
A Subject Matter Expert in Risk Management Framework (RMF) with extensive understanding of NIST Special Publications series, such as SP 800 -53 rev4, SP 800-53A, SP 800-37, SP 800-60 and to include implementing security controls, creating documentation, and completing risk assessments. In-depth knowledge of Sarbanes-Oxley Act (SOX), HIPAA, Risk Assessment, IT General Controls (ITGC), SSAE 18 attestation and ERP security assessments. A strong ability to perform corrective action on identified vulnerabilities and review of Plan of Action and Milestone (POA&M).