Professional Summary
Overview
Work History
Education
Skills
Certification
Timeline

Darryl Danoo

Kapitus
Dallas,TX
1
Certification
13
years of professional experience

Cloud & AI Governance Analyst managing GRC, third-party risk management, and AI governance across cloud environments. Reviews controls, evidence, vendor assessments, and remediation activity using ServiceNow GRC, Secureframe, AWS Bedrock, and security tools to support audit readiness and policy alignment. Validates AI-assisted outputs against company policies, financial records, and trusted sources before using them in compliance work.

Work History

Cloud & AI Governance Analyst

2 Years 7 Months
Kapitus | 01.2024 - Current
  • Manage daily GRC activities by reviewing risks, security controls, compliance requirements, policies, risk-register items, and remediation activities.
  • Use ServiceNow GRC and Secureframe to manage compliance tasks, control evidence, findings, risk tracking, remediation, and audit readiness.
  • Developed and supported third-party risk management use cases, conducting vendor risk assessments, security questionnaires, due diligence, control reviews, evidence collection, risk scoring, remediation tracking, and ongoing monitoring to enhance risk management effectiveness.
  • Utilized AWS Bedrock and AI tools to streamline document reviews, summarize compliance information, identify potential risks, and prioritize GRC activities, contributing to improved compliance management.
  • Use AWS Bedrock and AI tools to improve productivity by reviewing documents, summarizing compliance information, identifying potential risks, and helping prioritize GRC activities.
  • Supported PCI DSS 4.0.1, SOC 2, NIST CSF, and AI governance activities through effective use of Wiz, AWS CloudTrail, IAM, Microsoft 365, Terraform, Jira, and Slack to ensure compliance with industry standards.

Information Security Consultant

2 Years
VikingCloud | 01.2022 - 01.2024
  • Leveraged Bifrost, VikingCloud's internal AI tool, to enhance security, governance, risk, and compliance activities through human review of critical outputs.
  • Created AOC/ROC documentation and remediation roadmaps based on audit findings, security assessments, compliance gaps, and control reviews.
  • Developed and supported third-party risk management use cases by reviewing vendor security evidence, assessing controls and compliance requirements, identifying gaps, documenting risks, and tracking remediation.
  • Used Microsoft Purview to support data governance, data security, privacy, information protection, and compliance requirements.
  • Reviewed and updated existing security protocols to align with industry regulations and organizational goals.
  • Managed third-party vendor relationships, ensuring compliance with established security standards and best practices.

Cloud Security Engineer

3 Years 8 Months
Lynk Remote Technologies | 04.2018 - 12.2021
  • Secured AWS infrastructure for Lynk's IoT, remote monitoring, video, and mobile applications, enhancing overall security posture.
  • Utilized AWS CloudTrail and CloudWatch for comprehensive logging, monitoring, and alerting, strengthening security investigations.
  • Employed Wiz CSPM and Terraform to identify AWS risks and standardize configurations, facilitating secure deployments.
  • Developed and implemented cloud security policies to protect sensitive data and applications.
  • Delivered regular reports on the status of organizational cloud security measures to key stakeholders, facilitating informed decision-making processes regarding risk management and ongoing improvement initiatives.

Information Security Analyst

2 Years 2 Months
Yehowa Medical Services | 06.2016 - 08.2018
  • Developed and updated security assessment plan documentation to meet federal certification and accreditation processes, ensuring compliance and effective risk management.
  • Conducted HIPAA audits and related NIST and PCI DSS IT reviews in accordance with annual audit plans.
  • Supported security-control implementation, assessment findings, remediation activities, and regulatory requirements.
  • Conducted security assessments to identify vulnerabilities in medical information systems.

Information Security Analyst

2 Years 2 Months
Nationwide Credit Corp | 02.2014 - 04.2016
  • Conducted IT control risk assessments, reviewing organizational policies, standards, procedures, and guidelines to enhance compliance and security posture.
  • Identified internal-control weaknesses, recommending improvements to strengthen security measures and operational efficiency.
  • Performed HIPAA and related IT security reviews according to annual audit plans.
  • Evaluated security controls, documented risks, and supported policy reviews, audit findings, and corrective-action recommendations.

Information Security Analyst

1 Year 8 Months
Cru Property Management | 06.2014 - 02.2016
  • Analyzed and updated risk assessments, privacy impact assessments, system security plans, security test & evaluation documentation, and POA&Ms to enhance compliance and security posture.
  • Analyzed and updated Risk Assessments, Privacy Impact Assessments, System Security Plans, Security Test & Evaluation documentation, and POA&Ms.
  • Identified privacy complaints and program gaps, recommending targeted remediation solutions to strengthen program effectiveness.
  • Supported risk mitigation and security-control implementation, contributing to comprehensive governance documentation.

Education

Bachelor of Science - Information Technology

University of Maryland, College Park | College Park | 05.2007

Associate of Science - Computer Information Systems

Montgomery College | Takoma Park | 12.2004

Skills

Core Skills & Frameworks: GRC & Risk Management | AI Governance | Cybersecurity | PCI DSS | SOC 2 | ISO 27001 | NIST | HIPAA | Cloud Security | Compliance Audits
Tools: ServiceNow GRC | Secureframe | AWS | Microsoft 365 | AWS Bedrock | Audit Manager | CloudTrail | IAM | KMS
Governance: Risk Assessments | Control Testing | Policy Management | Audit Readiness | Third-Party Risk | Remediation | Security Compliance

Certification

  • CISM
  • ISACA
  • CISA
  • QSA
  • PCI SSC
  • CompTIA Security+
  • AWS Certified Solutions Architect
  • Microsoft Certified: Azure Security Engineer Associate
  • PMP

Timeline

Cloud & AI Governance Analyst

Kapitus
01.2024 - CurrentRead More

Information Security Consultant

VikingCloud
01.2022 - 01.2024Read More

Cloud Security Engineer

Lynk Remote Technologies
04.2018 - 12.2021Read More

Information Security Analyst

Yehowa Medical Services
06.2016 - 08.2018Read More

Information Security Analyst

Cru Property Management
06.2014 - 02.2016Read More

Information Security Analyst

Nationwide Credit Corp
02.2014 - 04.2016Read More

University of Maryland, College Park

Bachelor of Science from Information Technology
Read More

Montgomery College

Associate of Science from Computer Information Systems
Read More
Darryl Danoo