concern.
•Facilitated issue escalation processes to ensure appropriate stakeholders and executives across the enterprise are involved based on defined risk thresholds.
•Aggregated KPIs, KRIs and other risk metrics through reporting and dashboards to stakeholders and leadership on a regular basis.
•Ensured businesses and TPRM stakeholders receive training regarding TPRM policies and procedures.
•Performed QC and QA on TPRM activities completed throughout the lifecycle.
•Oversight of third party data integrity and inventory management within the GRC Technology.
•Managed and administered TPRM Policy, Procedures, Tools and GRC Technology requirements.
•Performed other duties as assigned.
Google Dec 2018 – Jun 2020
New York, NY
Risk and Compliance Analyst
Developed and implemented security risk management wide risk strategy consistent with changing enterprise specific and industry wide risk and regulatory environment, and developed reports and scorecards, and implemented third party security risk management training program to educate staff.
Lead the design, implementation, maintenance, and enforcement of third party risk management policies, procedures, and controls.
Lead development and implementation of second line of defense Third Party Risk Management (TPRM) policies, processes and procedures across the enterprise to comply with regulatory requirements
Oversaw the execution of third party security risk management program in client engagements.
Provided oversight in the development and execution of third party security risk assessment criteria and client program.
Identified key program level metrics, e.g. key performance indicators (KPI) and key risk indicators (KRI).
Participated in sustainability assessments and assessed adherence to regulator, business and compliance requirements.
Partnered with other Embedded Risk Manager to identify best practices and monitor adherence to standard processes.
Assisted in the review of standards, policies, and procedures and performs rationalization per compliance guidelines.
Scotia Bank Aug 2018– Nov 2018
New York, NY
Corporate Risk Analyst
Cordinated, prepared, and reviewd regulatory submissions for domestic or international projects.
Ensured all vendors are classified and assessments completed in accordance with the VRM policy.
Ensured all vendor relationships are documented in the VRM system and all contracts related to vendors that provide outsourced services are uploaded in the system in accordance with the VRM policy
Reviewed services provided by vendor and define scope of assessment based on the SIG.
Defined appropriate risk levels and corrective actions.
Reported on assessment outcomes, risk level and associated recommendations.
Provided metrics on a regular basis (KPI / KRI).
Completed risk analysis for onsite assessments/remote assessments.
Cultivated strong ties with business and technology operations teams to manage software asset management activities, while closely collaborating with operations teams on key issues of accurate license entitlement data for software audits, worked closely with software vendors.
Improved and updated user access and permission on Windows server after review of Active Directory environment as per security policy.
Influenced and provided guidance to the business and other stakeholders to ensure requirements of VRM are fully understood.
Wells Fargo Oct 2016– Aug 2018
Jersey City, NJ
Risk Analyst
Coordinated with stakeholders to initiate, scope and plan controls assessments of new and existing vendor engagements.
Assessed completed questionnaire and supporting documentation to validate vendor appropriate implementation of information security controls.
Produced detailed documentation of assessments.
Communicated vendor information security issues to stakeholders, ensuring their understanding of associated risks and actions needed to remediate those risks.
Validated evidence from vendors before remediation plans are closed.
Escalated issues associated with vendors as needed to management.
Supported the VRM Program to effectively manage vendor risk in accordance with internal policy and regulatory requirements, ensuring strong oversight of all vendor risks and provide visibility of existing and emerging risks.
Maintained established relationships with the business and applicable stakeholders to ensure proper execution and compliance with VRM policies and procedures.
Assisted in the reporting of vendor risk management activities.
Promoted and delivered continuous training and awareness to Business partners on vendor risk.
BNY Mellon 2015– 2016
New York, NY Vendor Risk Analyst
Managed all classification programs for vendors and mitigation of vendor risk.
Worked with the appropriate business user and technology owner to ensure that for any identified risks that require mitigating action, a plan is developed and executed.
Assisted in the reporting of vendor risk management activities.
Provided analysis and recommendations for identified security exceptions; participated in defining remediation efforts.
Led and worked with team to secure / hardening of Application, Database, Linux and Windows servers and network components based on vulnerability analysis results.
Tested controls and identified deficiencies.
Ensured all vendors are classified and assessments completed in accordance with the VRM policy.
Ensured all vendor relationships are documented in the VRM system and all contracts related to vendors that provide outsourced services are uploaded in the system in accordance with the VRM policy.
Education & Training
M.Sc., Biochemistry – Kwara State University, Nigeria
B.Sc., Biochemistry – Kwara State University, Nigeria
Certified Third Party Risk Professional (CTPRP) – Shared Assessments
Certified in Risk and Information Systems Control (CRISC) – ISACA
Certified Information Security Manager (CISM) – ISACA
Certified Frontline Customer Service Professional