Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Donna Heise

Sr GRC Analyst
West Union,OH

Summary

Governance, Risk, & Compliance Analyst with 9+ years of experience, excels in establishing and enhancing IT Vendor Management Programs in alignment with SOC 2 and PCI DSS standards. Demonstrates proficiency in deploying Third-Party Risk Management using OneTrust software, ensuring stringent compliance and risk mitigation. With strong analytical skills, attention to detail, and a solid understanding of regulatory frameworks, this professional is adept at enhancing security processes and compliance across all operational levels. Results-oriented Analyst skillful in managing and breaking down large volumes of information. Proactive at heading off issues in operations, workflow and production by uncovering trends affecting business success.

Overview

9
9
years of professional experience
1
1
Certification

Work History

Sr. GRC Analyst

Upgrade, Inc
Remote
10.2022 - Current
  • Established IT Vendor Management Program in alignment with SOC 2 and PCI DSS standards
  • Spearheaded the implementation of OneTrust, a Third-Party Risk Management and Due Diligence Software
  • Designed monthly physical security processes for all sites
  • Ensured compliance with investor requirements and industry standards
  • Contributed to the company's risk mitigation strategies
  • Developed and deployed IT Vendor Management Program enhancing SOC 2 and PCI DSS compliance
  • Launched Third-Party Risk Management using OneTrust, elevating security and compliance.
  • Increased efficiency by streamlining data analysis processes and implementing automation tools.

Business Analyst

Rose International, Compliance
Remote
10.2021 - 10.2022
  • Contracted to Kaiser Permanente Privacy, Security, Technology Compliance Department to assist with development of a new line of business
  • Assisted with the review and gathering of evidence for CMMC certification using NIST 800-171 controls
  • Coordinated and scheduled meetings with stakeholders to explain requirements and assist with the gathering of evidence
  • Administrator of SharePoint lists and site integrating Power BI dashboards

IT Risk and Compliance Specialist

Hexion Inc
Remote
12.2020 - 10.2021
  • Liaison between business and third-party provider of Business Continuity/Continuity Planning to ensure adequacy of recovery plans align with organizational expectations
  • Supported the development and implementation, as a project manager, of the system-wide Information Technology Risk Management Software as a Service Solution
  • Developed and maintain Information Technology Policy Library
  • Partnered with Internal Audit to on security assessments and audit
  • Partnered with Data Privacy to ensure Information Technology Data Privacy Impact Assessment completed.

Security & Compliance Business Analyst

Artech Information Systems LLC
Remote
06.2019 - 12.2020
  • Review of applications for Proof-of-Concept process to determine compliance of various regulations in the healthcare environment, including HIPAA and PCI
  • Assist with the development of process documentation as well as metrics for reporting to leadership.

Information Security Analyst

AIM Consulting
Denver CO
03.2018 - 06.2019
  • Review applications for compliance with the EU General Data Protection Regulation and the New York Department of Financial Cybersecurity regulation as well as organization security policies
  • Prepared documentation and evidence to ensure successful compliance and to assure CIO organization has met the requirements for signoff
  • Assisted with documentation of vulnerabilities and remediation tracking
  • Assisted with process improvement documentation for encryption and security policies.

Security Assurance Compliance Analyst

Leidos, Centennial CO
Centennial CO
01.2018 - 03.2018
  • Complete analysis and assessment of compliance with security and privacy laws, information technology regulations, guidance, and direction, including the Federal Information Security Management Act (FISMA), National Institute of Standards and Technology (NIST) guidance, Federal Information Processing Standards (FIPS), applicable Office of Management and Budget (OMB) memorandum
  • Responsible for review of security compliance forms, risk rating scores (CVSS), and entry into proprietary application for reporting
  • Compiled and distribution of monthly scorecards to site leadership
  • Responsible for the completion and review of Security System Plan for enterprise in both NIST 800-53a rev four and rev5 controls.

TekSystems | Security Assurance Compliance Analyst

Centennial CO
Greenwood Village CO
10.2017 - 01.2018
  • Complete analysis and assessment of compliance with security and privacy laws, information technology regulations, guidance, and direction, including the Federal Information Security Management Act (FISMA), National Institute of Standards and Technology (NIST) guidance, Federal Information Processing Standards (FIPS), applicable Office of Management and Budget (OMB) memorandum
  • Reviewed security compliance forms and entered data into proprietary application for reporting
  • Compiled and distributed monthly scorecards to site leadership
  • Responsible for the completion and review of Security System Plan for enterprise in both NIST 800-53a rev four and rev5 controls.

Security & Compliance Project Manager

TechOne Staffing, Denver
Greenwood Village CO
04.2017 - 10.2017
  • Followed the RACI model of compliance using NIST-800-66, NIST 800-53a controls for assessments
  • Provided advance compliance program management to focus on identified controls alignment for HIPAA, PHI, ePHI, PII, PCI, SOX, FDA, best practice, and organization policies.

Security Compliance Analyst

APEX Consulting
Greenwood Village CO
05.2015 - 12.2016
  • Profiled over 2,000 applications, with proprietary software, to determine risk calculations for HIPAA Security Program via assessments/audits for HIPPA, PHI, ePHI, PII, PCI, SOX, FDA, best practice, and organizational policies
  • Documented risk analysis and control assessment results, providing daily, weekly, and monthly dashboard and metrics for presentation to executive management
  • Created use case scenarios for user access testing (UAT) to ensure wide variety of scenarios were tested during risk evaluation.

Education

Bachelor of Science - Healthcare Administration & Management

CSU-Global
Greenwood Village, CO
08.2014

Associates of Applied Business Cum Laude - Applied Business, Accounting Technology

University of Cincinnati
Batavia, OH
03.2011

Skills

    • Project Management (Skillful)
    • Process/Procedure (Skillful)
    • Implementation (Skillful)
    • Team Building (Skillful)
      • Time Management (Experienced)
      • Strong Analytical Skills (Experienced)
      • Understanding of Regulatory Frameworks (Experienced)
      • User Access Testing (Skillful)

Certification

  • Certified Data Privacy Solutions Engineer (CDPSE), ISACA
  • Certified Security+, CompTIA

Timeline

Sr. GRC Analyst

Upgrade, Inc
10.2022 - Current

Business Analyst

Rose International, Compliance
10.2021 - 10.2022

IT Risk and Compliance Specialist

Hexion Inc
12.2020 - 10.2021

Security & Compliance Business Analyst

Artech Information Systems LLC
06.2019 - 12.2020

Information Security Analyst

AIM Consulting
03.2018 - 06.2019

Security Assurance Compliance Analyst

Leidos, Centennial CO
01.2018 - 03.2018

TekSystems | Security Assurance Compliance Analyst

Centennial CO
10.2017 - 01.2018

Security & Compliance Project Manager

TechOne Staffing, Denver
04.2017 - 10.2017

Security Compliance Analyst

APEX Consulting
05.2015 - 12.2016

Bachelor of Science - Healthcare Administration & Management

CSU-Global

Associates of Applied Business Cum Laude - Applied Business, Accounting Technology

University of Cincinnati
Donna HeiseSr GRC Analyst