Morris T. Mend
GRC Analyst
**** ********* ** ** ******* Georgia 30354 • +1-470-***-**** • ************@*****.***
Professional Summary
Results-driven Governance, Risk, and Compliance (GRC) Analyst with 3+ years of experience in cybersecurity and environmental policy. Skilled in managing compliance programs across ISO 27001, PCI-DSS, NIST, GDPR, HIPAA, and SOX. Expertise in risk assessments, security policy enhancement, and gap analysis. Proficient in RSA Archer, ServiceNow, Nessus, and QRadar for incident management and compliance tracking. Collaborates with cross-functional teams to strengthen risk frameworks, reducing incident response times by 30% and improving compliance by 15%.
Skills
Security Tools: Splunk, ArcSight, RSA Archer, QRadar, Nessus, Qualys, OpenVAS, Nmap, Wireshark, Firewalls, IDS/IPS
Incident Management: ServiceNow, Jira
Frameworks and Compliance Standards: NIST AI RMF, ISO/IEC 24029, PCI-DSS, ISO 27001, GDPR, HIPAA, SOX, FedRAMP, HITRUST, SOC I, SOC II, TPRM
Risk & Compliance: Risk Assessments, Vendor Risk Management, Gap Analysis, Control Testing
Cybersecurity: Incident Response, Threat Intelligence, Vulnerability Management
Soft Skills: Analytical Thinking, Cross-functional Collaboration, Communication, Organization
Other Tools: Tableau, Jira, Smartsheet, Salesforce, Microsoft Office Suite
Experience
Governance, Risk and Compliance (GRC) Analyst, 02/2023 to Current
Vision Atlantic LLC
Updated at least 10 cybersecurity policies, standards, and procedures annually, ensuring 100% alignment with industry best practices and regulatory requirements.
Performed quarterly gap analyses, closing identified non-compliance issues within 30 days to maintain compliance.
Oversaw compliance with relevant regulations (GDPR, HIPAA, PCI DSS) and industry standards to safeguard organizational data.
Conducted security risk assessments for 10 or more new vendors annually, ensuring adherence to security policies, and reducing vulnerabilities.
Conducted regular audits of Splunk logs to ensure accuracy and compliance with regulatory frameworks, such as PCI-DSS, HIPAA, and NIST, enhancing the organization's overall security posture.
Developed custom Splunk alerts and reports for critical compliance metrics, facilitating a reduction in incident response time by 30%, and supporting GRC requirements.
Strengthen risk management frameworks by 25%, aligning with NIST Special Publication 800 series and ISO standards.
Monitored vendor performance, achieving 95% adherence to security KPIs, KRIs, and SLAs, improving security posture.
Leveraged GRC tools like RSA Archer and ServiceNow to track and manage security incidents, reducing incident response time by 30%.
Identified control deficiencies during SOX audits, collaborating with stakeholders to develop corrective actions and improve control frameworks.
Evaluated assessment artifacts to verify compliance with NIST SP 800-53 Rev 4 control requirements.
Reviewed the effectiveness of existing controls by examining security questionnaires, independent audit reports (SOC 2, HITRUST, ISO), and artifacts, ensuring vendor compliance.
Compliance Analyst, 08/2022 to 01/2023
DeKalb County School District
Worked closely with cross-functional teams to foster a culture of compliance, and ensure that governance policies were effectively implemented across the organization.
Led the SOC II audit process and achieved an approximately 80% compliance rate with no major findings.
Collaborated with the cybersecurity team to leverage Splunk's threat intelligence capabilities, aiding in the improvement of vendor risk management processes and incident investigation efficiency.
Designed and implemented risk management frameworks, aligning with regulatory requirements (SOX, GDPR, PCI-DSS), to strengthen organizational security posture.
Spearheaded the enhancement of compliance monitoring processes, leading to a 15% increase in regulatory adherence across different departments.
Collaborated with cross-functional teams to establish and enforce security policies and procedures, ensuring alignment with industry standards (NIST, ISO 27001), and organizational goals.
Supported HIPAA compliance program implementation and maintenance, ensuring adherence to regulatory requirements across the organization.
Senior Quality Inspector, 02/2019 to 01/2022
Protolabs
Led the development and qualification of test methods, data sheets, equipment/fixtures, and visual standards in support of new and existing processes to demonstrate capability
I was responsible for recording, verifying, interpreting, process monitoring, testing, comparing to known specifications and criteria
Trended, identified, prioritized, resolved and reported quality issues using information gained from testing and other process monitoring activities, Non-Conforming Events (NCE) and development of Corrective Actions, continuous improvement projects and other quality metrics
Defined training requirements for test methods and work instructions
Identified best quality practices and areas for improvement and lead continuous improvement projects across the plant;
Used documentation systems to research information and generated Change Request
Senior Financial Analyst, 05/2017 to 01/2019
P & D LLC. MN
Led monthly financial forecast process for key business units or core departments
Conducted financial analysis of potential new products, pricing strategies, and strategic opportunities
Analyze financial statements for discrepancies and alert the CFO if necessary.
Created and maintained management reporting packages
Coordinate semi-annual audits and assist the CFO in running audits.
Reconcile accounts monthly to ensure accurate reporting and ledger maintenance.
Maintained Hyperion financial system which supports budget and forecast processes
Project Accountant, 06/2017 to 12/2017
J Max Group of Company – MN,
Created project accounts in the accounting system
Maintained project-related records, including contracts and change orders
Reviewed and approved overhead charges to be applied to a project
Reported on project profitability to management
Reported to management regarding expenditures and funds balance for projects
Approved all project-related billings to customers
Documents and records vendor invoices, purchase requisitions, and other transactions; verifies amounts due and pays in accordance to payment terms.
Compile information for internal and external auditors, as required
Prepared and interprets cost accounting reports to project managers and senior management (i.e. encumbrance reports, project reconciliation, status logs, etc.).
Audit Consultant, 07/2015 to 01/2017
Robert Half – MN
I was responsible to plan and conduct audit in compliance the Generally Accepted Auditing Standards (GAAS)
I was responsible to rectify in a timely fashion and evolve new methods for improving the efficiency and effectiveness of the audit process.
Reviewed of audit files in line with GAAS and GAAP
Provided assurance on the auditor's general reports
Developed audit methodology, audit procedures, audit template and audit program.
Certifications
CompTIA Security+
Quality Control and Assurance
Financial Statement Audit
Government Auditing
IT Auditing &GRC
Education
Bachelor of Business Administration (BBA): Accounting, 12/2011
Master of Business Administration (MBA), 07/2017
Master of Science: Accountancy, 10/2018