Summary
Overview
Work History
Education
Skills
Certification
Timeline
Professional Strengths
Generic

Andrew Annor

Summary

Cybersecurity and GRC professional with advanced experience in vendor risk management, compliance, and security monitoring. Trusted for leading initiatives that improve organizational posture and resilience through collaboration, technical expertise, and continuous best practices.

Overview

6
6
years of professional experience
1
1
Certification

Work History

Global Information Security Analyst (GRC)

New Balance
10.2024 - 09.2025

Led global vendor risk initiatives, improving third-party security review workflows and integrating them across procurement, legal, and HR to protect company data and strengthen overall governance.

  • Conducted comprehensive third-party risk assessments, documenting and driving remediation plans aligned to enterprise security objectives, resulting in measurable reduction of vendor-related risks.
  • Partnered with security engineering to review penetration testing findings; prioritized and addressed vulnerabilities which enhanced security controls and audit readiness.
  • Evaluated new technologies for security impact, updated governance baselines, and influenced onboarding and policy guidance for company-wide adoption.
  • Developed policy documentation and delivered training that embedded risk awareness throughout all levels of the organization.
  • Reviewed over 150 vendors per quarter.
  • Provided training sessions on data protection laws and compliance, raising awareness across the organization.

Compliance Analyst

CloudFit, MD
10.2021 - 07.2024
  • Performed SOX compliance walkthroughs and ITGC testing, proactively collecting and organizing audit evidence ahead of deadlines to support successful internal and external audit outcomes.
  • Authored detailed audit narratives and process documentation, providing remediation guidance that strengthened process controls and regulatory compliance across finance and IT teams.
  • Tracked Key Risk Indicators and compliance findings, enabling timely remediation actions and promoting a continuous improvement culture organization-wide.
  • Advised and coached business/IT units on SOX control requirements, bridging communication between technical, operational, and executive stakeholders for effective compliance enablement.
  • Hybrid

Information Risk Analyst

Pace Inc., CT
06.2019 - 09.2021
  • Conducted cybersecurity risk assessments internally and for external vendors, reviewing SOC 2 reports and penetration test results to calibrate risk levels and inform partnership decisions.
  • Executed vulnerability scans and collaborated with IT teams to prioritize and resolve security gaps, supporting regulatory compliance and governance improvement projects.
  • Tiered vendors’ risk profiles across onboarding, monitoring, and contract offboarding, directly influencing procurement strategy and minimizing enterprise risk exposure.
  • Prepared audit and regulatory exam evidence and produced risk reports for senior leadership, enabling data-driven decisions for resource allocation and resilience strengthening.
  • Remote

Education

Bachelor’s Degree - Computer Science

University of Ghana

Skills

  • Frameworks/Standards : NIST 800-53, PCI DSS, SOC 2, ISO 27001, SOX ITGC
  • Risk Assessment, Security Audits, Policy Documentation
  • Tools: Nessus, OneTrust, Jira, Trello, Azure, AWS
  • Threat intelligence
  • Risk mitigation
  • Incident response
  • Privacy regulations
  • Data security
  • Vendor reviews
  • Encryption

Certification

  • CompTIA Security+
  • Microsoft Introduction to AI & ML
  • CISA - Certified Information Systems Auditor

Timeline

Global Information Security Analyst (GRC)

New Balance
10.2024 - 09.2025

Compliance Analyst

CloudFit, MD
10.2021 - 07.2024

Information Risk Analyst

Pace Inc., CT
06.2019 - 09.2021

Bachelor’s Degree - Computer Science

University of Ghana

Professional Strengths

  • Collaborative communicator with coaching and enablement experience
  • Analytical thinker skilled at root cause analysis and solution development
  • Maintains accuracy, integrity, and performance under time pressure
  • Proactive learner and process improvement advocate
Andrew Annor