MARIE M WEEKS
Washington, DC *****• ************@*****.*** • +1-860-***-****
PROFESSIONAL EXPERIENCE
PNC Financial Services Group, Inc. (PNC Bank) — Pittsburgh, PA (Remote) C&IB Senior Risk Specialist Audit Liaison & Policy Exception Governance January 2024 – Present
• Execute the Line of Business Risk Management program, identifying areas for improvement, aligning with enterprise risk frameworks, and ensuring adherence to regulatory expectations.
• Lead the design and development of risk management programs, integrating business objectives with compliance requirements to strengthen operational resilience.
• Serve as the primary Audit Liaison for Internal Audits, External Audits (regulatory/third-party), IT Application Audits, and quarterly Continuous Audit Requests; consistently achieve 100% on-time delivery with zero repeat findings.
• Manage the Continuous Audit cycle, coordinating quarterly evidence submissions and stakeholder engagement, which reduced recurring audit rework by 30% and improved audit readiness posture.
• Prepare and present monthly executive summary reports to senior leadership, consolidating internal/external audit results, remediation timelines, and policy exception reviews into actionable insights that improved oversight by 40%.
• Oversee risk assessments, control self-evaluations, and quality reviews, ensuring risks are identified, escalated, and remediated with minimal business impact.
• Drive business-as-usual (BAU) risk initiatives, analyzing emerging risks, recommending solutions, and enhancing governance processes, which reduced overdue remediation items by 20%.
• Lead the Policy Exception (PE) process, coordinating annual refresh activities to validate extension requests, confirm remediation efforts, and require justification for continued risk acceptance when no remediation occurs, reducing undocumented extensions by 25%.
• Evaluate and manage third-party vendor risks, ensuring alignment with security, business continuity, and regulatory requirements.
• Collaborate with Compliance, Credit, Legal, and Technology stakeholders to strengthen accountability, improve cross- functional governance, and mitigate risks more effectively.
• Utilize risk registers, heat maps, and control matrices to track, monitor, and communicate risks, providing senior leadership with clear visibility into exposures and remediation progress. Mitsubishi UFJ Financial Group (MUFG) – Jersey City, NJ (Remote) Senior Technology Risk Officer Issues and Findings Management January 2023 – December 2023
• Lead examinations and findings assessment from Second Line of Defense (SLoD), Third Line of Defense (TLoD), and regulators, effectively aligning resources for remediation. Manage the end-to-end review process, actively contributing to resolving 15% of identified issues while ensuring policy adherence and improving control effectiveness.
• Monitored and tracked remedial actions, conducting regular progress meetings resulting in a remarkable 45% increase in action completion rate. Address challenges proactively, ensuring timely resolutions and providing comprehensive updates to senior management.
• Drive cross-business risk management initiatives and identify automation opportunities to enhance processes. Collaborate on technology risk governance protocols, consistently upholding SLoD policies and delivering excellent presentations for team meetings.
• Work closely with Risk Analysts to evaluate findings, resulting in a notable 25% decrease in data discrepancies by implementing improved validation methods.
• Deliver 'How-to' training sessions on the Archer Findings Module, substantially improving team competency and process efficiency.
• Utilize SharePoint to meticulously document, track, and communicate policy exception requests, ensuring precision and alignment with stakeholders. Maintain transparent communication channels with senior management, offering comprehensive updates on technology risk governance and remediation efforts.
• Develop and manage a Technology Findings Dashboard, categorizing open and closed findings, including those with remediation plans, observations, and canceled/rejected findings. Implement a reporting system for tracking findings as issues and observations, effectively managing current and past-due items.
• Develop over 12+ business-approved documentation surrounding Vulnerability Management / Patch Management Standards, Information Security Policy, Variance / Exception Policy, RACIs, step-by-step workflows, and Standard Work for remediation.
Intesa Sanpaolo – New York, NY
Senior Cybersecurity and Business Continuity Specialist November 2019 – December 2022
• Provided direct support to the CISO on division-wide matters and addressed priority impacts to company operations, assets, and information for the continued development of the organization’s cybersecurity program and the planning and implementation of security and business continuity measures.
• Reviewed policies and procedures to ensure alignment with updated applicable regulatory requirements and industry best practices.
• Managed cybersecurity threats, risks, and issues through effective governance and compliance with local (NYSDFS Part 500) and federal (FRBNY) regulations.
• Collaborated with Head Office Cybersecurity teams to develop strategic goals relevant to the local New York branch requirements.
• Organized and supported Microsoft Security and foundational compliance center rollout and assisted in integrating Azure Information Protection for email security.
• Facilitated technical / non-technical teams to dissolve 500+ threats and vulnerabilities, remediate criticalities, and maintain best practices.
• Removed over 15,000 security vulnerabilities in a single month by configuring and optimizing the QualysGuard Vulnerability Scanner to identify system security flaws on critical systems. This reduced risks and allowed the company to be PCI DSS compliant.
• Led Third Party Vendor Due Diligence efforts involving the utilization of the CSA CCM (Cloud Controls Matrix) to assess third-party vendors for compliance and proper auditing procedures.
• Performed Data Handling and Classification assessments to maintain the division’s regulatory compliance standpoint by delegating Data Owners, organizing risk metrics through PCI and SOC1&2, and developing Data Retention solutions.
• Communicated regular status updates, such as executive-level communication to governing committees and head office leadership.
• Interfaced with regulatory auditors during examinations to review audit artifacts and respond to inquiries.
• Analyzed and revamped to establish security processes and internal workflows across 3+ business groups, including Splunk notifications, log analysis, Qualys configurations, penetration testing scheduling, and threat modeling.
• Conducted annual BIA exercises to accurately document critical and mission-essential processes, dependencies, RTOs, RPOs, and MTOs.
• Coordinated and observed Business Continuity and Disaster Recovery exercises to ensure BC plans, call trees, critical persons, and relevant back-ups were documented and evaluated annually.
• Developed overall training and awareness plans and newsletters to keep branch personnel abreast of relevant emerging risks and pertinent security topics.
• Increased compliance with regulatory requirements by 20%, backed by the following data: implementing, reporting, escalating processes for missing training, and preliminary mitigation plans. KBC Bank – New York, NY
Senior Risk Analyst January 2016 – October 2019
• Performed security event monitoring, including collecting, reviewing, and analyzing audit logs to identify anomalies.
• Conducted thorough reviews of user access rights and managed identity in various systems, including applications, operating systems, databases, and network components.
• Collaborated with key organizational stakeholders in Information Technology (IT) and Business departments.
• Supported the Chief Information Security Officer (CISO) with various Ad Hoc security-related topics.
• Vetted third-party vendors using the Consensus Assessment Initiative Questionnaire (CAIQ) and Security Information Gathering (SIG) methodologies.
• Audited third-party vendors' security controls utilizing the Cloud Controls Matrix (CCM) and documented exceptions in SOC2 Type 1 and Type 2 reports.
• Generated daily reports using Citrix applications such as Surety, Splunk, Prime, and E-gifts.
• Worked closely with the IT department to monitor device inventory, oversee patching processes, and manage ticketing systems.
• Conducted comprehensive vendor reviews employing due diligence checklists and Dun & Bradstreet data.
• Facilitated requirement-gathering workshops with stakeholders, including site visits, to elicit and document functional and non-functional requirements for business process improvements.
• Prepared and documented status reports, created presentations, performed analyses, and organized content for team collaboration.
• Reviewed and enhanced existing IT business processes for optimization and ensured adherence to change processes and compliance standards.
• Managed and tracked the change control process for requirements and design modifications, documenting changes, issues, and their impact on system design and delivery.
• Provided support in computer network exploitation and defense techniques, focusing on deterring, identifying, and investigating computer and network intrusions.
• Maintained proficiency in open and closed-source computer exploitation tools, attack techniques, procedures, and trends.
• Supported continuous monitoring, computer exploitation, and reconnaissance efforts. Wells Fargo – Charlotte, NC
Information Security Risk and Control Analyst June 2014 – December 2015
• Provided direct support to the CISO in implementing, designing, testing, and continuously monitoring security and IT controls.
• Performed assessment of security controls in the environment to determine effective risk mitigations, identify gaps, and prioritize actions to drive program maturity.
• Expanded compliance with regulatory requirements by 30% and is supported by the following data: implementing, reporting, and escalating processes for continuous control monitoring.
• Acted in an advisory role to business units and Information Technology to ensure secure network architecture controls and secure development practices controls were appropriately developed, documented, and performed.
• Developed control test scripts based on control purpose, description, details, and business partner walk-throughs.
• Designed continuous monitoring KCIs to provide business partners with relevant information for adherence to key and high-risk controls.
• Documented and identified issues during control testing and monitored progress until remediation and closure. Interfaced with regulatory auditors during examinations to review audit artifacts and respond to inquiries related to control assessments and testing.
• Performed design testing for newly identified and written controls to evaluate all appropriate elements captured and implemented.
• Executed control testing every quarter and captured evidence of test completion for regulatory compliance. Common Spirit Health – Phoenix, AZ
Cyber Security Analyst/Lead Vulnerability Management Analyst February 2010 – May 2014
• Developed standardized guidance, methodologies, and tracking documentation for Nexpose Rapid7, ensuring efficient and effective vulnerability management.
• Spearheaded the Vulnerability Management Program, implementing strategic initiatives to lower critical risk ratings and thwart threat actors targeting healthcare system vulnerabilities.
• Orchestrated the remediation efforts for over 12.7 million vulnerability findings across Rapid7, Cycognito, and SecurityScorecard platforms.
• Conducted monthly network scans utilizing Rapid7 Nexpose, identifying an average of 175 vulnerabilities per scan across 500+ devices, showcasing adept analytical and problem-solving skills.
• Managed a complex ticket queue, successfully resolving 90% of high-complexity issues within SLA timeframes, demonstrating exceptional prioritization and issue-resolution skills.
• Provided expert guidance for 1450+ vulnerability cases, achieving a remarkable 98% remediation rate within agreed timelines, highlighting meticulous attention to detail and strategic planning abilities.
• Collaborated with cross-functional teams, including Security Engineering, Identity Management Engineering, and other key IT departments, ensuring seamless team-related engagement and fostering enhanced communication skills.
• Expertly handled Information Security vulnerability and configuration issues, efficiently managing tickets of varying complexity with precision.
• Delivered exceptional vulnerability and configuration remediation, engagement, and escalation support, significantly enhancing service line performance and customer satisfaction.
• Collected, tracked, and reported quality metrics across clinical operations, producing timely and accurate reports for leadership and regulatory bodies (CMS, internal audits).
• Resolved critical data discrepancies impacting patient and provider reporting, improving data trust and boosting satisfaction by 20%.
• Partnered with multidisciplinary healthcare teams, presenting dashboards, graphs, and variance reports to identify care gaps and recommend improvements.
• Supported a data-driven healthcare culture by providing ad hoc reports and investigative analysis that influenced process efficiency and care quality initiatives.
EDUCATION
Missouri State University – Springfield, MO
o Master Of Science, Cybersecurity 2024– Present BlueCrest College – Accra, Ghana
o Bachelor of Science in Information Technology
CERTIFICATIONS
• Certified Information Security Manager (CISM) - Active
• Certified in Risk and Information Systems Control (CRISC) - Active
• CompTIA Security+ CE - Active
• CompTIA Cybersecurity Analyst (CySA+) - Active
• Certified Qualys Specialist– Active
• Certified Scrum Master CompTIA (CSM) Certified - Active
• Professional Scrum Product Owner (PSPO) Certified- Active TECHNICAL SKILLS
Tools & Platforms: Tenable Nessus, Qualys, OpenVAS, Rapid 7 Nexpose, Splunk, XSOAR, LogRhythm, Exabeam, RSA Archer GRC, ZenGRC, Surety, Tanium, McAfee Total Protection, TrendMicro, IBM Tivoli. Web Inspect, JIRA, Confluence, MS Project, ServiceNow, KnowB4, IPVOID, MX Toolbox, MS SQL Server Reporting Services Microsoft Office Suite: Proficient in Word, Excel, PowerPoint, Access, Outlook