Experienced IT professional with a strong background in risk management, compliance, and ERP systems. CompTIA Security+ certified with proven expertise in evaluating application controls, access risks, and segregation of duties (SoD). Skilled in ERP risk assessments, SAP governance solutions, and IT audit practices. Adept at delivering client-focused recommendations, ensuring compliance with industry standards, and strengthening governance frameworks. Known for strong analytical ability, collaboration, and client-facing communication skills.
Helped maintain and update more than a dozen company security policies, ensuring they matched ISO 27001, NIST CSF and HIPAA standards and cutting down on policy exceptions by 35% over a year.
• Partnered with multiple business units on quarterly policy reviews to keep governance documents current and relevant.
• Performed risk assessments on 50+ internal applications and third-party vendors, flagging and remediating over 200 medium-to-high risks, which reduced overall exposure by nearly 30%.
• Rolled out a risk scoring framework that gave leadership a clear picture of the organization’s top risks and allowed them to focus on the 10 most critical issues.
• Supported SOC 2, SOX, and PCI DSS audits with zero major findings while reducing audit prep time by 40% through better evidence collection and organization.
• Tracked more than 150 security and compliance controls using Archer/ServiceNow GRC, keeping effectiveness above 90% across the portfolio.
• Built executive dashboards that made compliance posture easy to monitor, improving audit readiness scores by 20%.
• Led monthly GRC awareness sessions for 200+ employees, which drove down policy violations by 45% and boosted phishing test pass rates from 68% to 90% within nine months.
• Conducted due diligence on 30+ vendors each year, ensuring 95% met security requirements before contract signing and cutting review turnaround time by 25%.
CompTIA Security+ 2025