Cloud & AI Governance Analyst managing GRC, third-party risk management, and AI governance across cloud environments. Reviews controls, evidence, vendor assessments, and remediation activity using ServiceNow GRC, Secureframe, AWS Bedrock, and security tools to support audit readiness and policy alignment. Validates AI-assisted outputs against company policies, financial records, and trusted sources before using them in compliance work.
Work History
Cloud & AI Governance Analyst
2 Years 7 Months
Kapitus | 01.2024 - Current
Manage daily GRC activities by reviewing risks, security controls, compliance requirements, policies, risk-register items, and remediation activities.
Use ServiceNow GRC and Secureframe to manage compliance tasks, control evidence, findings, risk tracking, remediation, and audit readiness.
Developed and supported third-party risk management use cases, conducting vendor risk assessments, security questionnaires, due diligence, control reviews, evidence collection, risk scoring, remediation tracking, and ongoing monitoring to enhance risk management effectiveness.
Utilized AWS Bedrock and AI tools to streamline document reviews, summarize compliance information, identify potential risks, and prioritize GRC activities, contributing to improved compliance management.
Use AWS Bedrock and AI tools to improve productivity by reviewing documents, summarizing compliance information, identifying potential risks, and helping prioritize GRC activities.
Supported PCI DSS 4.0.1, SOC 2, NIST CSF, and AI governance activities through effective use of Wiz, AWS CloudTrail, IAM, Microsoft 365, Terraform, Jira, and Slack to ensure compliance with industry standards.
Information Security Consultant
2 Years
VikingCloud | 01.2022 - 01.2024
Leveraged Bifrost, VikingCloud's internal AI tool, to enhance security, governance, risk, and compliance activities through human review of critical outputs.
Created AOC/ROC documentation and remediation roadmaps based on audit findings, security assessments, compliance gaps, and control reviews.
Developed and supported third-party risk management use cases by reviewing vendor security evidence, assessing controls and compliance requirements, identifying gaps, documenting risks, and tracking remediation.
Used Microsoft Purview to support data governance, data security, privacy, information protection, and compliance requirements.
Reviewed and updated existing security protocols to align with industry regulations and organizational goals.
Managed third-party vendor relationships, ensuring compliance with established security standards and best practices.
Cloud Security Engineer
3 Years 8 Months
Lynk Remote Technologies | 04.2018 - 12.2021
Secured AWS infrastructure for Lynk's IoT, remote monitoring, video, and mobile applications, enhancing overall security posture.
Utilized AWS CloudTrail and CloudWatch for comprehensive logging, monitoring, and alerting, strengthening security investigations.
Employed Wiz CSPM and Terraform to identify AWS risks and standardize configurations, facilitating secure deployments.
Developed and implemented cloud security policies to protect sensitive data and applications.
Delivered regular reports on the status of organizational cloud security measures to key stakeholders, facilitating informed decision-making processes regarding risk management and ongoing improvement initiatives.
Information Security Analyst
2 Years 2 Months
Yehowa Medical Services | 06.2016 - 08.2018
Developed and updated security assessment plan documentation to meet federal certification and accreditation processes, ensuring compliance and effective risk management.
Conducted HIPAA audits and related NIST and PCI DSS IT reviews in accordance with annual audit plans.
Supported security-control implementation, assessment findings, remediation activities, and regulatory requirements.
Conducted security assessments to identify vulnerabilities in medical information systems.
Information Security Analyst
2 Years 2 Months
Nationwide Credit Corp | 02.2014 - 04.2016
Conducted IT control risk assessments, reviewing organizational policies, standards, procedures, and guidelines to enhance compliance and security posture.
Identified internal-control weaknesses, recommending improvements to strengthen security measures and operational efficiency.
Performed HIPAA and related IT security reviews according to annual audit plans.
Evaluated security controls, documented risks, and supported policy reviews, audit findings, and corrective-action recommendations.
Information Security Analyst
1 Year 8 Months
Cru Property Management | 06.2014 - 02.2016
Analyzed and updated risk assessments, privacy impact assessments, system security plans, security test & evaluation documentation, and POA&Ms to enhance compliance and security posture.
Analyzed and updated Risk Assessments, Privacy Impact Assessments, System Security Plans, Security Test & Evaluation documentation, and POA&Ms.
Identified privacy complaints and program gaps, recommending targeted remediation solutions to strengthen program effectiveness.
Supported risk mitigation and security-control implementation, contributing to comprehensive governance documentation.
Education
Bachelor of Science - Information Technology
University of Maryland, College Park | College Park | 05.2007
Associate of Science - Computer Information Systems
Montgomery College | Takoma Park | 12.2004
Skills
Core Skills & Frameworks: GRC & Risk Management | AI Governance | Cybersecurity | PCI DSS | SOC 2 | ISO 27001 | NIST | HIPAA | Cloud Security | Compliance Audits