HYATTSVILLE, US, ***** • **********@*****.*** • 202-***-****
ISHMAEL AGHANIFOR
Data Risk Analyst
PROFESSIONAL SUMMARY
Experienced Data-driven GRC Analyst with 12+ years of expertise in data risk management, compliance, and governance. Proven ability to implement regulatory frameworks (GDPR, HIPAA, CCPA, SOX, ISO27001) and security standards (NIST, SOC 2, HITRUST) to enhance data privacy, integrity, and regulatory adherence. Successfully led audits resulting in a 98% compliance rate and developed mitigation strategies that reduced security incidents by 30%. Skilled in leveraging GRC tools
(ServiceNow, Archer, OneTrust) and data analytics platforms (Excel, Power BI, Tableau) to deliver actionable insights. Known for translating complex technical risks into clear guidance for non-technical audiences and driving operational improvements through automated compliance solutions.
EMPLOYMENT HISTORY
TEACH MATHEMATICS AND QUANTITATIVE MODELLING Aug 2024 - Present Prince Georges County Public Schools (PGCPS) Hyattsville, MD
• Teach students how to model scenarios and make data-driven decisions.
• Integrate Real-World Financial Data Sets using authentic data from stock markets, bank reports, consumer credit data, or insurance datasets.
• Apply Descriptive & Inferential Statistics for Financial Decisions, focusing on statistical techniques used in risk assessments and financial forecasting.
• Model Data Risk and Governance Scenarios, simulating scenarios involving data classification, data integrity, and data privacy in a financial context.
• Teach Dashboard Creation and Data Visualization, assigning projects where students use Excel or Google Sheets to create dashboards showing KPIs, trends, or profit/loss analysis.
• Use Spreadsheet Modelling for Business Scenarios, teaching linear programming, break-even analysis, or compound interest with spreadsheet simulations.
• Emphasize Forecasting and Trend Analysis using time-series data to forecast earnings or loan repayment.
• Discuss Regulatory Frameworks Briefly, introducing students to basic regulatory concepts like SOX, GDPR, or HIPAA in a financial-data context.
• Promote Problem Solving with GRC Context, including case studies or role-play on decision-making during financial or compliance audits.
• Simulate Data-Driven Decision Making using financial scenarios where students must decide on investments, loans, or insurance policies using risk and return metrics.
GRC ANALYST Dec 2023 - May 2024
ExcelMindCyber Chicago, IL
• Develop and implement a comprehensive risk assessment framework, achieving a 20% reduction in operational risks.
• Enhance compliance monitoring processes, yielding a 15% improvement in regulatory adherence.
• Conduct internal audits to identify and mitigate compliance gaps, leading to a 30% decrease in exposure to fines and penalties.
• Streamlined compliance reporting processes, enhancing efficiency and achieving noticeable results in regulatory audits and assessments.
DATA RISK COMPLIANCE MANAGER Jan 2023 - Dec 2023
Nemlig.com Remote
• Directed control evaluation tasks encompassing risk assessment, ongoing testing of transactional key controls, and review of IT general controls, achieving a 95% accuracy rate in control identification and documentation.
• Conducted detailed audits to ensure compliance, leading to substantial improvements in operational efficiency and risk mitigation.
Introduce Common Tools Used in Industry, providing exposure to Excel, Google Sheets, or even Power BI basics for financial data manipulation.
Facilitated data-driven decision-making simulations, guiding students to assess investment risks and returns through practical financial scenarios.
• Implemented robust compliance frameworks, enhancing data integrity and fostering trust with stakeholders through improved transparency.
• Coordinated cross-functional teams to streamline data governance practices, achieving marked gains in operational efficiency and risk awareness.
THIRD PARTY DATA RISK ANALYST Jan 2021 - Dec 2022
Swedish Bank Remote
• Analysed market trends and regulatory changes to advise senior management on potential risks, contributing to a 10% improvement in strategic decision-making.
• Coordinated client discussions to establish GRC program and technology vision and strategy, review, design and develop functional and technical requirements, and define solution architecture.
• Led the design and implementation of a comprehensive data risk management strategy, resulting in strengthened compliance and reduced vulnerabilities.
• Conducted thorough assessments of third-party data risks, enabling proactive mitigation strategies and enhancing overall security posture.
BUSINESS DATA COMPLIANCE ANALYST Feb 2017 - Dec 2020 Prisma Safe Ab (SWEDAF) Remote
• Managed and completed all third-party certifications and audits (SOX, HITRUST and SOC 2) with a 100% compliance rate, ensuring adherence to industry standards and regulations while minimizing audit cycle time by 15%.
• Enhanced data reporting processes by implementing advanced analytics tools, leading to more accurate insights and informed decision-making across departments.
• Conducted thorough data integrity assessments, identifying inconsistencies that led to measurable improvements in data quality and reliability.
• Streamlined data integrity assessments, enhancing data quality and reliability while fostering strong stakeholder trust. IS AUDIT AND RISK CONTROL CONSULTANT Dec 2014 - Jan 2017 Karlstad and Orebro Universities Sweden
• Cooperated with stakeholders to assess and analyse the university’s e-LMS System and environment, identifying significant gaps and weaknesses, resulting in a 15% reduction in high-risk areas within 6 months.
• Coordinated end-to-end analysis to determine root causes of infiltrations, ensuring proper design and operation of controls, resulting in a 20% decline in control break occurrences in one year.
• Performed ongoing analysis of program-related data and generated ad-hoc reports to support business related programs and strategies, resulting in a 25% improvement in decision-making efficiency and accuracy. IT DATA BUSINESS ANALYST Sep 2009 - Dec 2014
Prolog Orebro, Sweden
• Gathered, analyzed, and reported data findings from Customer Data.
• Performed analysis on information governance related topics, laws, and regulations.
• Developed comprehensive business cases that secured stakeholder buy-in, resulting in successful project implementations.
• Facilitated cross-departmental meetings to align data governance strategies, strengthening compliance and operational efficiency.
EDUCATION
MBA FOCUS ON ACCOUNTING AND CONTROL
Dalarna University School of Technology Sweden
MSC ECONOMICS AND ECONOMETRICS Nov 2014
Orebro University Sweden
MSC IN INFORMATION TECHNOLOGY (INFORMATICS)
Swedish Business School Orebro University Sweden
BACHELOR OF SCIENCE IN ECONOMICS Oct 2004 - Oct 2007 University of Buea Cameroon
SKILLS
Governance, Risk & Compliance, Policy & Procedure Development, Risk Assessment & Mitigation, Vulnerability Assessment, Strategic Compliance Management, ServiceNow, RSA Archer, Black Kite, Regulatory Compliance, GRC Framework Implementation, Stakeholder Engagement, Security Architecture Design, Risk Management, IT Auditing. GAAP, Accounting and Reporting.
LANGUAGES
English (Native), French (Highly proficient), Swedish (Novice). LINKS
LinkedIn: www.linkedin.com.
ADDITIONAL INFORMATION
CERTIFICATIONS
• ISACA, CRISC Certifications. Certified Risk and Information Systems Control (CRISC)
• ISACA Certified Information Systems Auditor (CISA)
• JOBSHOP Certificate in HR/Personnel Management and Customer Care
• BRAINEST Industrial Training Certificate in Accounting