Post Job Free
Sign in

GRC Analyst - Cybersecurity Risk & Compliance

Location:
Manhattan, NY, 10007
Posted:
July 27, 2026

Contact this candidate

Resume:

Morris T. Mend

GRC Analyst

**** ********* ** ** ******* Georgia 30354 • +1-470-***-**** • ************@*****.***

Professional Summary

Results-driven Governance, Risk, and Compliance (GRC) Analyst with 3+ years of experience in cybersecurity and environmental policy. Skilled in managing compliance programs across ISO 27001, PCI-DSS, NIST, GDPR, HIPAA, and SOX. Expertise in risk assessments, security policy enhancement, and gap analysis. Proficient in RSA Archer, ServiceNow, Nessus, and QRadar for incident management and compliance tracking. Collaborates with cross-functional teams to strengthen risk frameworks, reducing incident response times by 30% and improving compliance by 15%.

Skills

Security Tools: Splunk, ArcSight, RSA Archer, QRadar, Nessus, Qualys, OpenVAS, Nmap, Wireshark, Firewalls, IDS/IPS

Incident Management: ServiceNow, Jira

Frameworks and Compliance Standards: NIST AI RMF, ISO/IEC 24029, PCI-DSS, ISO 27001, GDPR, HIPAA, SOX, FedRAMP, HITRUST, SOC I, SOC II, TPRM

Risk & Compliance: Risk Assessments, Vendor Risk Management, Gap Analysis, Control Testing

Cybersecurity: Incident Response, Threat Intelligence, Vulnerability Management

Soft Skills: Analytical Thinking, Cross-functional Collaboration, Communication, Organization

Other Tools: Tableau, Jira, Smartsheet, Salesforce, Microsoft Office Suite

Experience

Governance, Risk and Compliance (GRC) Analyst, 02/2023 to Current

Vision Atlantic LLC

Updated at least 10 cybersecurity policies, standards, and procedures annually, ensuring 100% alignment with industry best practices and regulatory requirements.

Performed quarterly gap analyses, closing identified non-compliance issues within 30 days to maintain compliance.

Oversaw compliance with relevant regulations (GDPR, HIPAA, PCI DSS) and industry standards to safeguard organizational data.

Conducted security risk assessments for 10 or more new vendors annually, ensuring adherence to security policies, and reducing vulnerabilities.

Conducted regular audits of Splunk logs to ensure accuracy and compliance with regulatory frameworks, such as PCI-DSS, HIPAA, and NIST, enhancing the organization's overall security posture.

Developed custom Splunk alerts and reports for critical compliance metrics, facilitating a reduction in incident response time by 30%, and supporting GRC requirements.

Strengthen risk management frameworks by 25%, aligning with NIST Special Publication 800 series and ISO standards.

Monitored vendor performance, achieving 95% adherence to security KPIs, KRIs, and SLAs, improving security posture.

Leveraged GRC tools like RSA Archer and ServiceNow to track and manage security incidents, reducing incident response time by 30%.

Identified control deficiencies during SOX audits, collaborating with stakeholders to develop corrective actions and improve control frameworks.

Evaluated assessment artifacts to verify compliance with NIST SP 800-53 Rev 4 control requirements.

Reviewed the effectiveness of existing controls by examining security questionnaires, independent audit reports (SOC 2, HITRUST, ISO), and artifacts, ensuring vendor compliance.

Compliance Analyst, 08/2022 to 01/2023

DeKalb County School District

Worked closely with cross-functional teams to foster a culture of compliance, and ensure that governance policies were effectively implemented across the organization.

Led the SOC II audit process and achieved an approximately 80% compliance rate with no major findings.

Collaborated with the cybersecurity team to leverage Splunk's threat intelligence capabilities, aiding in the improvement of vendor risk management processes and incident investigation efficiency.

Designed and implemented risk management frameworks, aligning with regulatory requirements (SOX, GDPR, PCI-DSS), to strengthen organizational security posture.

Spearheaded the enhancement of compliance monitoring processes, leading to a 15% increase in regulatory adherence across different departments.

Collaborated with cross-functional teams to establish and enforce security policies and procedures, ensuring alignment with industry standards (NIST, ISO 27001), and organizational goals.

Supported HIPAA compliance program implementation and maintenance, ensuring adherence to regulatory requirements across the organization.

Senior Quality Inspector, 02/2019 to 01/2022

Protolabs

Led the development and qualification of test methods, data sheets, equipment/fixtures, and visual standards in support of new and existing processes to demonstrate capability

I was responsible for recording, verifying, interpreting, process monitoring, testing, comparing to known specifications and criteria

Trended, identified, prioritized, resolved and reported quality issues using information gained from testing and other process monitoring activities, Non-Conforming Events (NCE) and development of Corrective Actions, continuous improvement projects and other quality metrics

Defined training requirements for test methods and work instructions

Identified best quality practices and areas for improvement and lead continuous improvement projects across the plant;

Used documentation systems to research information and generated Change Request

Senior Financial Analyst, 05/2017 to 01/2019

P & D LLC. MN

Led monthly financial forecast process for key business units or core departments

Conducted financial analysis of potential new products, pricing strategies, and strategic opportunities

Analyze financial statements for discrepancies and alert the CFO if necessary.

Created and maintained management reporting packages

Coordinate semi-annual audits and assist the CFO in running audits.

Reconcile accounts monthly to ensure accurate reporting and ledger maintenance.

Maintained Hyperion financial system which supports budget and forecast processes

Project Accountant, 06/2017 to 12/2017

J Max Group of Company – MN,

Created project accounts in the accounting system

Maintained project-related records, including contracts and change orders

Reviewed and approved overhead charges to be applied to a project

Reported on project profitability to management

Reported to management regarding expenditures and funds balance for projects

Approved all project-related billings to customers

Documents and records vendor invoices, purchase requisitions, and other transactions; verifies amounts due and pays in accordance to payment terms.

Compile information for internal and external auditors, as required

Prepared and interprets cost accounting reports to project managers and senior management (i.e. encumbrance reports, project reconciliation, status logs, etc.).

Audit Consultant, 07/2015 to 01/2017

Robert Half – MN

I was responsible to plan and conduct audit in compliance the Generally Accepted Auditing Standards (GAAS)

I was responsible to rectify in a timely fashion and evolve new methods for improving the efficiency and effectiveness of the audit process.

Reviewed of audit files in line with GAAS and GAAP

Provided assurance on the auditor's general reports

Developed audit methodology, audit procedures, audit template and audit program.

Certifications

CompTIA Security+

Quality Control and Assurance

Financial Statement Audit

Government Auditing

IT Auditing &GRC

Education

Bachelor of Business Administration (BBA): Accounting, 12/2011

Master of Business Administration (MBA), 07/2017

Master of Science: Accountancy, 10/2018



Contact this candidate