ABIGAIL O. JENKINS
Laurel MD ***** 240-***-**** *****************@*****.***
Professional skills and Summary
Results-driven and knowledgeable Information System Privacy Security Officer (ISSO) and Governance, Risk, and Compliance (GRC) specialist with over 7 years of proven experience implementing and enforcing Risk Management Framework (RMF) methodologies. Adept at safeguarding information systems by applying industry best practices to ensure the Confidentiality, Integrity, and Availability (CIA) of enterprise environments. Demonstrated expertise in assessing and implementing NIST SP 800-series security controls aligned with FIPS 199 categorizations and managing key deliverables such as System Security Plans (SSPs), POA&Ms, PTAs, PIAs, and ATO packages, ISO 27001, and SOC 2, ensuring systems are audit-ready, risk-aware, and business-aligned. Skilled in Security Assessment and Authorization (SA&A), Certification & Accreditation (C&A), vulnerability management, patch management, incident response, contingency planning, and business impact analysis. Proficient in leveraging tools such as CSAM, RSA Archer, eMASS, Nessus, and Tenable to support compliance, risk mitigation, and continuous monitoring.
Competence &Tools
•Federal security regulations, standards, and processes including FISMA, FIPS199, 200, NIST 800-Special Publication series rev5, and FedRAMP
•Curating and updating system documentation. i.e., SSP, PTA, PIA, SIA, BIA, RA, SAP, SAR, POA&Ms, etc
•ISO 27001, CMMC, GCC
•HIPPA, SOPs, Security policy documentation
•Vulnerability assessments, Audit log reviews
•Archer, Xacta, CSAM, Azure
•Nessus
•Strategic Analysis
•Creative, detail-oriented reporting and updates
•Expert Client advising and education
Experience
Information System Privacy Officer, Governance Risk and Compliance (ISPO/GRC SME)
Koniag Government Services- Chantilly, VA
November 2020 – Present
•Conduct readiness assessments and gap analyses for CMMC Level 2, aligning controls with NIST 800-171 requirements and providing executive leadership with strategic remediation plans and compliance roadmaps that improved audit preparedness and reduced potential contract risk exposure by over 40%.
•Guide stakeholders through CMMC practices and processes, enhancing maturity scores and reducing compliance risks while collaborating with DoD contractors to implement CMMC-aligned policies for access control, incident response, and risk management.
•Develop and implement System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and security control documentation in coordination with RMF and DFARS 252-***-**** requirements, ensuring contractor eligibility for DoD contracts under CMMC guidelines.
•Lead full lifecycle Certification & Accreditation (C&A) and Security Assessment & Authorization (SA&A) for multiple moderate and high-impact federal systems, ensuring compliance with NIST SP 800-53 Rev 5, FISMA, and agency-specific standards, resulting in successful ATO approvals with zero major audit findings.
•Develop and maintained complete C&A documentation packages including System Security Plans (SSPs), Security Assessment Reports (SARs), and POA&Ms, aligning control implementation with FIPS 199 categorizations and streamlining audit readiness for recurring reviews.
•Partner with system owners, ISSMs, and assessors to remediate control deficiencies identified during C&A activities, achieving a 90% POA&M closure rate within required deadlines and strengthening overall security posture.
•Lead privacy and security assessments of Administration for Strategic Preparedness and Response (ASPR) systems under the Health and Human Services (HHS), OpDiv ensuring compliance Privacy Impact Assessments (PIAs), Privacy Threshold Analyses (PTAs), and System of Records Notices (SORNs) were met ensuring legal compliance and transparency in data use.
•Serves as the Privacy POC on cross-functional security and compliance teams at HHS, interpreting and applying OMB Circular A-130, NIST SP 800-53 (Rev. 5), ensuring compliance with the Privacy Act of 1974, the E-Government Act of 2002, and HHS Privacy Threshold Analyses (PTAs) to safeguard sensitive PII and ePHI across cloud-hosted platforms and shared services.
•Conduct in-depth PII inventories, Data Mapping, and Records Management reviews for systems handling sensitive and health-related data (e.g., HIPAA, 42 CFR Part 2) paying attention to Privacy Controls, NIST SP 800-122, and OMB Circular A-130.
•Interpret and applied major data privacy regulations—including GDPR, and CCPA—across enterprise systems, ensuring compliant handling of consumer data, minimizing legal exposure, and supporting business units with policy alignment and regulatory audits.
•Conduct in-depth data flow mapping and privacy risk assessments for enterprise applications and health data systems, integrating privacy controls into the RMF lifecycle, and ensuring all privacy risks were addressed during ATO (Authorization to Operate) reviews.
•Conduct risk-based gap analyses and internal audits, providing executive leadership with strategic remediation plans and compliance roadmaps that improved audit preparedness and reduced potential contract risk exposure by over 40%.
•Provide executive-level guidance on data sharing agreements (DUAs, BAAs) and breach response, including coordinating incident response with HHS OCIO and OCR, ensuring timely breach notification and documentation in alignment with federal mandates and HHS incident handling procedures.
•Manage and tracked POA&Ms across multiple information systems, ensuring timely remediation of security vulnerabilities in alignment with NIST SP 800-53 and agency-specific compliance requirements.
•Collaborate with system owners and engineers to develop actionable POA&M entries, assign remediation responsibilities, and validate corrective actions, resulting in a 90% closure rate within required deadlines.
•Provide weekly POA&M status reports to senior leadership and AOs, highlighting risk trends, unresolved issues, and system impact assessments to support continuous monitoring and accreditation decisions.
•Configure and maintain continuous monitoring workflows in Xacta to track vulnerabilities, remediation, audit status and automate control inheritance, assessment results, and POA&M tracking across enterprise environments.
ISSO/Audit SME
Tetra Tech – Washington, DC
July 2018 – November 2020
•Assisted in developing and improving cybersecurity capability while leading project to develop tracker for OIG audit deficiencies for the office of the secretary ensuring that vulnerabilities were mitigated in a timely fashion.
•Composed software and hardware inventory spreadsheets to create awareness of tools that need to be updated or disposed.
•Oversaw Security Assessment and Authorization packages to determine management, operational and technical controls are in compliance with the NIST SP 800-53 standards and guidelines.
•Managed gap analysis to reveal misalignment between standards of procedures (SOP) and policies according to NIST 800 53 criteria.
•Developed audit activity PowerPoints and spreadsheets for CISO council review while assisting to create system security plans (SSPs) for moderate systems.
•Performed Agency FISMA audits to ensure that security controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirement for the systems, including information technology products and services used in security control.
•Led a project that developed a comprehensive tracking tool for audit deficiencies, ensuring timely mitigation of vulnerabilities identified by the Office of Inspector General (OIG).
•Facilitated security assessments, vulnerability scans, and continuous monitoring activities, ensuring operational and technical controls meet required standards.
•Collaborated with technical teams to interpret intrusion events and formulate risk mitigation strategies using ArcSight SIEM.
•Managed Audit platform deployment (RSA Archer) across global operations, integrating 200+ risk and compliance controls
•Oversaw internal audit readiness for SOX and GDPR compliance; led remediation for over 50 control gaps.
•Drafted and maintained over 25 policies and standards covering access management, encryption, and data retention.
•Maintained regulatory requirements while managing and facilitating information security assessment continuous monitoring activities.
Information Technology Control Assessor
/Security Engineer
Nov 2017 – July 2019
BRTRC - Washington-DC
•Analyzed and made recommendations on policy, governance, and procedural changes to identify and reduce transmission cyber risk commensurate with evolving industry best practices and standards.
•Utilized NIST SP 800 53-A to assess security controls every fiscal year during my contract for 6 moderate, 3 high and 2 low systems.
•Coordinated meetings with stakeholders to review POA&M’s that were created as a result of assessment and also to guide on document retrieval to satisfy control requirements.
•Provided a detailed assessment on the severity of discovered weaknesses in the information system and it’s operation environment ensuring that resolution suggestions were given for identified vulnerabilities.
•Updated and composed documentation including but not limited to; contingency plans, configuration management plans, incident response plans, security assessment reports residual risk reports, risk threat matrix reports.
•Identified security integration issues related to the implementation of new systems within the existing infrastructure; recommend mitigation and/or resolution options.
•Proposed mitigation plan measures and timelines for vulnerabilities and compliance incidents
•Played key role as subject matter expert in ensuring security baseline met command cyber criteria for excellent rating during security audit. Guided leadership, peers and subordinates in tactics techniques and procedures.
Education
Bachelor of Science, Information Technology
Methodist University of Ghana
CompTIA Security +
Certified Authorization Professional (CAP)