Summary
Overview
Work History
Education
Skills
Websites
Timeline
Certification
Generic

Chisom Nwoke

Houston,USA

Summary

Experienced IT professional with a strong background in risk management, compliance, and ERP systems. CompTIA Security+ certified with proven expertise in evaluating application controls, access risks, and segregation of duties (SoD). Skilled in ERP risk assessments, SAP governance solutions, and IT audit practices. Adept at delivering client-focused recommendations, ensuring compliance with industry standards, and strengthening governance frameworks. Known for strong analytical ability, collaboration, and client-facing communication skills.

Overview

8
8
years of professional experience

Work History

GRC Analyst II

McKesson
08.2021 - Current

Helped maintain and update more than a dozen company security policies, ensuring they matched ISO 27001, NIST CSF and HIPAA standards and cutting down on policy exceptions by 35% over a year.

• Partnered with multiple business units on quarterly policy reviews to keep governance documents current and relevant.

• Performed risk assessments on 50+ internal applications and third-party vendors, flagging and remediating over 200 medium-to-high risks, which reduced overall exposure by nearly 30%.

• Rolled out a risk scoring framework that gave leadership a clear picture of the organization’s top risks and allowed them to focus on the 10 most critical issues.

• Supported SOC 2, SOX, and PCI DSS audits with zero major findings while reducing audit prep time by 40% through better evidence collection and organization.

• Tracked more than 150 security and compliance controls using Archer/ServiceNow GRC, keeping effectiveness above 90% across the portfolio.

• Built executive dashboards that made compliance posture easy to monitor, improving audit readiness scores by 20%.

• Led monthly GRC awareness sessions for 200+ employees, which drove down policy violations by 45% and boosted phishing test pass rates from 68% to 90% within nine months.

• Conducted due diligence on 30+ vendors each year, ensuring 95% met security requirements before contract signing and cutting review turnaround time by 25%.

Cloud Migration & Risk Analyst

Applied Supercomputing Users (ASU) Inc. (Academic Cloud Project)
01.2025 - 06.2025
  • Developed proof-of-concept for migrating from physical infrastructure to AWS, analyzing both computing and cost risks.
  • Configured AWS resources (EC2, DynamoDB, Route 53, CloudWatch) and tested cloud security groups and load balancing.

GRC Analyst

Tungland Corporation
10.2017 - 06.2021
  • Managed operations, compliance documentation, and workforce scheduling while maintaining regulatory standards.
  • Conducted risk and compliance reviews of IT workflows, ensuring alignment with internal controls and regulatory requirements.
  • Collaborated with cross-functional teams to identify, test, and remediate control gaps in access management processes.
  • Supported IT audit requests and delivered documentation on application security and system compliance.
  • Partnered with leadership to update Acceptable Use and Privacy Policies, strengthening the governance framework.
  • Applied analytical problem-solving to identify compliance risks within operational reporting and workforce systems.

Education

Bachelor of Science - Information Technology

Arizona State University
08-2025

Skills

  • Programming Languages: Java, Python, SQL
  • Software Methodologies: Agile, Scrum
  • Databases Related: mySQL, Excel
  • DevOps Tools: Teams, Slack, Jira, Verint, SharePoint, Five9
  • Virtualization: VMware, VirtualBox, Ubuntu
  • Operating Systems: Windows, Linux, MacOS, Android
  • ERP Risk & Compliance (SAP/Oracle)
  • Application & Access Controls
  • Segregation of Duties (SoD) Testing
  • Governance, Risk & Compliance (GRC) Tools (SAP GRC)
  • IT Audit & Compliance Assessments

Timeline

Cloud Migration & Risk Analyst

Applied Supercomputing Users (ASU) Inc. (Academic Cloud Project)
01.2025 - 06.2025

GRC Analyst II

McKesson
08.2021 - Current

GRC Analyst

Tungland Corporation
10.2017 - 06.2021

Bachelor of Science - Information Technology

Arizona State University

Certification

CompTIA Security+ 2025