Aziz Said
Mobile: 832-***-**** Email: ********@*****.*** Cypress, TX
LinkedIn: https://linkedin.com/in/azizsaid1
Professional Summary
Senior GRC and cybersecurity professional with more than 15 years of progressive experience spanning governance, enterprise risk, regulatory compliance, and security operations. Proven experience building and strengthening security programs, assessing control environments, identifying and prioritizing enterprise risk, driving remediation, and preparing organizations for complex regulatory audits. Demonstrated impact through a 65% improvement in vulnerability detection and remediation efficiency and a 50% reduction in critical risk. Extensive expertise across NIST, ISO 27001, HIPAA, and PCI DSS, coupled with hands-on experience in policy and standards development, enterprise risk assessments, third-party risk management, audit readiness, control validation, and executive risk reporting. CRISC and CISM certified with the technical depth to understand how controls operate and the GRC expertise to evaluate their effectiveness, uncover meaningful risk, and translate findings into actionable business decisions.
Professional Experience
Senior Security & Governance Analyst Empower Pharmacy
November 2024 – Present
Strengthened data governance and compliance controls by identifying requirements for protecting PII, PHI, PCI, and intellectual property, defining risk-based DLP policies based on user and group requirements, and transitioning enforcement from Microsoft Purview to Zscaler ZIA to improve oversight and reduce the risk of unauthorized data exposure.
Established and maintained enterprise security policies, standards, and procedures aligned with NIST CSF, ISO 27001, and HIPAA by translating regulatory and security requirements into governance practices that strengthened compliance and established consistent security expectations across business units.
Conducted enterprise risk and control assessments across IT systems and business processes to identify control gaps and areas of compliance exposure, documenting findings within the risk register and providing prioritized remediation recommendations based on risk severity and potential business impact.
Managed third-party risk assessments for new and existing vendors by evaluating their security posture and control environments through SecurityScorecard, documenting identified risks, and coordinating remediation activities to support informed vendor decisions and reduce third-party risk exposure.
Supported PCI DSS and HIPAA compliance assessments and audits by partnering with control owners to validate control implementation, collect and review supporting evidence, resolve documentation gaps, and track findings through remediation to strengthen audit readiness and demonstrate compliance.
Partnered with Legal, IT, and business stakeholders to evaluate changes in regulatory and security requirements, assess their impact on existing controls, and coordinate updates to policies and compliance practices to maintain alignment with the organization’s evolving regulatory and risk environment.
Developed and delivered security awareness and governance training by translating security policies, compliance requirements, and data protection responsibilities into practical employee guidance that strengthened workforce awareness and supported a more risk-conscious organizational culture.
Senior Team Lead of Vulnerability & Threat Management CenterPoint Energy Inc
September 2022 – November 2024
Developed the organization’s Vulnerability Management Policy and supporting standards while establishing scanning requirements, schedules, asset groups, and governance processes within Rapid7 to create a consistent framework for identifying and managing vulnerabilities across the enterprise.
Helped rebuild the enterprise Vulnerability Management Program by establishing standardized assessment, prioritization, and remediation processes that improved vulnerability detection and remediation efficiency by 65% across the organization.
Led the identification, assessment, and prioritization of security vulnerabilities using risk and exploitability criteria to focus remediation efforts on the organization’s highest exposures, contributing to a 50% reduction in critical risk while incorporating DAST assessments for OWASP Top 10 vulnerabilities through InsightAppSec.
Developed and presented monthly vulnerability and risk metrics to senior leadership, providing visibility into vulnerability trends, remediation progress, critical exposures, and overall program performance to support risk-informed decision-making.
Built and led a team of four vulnerability analysts by providing training, technical guidance, and oversight of enterprise vulnerability assessments, increasing the team’s capacity to consistently identify, evaluate, and communicate security risks across the organization.
Established recurring vulnerability remediation reviews with system owners and key stakeholders to communicate risk, establish remediation timelines, assign action items, and track identified vulnerabilities through resolution.
Managed the Vulnerability Management Program against established budget, operational, and remediation milestones, balancing security priorities with organizational resources to maintain a cost-effective program while consistently meeting program objectives.
Lead Cybersecurity Specialist Energy Transfer Partners
February 2021 – September 2022
Led a team of five cybersecurity analysts responsible for vulnerability and threat management, providing program oversight, technical guidance, and risk prioritization to support consistent execution of security objectives across the enterprise.
Coordinated vulnerability remediation and risk reduction efforts across enterprise infrastructure and applications by partnering with technical stakeholders to address identified weaknesses, prioritize corrective actions, and drive vulnerabilities toward timely resolution.
Developed Power BI risk dashboards and reporting capabilities to provide stakeholders with proactive visibility into vulnerability exposure, remediation status, and security trends, improving accountability and enabling more informed remediation decisions across the enterprise.
Led incident response and threat management activities using the MITRE ATT&CK framework to identify, analyze, and respond to advanced threats, strengthening the organization’s ability to manage security incidents and address threats that bypassed traditional security controls.
Supported broader enterprise risk management activities by conducting third-party security assessments through SecurityScorecard and providing backup administration of Cisco SecureX and Stealthwatch to maintain visibility into vendor and internal security risks.
Senior Cybersecurity Analyst Memorial Hermann Health Systems (Insight Global Consultant)
March 2020 – February 2021
Implemented Tenable across the organization’s environment while developing standardized scanning practices, training employees on assessment procedures, and coordinating remediation activities to improve the identification and management of security risks.
Managed email and web security controls through Proofpoint, Forcepoint, and OpenDNS by reviewing malicious senders and links, evaluating business requests for URL exceptions, and maintaining appropriate access controls to reduce exposure to email and web-based threats.
Supported endpoint security and risk monitoring through the administration of CrowdStrike and Carbon Black, helping identify potential threats and maintain security controls designed to protect enterprise systems and data.
Partnered with control owners to evaluate security and compliance requirements for critical infrastructure, identify outstanding risks, and coordinate remediation activities prior to production deployment to reduce the likelihood of introducing unacceptable risk into the environment.
Managed inherent risk and remediation activities within ServiceNow GRC by reviewing identified risks, prioritizing tasks based on criticality and potential business impact, and tracking security issues to support timely risk treatment and resolution.
Senior Cybersecurity Analyst Harris County – Universal Services
October 2018 – March 2020
Led the implementation of endpoint and ransomware protection controls by coordinating the deployment of SentinelOne and BullWall across the enterprise, thus strengthening safeguards against advanced threats and reducing risk to critical systems and network file shares.
Served as an active member of the Incident Response Team by investigating and responding to cybersecurity events in alignment with the NIST Incident Response framework, supporting consistent incident handling and timely mitigation of identified threats.
Monitored enterprise security controls and threat intelligence through Palo Alto firewalls to identify indicators of compromise, assess potential threats, and proactively block malicious IP addresses and URLs to reduce the likelihood of successful attacks.
Led the evaluation and implementation of threat intelligence capabilities by assessing MineMeld and AutoFocus for integration with Palo Alto security controls, ultimately supporting the selection of AutoFocus to improve threat intelligence integration and enable more proactive risk mitigation.
Information Security Engineer Wells Fargo (KForce Consultant)
March 2017 – September 2017
Conducted risk-based assessments of SaaS applications by assigning security ratings from poor to high and performing additional analysis to determine appropriate blocking or whitelisting actions, successfully completing 100% of assigned SaaS application reviews to support secure cloud adoption.
Managed the security exception process through the FARM system by evaluating user requests, validating business justification and operational impact, and approving appropriate exceptions to balance business requirements with organizational security risk.
Participated in recurring cloud security governance reviews to evaluate existing processes, identify opportunities for procedural improvements, and strengthen the team’s approach to managing cloud security risks across the Wells Fargo environment.
Developed and maintained SaaS risk metrics and management reporting using Excel to communicate assessment results, application risk ratings, and analysis progress to senior leadership, providing greater visibility into the organization’s cloud security risk posture.
Harris County Toll Road Authority
May 2014 – January 2017
Established and refined information security policies based on NIST 800-series guidance by translating security requirements into documented organizational practices that strengthened governance and provided consistent expectations for protecting enterprise systems and information.
Led security initiatives by assessing proposed solutions against confidentiality, integrity, and availability requirements, documenting security considerations, and providing guidance throughout implementation to ensure technology and operational services aligned with organizational security objectives.
Performed continuous security control monitoring by reviewing network activity, documenting security events, and investigating potential threats through IDS/IPS, file integrity monitoring, security configuration management, and antivirus controls to identify and address security risks within the environment.
Implemented and enhanced access, encryption, and audit controls through RSA SecurID, Tripwire, Oracle Audit Vault and Key Manager, and WAVE Encryption to strengthen protection of sensitive systems and support compliance with PCI DSS requirements.
Served as the primary security contact for PCI DSS compliance and audit readiness by coordinating with Protiviti during Report on Compliance (ROC) assessments, maintaining required policies and supporting documentation, demonstrating logging and network segmentation controls, and providing vulnerability scanning and penetration testing evidence to validate remediation of cardholder data environment risks.
Conducted vulnerability and risk assessments across critical assets and internal controls to identify security exposures, evaluate remediation needs, and communicate security advisories to executive leadership to support risk-informed decision-making.
Strengthened continuous monitoring and security oversight by implementing and optimizing Alert Logic SIEM and log analysis capabilities to identify potentially malicious activity across internet-facing and internal infrastructure and improve visibility into enterprise security risk.
Security Operations Analyst BP plc
November 2010 – April 2014
Monitored enterprise security controls through ArcSight ESM, IDS, HIPS, Active Directory event logs, antivirus, file integrity monitoring, and vulnerability scanning solutions to identify security events and support timely investigation of potential risks.
Investigated and documented security events and potential threats by analyzing alerts and detection rules, maintaining incident records within the SOC knowledge base, and implementing appropriate blocking actions to reduce exposure to malicious domains and activity.
Analyzed advanced security threats using FireEye, Damballa, NetWitness, and Wireshark to validate security alerts and distinguish legitimate threats from false positives while developing documented procedures to standardize alert handling and response activities.
Conducted vulnerability assessments using Qualys to identify security weaknesses, evaluate potential exposure, and prepare security advisories for executive leadership to support visibility and risk-informed remediation decisions.
Implemented log monitoring and analysis controls for internet-facing business and partner applications to identify potentially malicious activity and strengthen visibility into external security threats.
Developed and delivered security metrics and management reporting through ArcSight to provide leadership with visibility into vulnerability trends, potential security incidents, and the organization’s broader security risk posture.
Managed email security monitoring and response controls through MessageLabs by investigating inbound and outbound spam and phishing activity, implementing blocks for identified threats, and producing reports to determine exposure to malicious messages and attachments.
Education
Bachelor’s Degree in Liberal Studies Minor: MIS University of Maine Presque Isle
Expected Graduation Date: May 2027
Certifications
Certified in Risk and Information Systems Control (CRISC) ISACA August 2026
Certified ISO/IEC 42001:2023 Lead Auditor Mastermind Assurance August 2026
Certified Information Security Manager (CISM) ISACA October 2024
GIAC Certified Intrusion Analyst (GCIA) SANS November 2012
Skills
NIST CSF NIST 800 Series ISO 27001 PCI DSS HIPAA MITRE ATT&CK Governance, Risk & Compliance (GRC) Enterprise Risk Management Risk & Control Assessments Risk Register Management Control Gap Analysis Control Validation Audit Readiness Audit Evidence Management Regulatory Compliance Policy & Standards Development Third-Party Risk Management (TPRM) Vendor Security Assessments Security Exception Management Risk Remediation Vulnerability Management Data Loss Prevention (DLP) Data Governance Security Awareness Incident Response Security Metrics & Reporting Executive Risk Reporting ServiceNow GRC SecurityScorecard Rapid7 InsightVM Tenable Qualys Zscaler ZIA Microsoft Purview Power BI