Summary
Overview
Work History
Education
Additional Information
Timeline
Generic

ADEGBOLA OYEKUNLE

Sugar Land,TX

Summary

A Subject Matter Expert in Risk Management Framework (RMF) with extensive understanding of NIST Special Publications series, such as SP 800 -53 rev4, SP 800-53A, SP 800-37, SP 800-60 and to include implementing security controls, creating documentation, and completing risk assessments. In-depth knowledge of Sarbanes-Oxley Act (SOX), HIPAA, Risk Assessment, IT General Controls (ITGC), SSAE 18 attestation and ERP security assessments. A strong ability to perform corrective action on identified vulnerabilities and review of Plan of Action and Milestone (POA&M).

Overview

5
5
years of professional experience

Work History

Information Security Analyst/ Risk Analyst

USAA
10.2020 - 08.2022
  • Coordinating and performing reviews of data center general controls, company-server security, operating systems, systems development life cycles (SDLC), monitor procedures relating to physical security over data centers, computer operations and network communications security.
  • Recommending corrective action plan to be documented in the Plan of Action and Milestone (POA&M).
  • Performing regular systems security scans using NESSUS, and reviewing the identified vulnerabilities for proper recommendation.
  • Reviewing system scans including vulnerability report and analyzing the report using Splunk- SIEM tool.
  • Supporting organization transition from traditional Assessment and Authorization process to an ongoing authorization approach.
  • Review of SOC I type II report, execute SOC I, II and III, review SSAE18, knowledge of GDPR and ISO 27000, and holds a CISA certification.
  • Assisted the system owners in preparing for the Assessment and Authorization (A&A) package to get Authorization To Operate (ATO).
  • Ensured the technical, operational and management controls adhere to security requirement through continuous monitoring process.
  • Performed periodic vulnerability management and remediation of vulnerabilities.
  • Conducted risk assessment including reviewing organizational policies, standards and procedures and provided advise on accuracy.
  • Coordinated continuous monitoring using eGRC tools such CSAM, RSA Archer.
  • Execute annual internal audit plan and prepare reports to keep stakeholders abreast of audit findings and make recommendations that add values as adequate.
  • Test controls using COSO & COBIT frameworks, FFIEC & NIST Standards to determine systems control design appropriateness and operating effectiveness.
  • Perform IT General Controls (ITGCs) and IT application Controls testing deploying a risk-based approach to determine controls’ design adequacy and operating effectiveness.
  • Deliver autonomous audit assurance in evaluating internal control design and effectiveness, reporting the results to the appropriate business units.
  • Document financial and information systems control testing for data integrity and quality to ensure completeness and accuracy of data.
  • Engage in the periodic review of a comprehensive Company risk assessment.

Education

BS - Computer Science, and Information Management

Ondo State University

Additional Information

  • |PMP|CISM|CISA|SECURITY+ CE|

Timeline

Information Security Analyst/ Risk Analyst

USAA
10.2020 - Current

BS - Computer Science, and Information Management

Ondo State University
ADEGBOLA OYEKUNLE