Post Job Free
Sign in

Cybersecurity GRC & Compliance Analyst

Location:
Newark, NJ
Posted:
September 27, 2026

Contact this candidate

Resume:

ABRAK YASHIM

646-***-**** ****************@*****.*** Newark, NJ

PROFESSIONAL SUMMARY

Cybersecurity GRC Analyst with 7+ years of experience advancing information security program maturity, insurance-related regulatory compliance, third-party vendor risk management, and security awareness program development. Skilled in mapping security controls to NIST CSF, CIS Controls, COBIT, and ISO 27001, conducting security framework gap assessments, and building audit-ready documentation that supports multi-state regulatory filings and state insurance department examinations. Experienced in developing KRI and KPI security dashboards, board presentation materials, and leading phishing simulation and social engineering awareness campaigns with tracked training participation and program effectiveness metrics. CISA-certified with CRISC in progress; working knowledge spans SOC 2, GDPR, PCI DSS, state insurance regulatory requirements, NYDFS, and multi-jurisdictional compliance obligations.

PROFESSIONAL EXPERIENCE

Cybersecurity GRC Analyst Mar 2024 – Present

United Ground Express (UGE) Newark, NJ

• Maintained audit-ready compliance documentation and coordinated multi-state regulatory filings across airport operations, ensuring submissions aligned with TSA, FAA, OSHA, and applicable state insurance regulatory standards through a structured evidence management process that contributed to measurable reductions in non-compliance findings during routine and unannounced regulatory examinations.

• Performed vendor security risk assessments throughout the vendor lifecycle for ground and cabin service providers using a standardized questionnaire and risk-tiering methodology, maintained the vendor risk register in ServiceNow, and tracked remediation activities toward defined risk mitigation objectives, consistently improving vendor adherence to operational security standards.

• Designed and executed a multi-function security awareness training program (covering policy acknowledgments, safety governance standards, and role-specific regulatory requirements), tracked training participation, measured program effectiveness, and drove measurable reductions in repeat policy violations by developing targeted phishing, social engineering, and secure behavior awareness campaigns.

• Built KPI and compliance tracking dashboards in Microsoft Excel and SharePoint, delivering leadership visibility into audit outcomes, incident escalation trends, training completion rates, and information security program performance across all operational areas, and prepared executive reporting and board presentation materials on security compliance status and risk posture.

• Mapped operational security controls to NIST CSF, CIS Controls, and NYDFS requirements through structured gap assessment, identifying procedural weaknesses and developing prioritized corrective action plans with specific recommendations to improve organizational maturity scores in subsequent audit cycles.

• Identified compliance gaps and escalated security risks to leadership, recommending process improvements that strengthened governance documentation, compliance activities, and security awareness efforts while partnering with Operations, Safety, and QA teams to sustain compliance continuity across all shifts.

• Established a GRC governance committee with C-level executive sponsorship, defining charter, escalation thresholds, and review cadence, substantially shortening policy approval cycles and increasing cross-functional compliance engagement.

• Implemented and configured ServiceNow GRC module to centralize risk management, compliance tracking, audit workflows, and real-time security performance reporting dashboards, substantially improving operational efficiency and eliminating fragmented manual tracking processes. Governance, Risk & Compliance (GRC) Analyst Aug 2022 – Jan 2024 Spaxel Property Management Newark, NJ

• Led ISO 27001 and SOC 2 Type II certification from scoping through Statement of Applicability

(SoA) development, Annex A control documentation, evidence collection for internal audits and regulatory reviews, and external audit execution, achieving first-attempt certification with zero findings and enabling the company to secure new enterprise client contracts.

• Designed and executed a security awareness training program including monthly security awareness communications (newsletters, alerts, and announcements), targeted phishing simulation campaigns, and role-specific training content, tracking participation rates and measuring program effectiveness through pre- and post-training assessments that measurably raised employee security knowledge scores within one year.

• Conducted structured security risk assessments for third-party vendors, documenting remediation activities, renegotiating contractual security requirements, and implementing tighter vendor management controls that significantly reduced supply chain security exposure.

• Developed executive security reporting packages and board presentation materials covering ISO 27001 control effectiveness, SOC 2 readiness, phishing simulation results, and awareness program effectiveness, enabling senior leadership to make data-informed decisions on security investment priorities.

• Introduced automated security monitoring capabilities, eliminating routine manual log review overhead, cutting threat detection and response time, and freeing the team for strategic risk and compliance priorities.

• Partnered with IT, Legal, and HR to build a coordinated security incident response plan, defining escalation paths, communication protocols, and post-incident review procedures that reduced cross-functional response confusion and improved event containment.

• Conducted quarterly internal control testing against ISO 27001 Annex A controls and SOC 2 Trust Services Criteria, identifying control deviations, updating the risk register, tracking remediation, and maintaining continuous certification readiness between annual external audits.

• Developed and maintained a comprehensive policy library covering information security, data governance, acceptable use, third-party vendor management, and incident response; each policy was version-controlled, aligned to applicable regulatory requirements, and structured as defensible audit evidence.

Risk and Compliance Analyst Jun 2019 – Jul 2022

F & C Realty LLC Newark, NJ

• Led SOX compliance testing across critical Finance, IT, and Operations processes, achieving a clean audit opinion with zero material weaknesses across three consecutive annual reporting cycles.

• Built an automated compliance reporting system using Microsoft Excel VBA and data extraction scripting that generated quarterly regulatory filings, significantly reducing preparation time per reporting cycle and improving submission accuracy.

• Maintained a regulatory change management process tracking annual federal and state regulatory updates, translating changes into timely policy revisions, control adjustments, and compliance bulletins distributed to business unit owners within defined response timelines.

• Coordinated GDPR compliance implementation across multiple office locations, conducting data mapping and processing activity documentation, establishing data subject request workflows, implementing data governance controls, and aligning Legal, IT, and Operations around shared data protection responsibilities.

• Conducted enterprise-wide risk assessments using a structured risk identification, scoring, and ranking methodology, identifying operational vulnerabilities, developing prioritized remediation recommendations, and tracking implementation through quarterly risk register reviews.

• Designed and operated a business continuity and disaster recovery testing program across critical business functions, executing tabletop exercises and technical failover scenarios, validating RTOs and RPOs, and updating continuity documentation based on test outcomes.

• Collaborated with IT, Finance, and Legal teams during quarterly user access entitlement reviews and access certification campaigns, identifying over-provisioned accounts, enforcing least-privilege access, and producing audit-defensible documentation for SOX IT General Control evidence requirements.

SKILLS

• GRC and Risk Management: Governance, Risk and Compliance (GRC), Risk Assessment and Management, Vendor Risk Register, Vendor Lifecycle Management, Third-Party Risk Management

(TPRM), Security Framework Gap Assessments, Organizational Maturity Assessments, Internal Control Design, Risk Identification and Prioritization, Risk Mitigation Planning

• Compliance and Audit: Insurance Regulatory Compliance, State Insurance Regulatory Requirements, Multi-State Regulatory Filings, NYDFS Requirements, SOX IT General Controls

(ITGC), GDPR, ISO 27001, PCI DSS, SOC 2 Type II, Audit Readiness, Evidence Collection, Compliance Gap Identification, Policy Development

• Security and Awareness: Security Awareness Training Program Design, Phishing Simulation, Social Engineering Awareness, Secure Behavior Campaigns, Security Newsletters and Alerts, Training Participation Tracking, Program Effectiveness Measurement, KRI and KPI Reporting, Security Dashboards, Executive Reporting, Board Presentation Materials, Security Performance Reporting

• Tools and Platforms: ServiceNow GRC, OneTrust, Drata, Vanta, Archer, Microsoft Office Suite

(Excel, Word, PowerPoint), SharePoint, Google Workspace, Power BI

• Standards and Frameworks: ISO 27001, NIST CSF, CIS Controls v8, NIST 800-53, NIST 800-30, COBIT-5, SOC 2 Trust Services Criteria, GDPR, PCI DSS, SOX ITGC EDUCATION

Bachelor of Arts (Fine and Applied Arts – NCE Equivalent) Kaduna State College of Education, Nigeria

CERTIFICATIONS

• Certified Information Systems Auditor (CISA) ISACA 2026

• Certified in Risk and Information Systems Control (CRISC)

• Information Security Management System (ISMS)



Contact this candidate