Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Emmanuel Boateng

Buford,GA

Summary

Seeking an Information Security Analyst position in a growth-oriented organization with a focus on Risk Assessments, System Security Monitoring and Auditing, Audit engagements, HIPAA Compliance Assessments and Testing Information Security Controls. Information Security Specialist with passion for aligning security architecture plans and processes with security standards and business goals. Extensive experience developing and testing security framework for cloud-based software. Versed in robust network defense strategies.

Overview

12
12
years of professional experience
1
1
Certification

Work History

Senior Information Security Analyst

Saia LTL
05.2022 - Current
  • Lead the development and implementation of the system-wide risk management function of the information security program to ensure information security risks are identified and monitored
  • Internally assess, evaluate and make recommendations to management regarding the adequacy of the security controls for Saia information and technology systems
  • Develop, publish, and maintain information security policies, standards, and control procedures
  • Maintain the policy lifecycle management function, ensuring information technology and security policies are reviewed and updated on a regular basis
  • Work closely with the Information Security Risk Management team to design, document, and test controls aligned to mitigate IT risks within the IT organization
  • Maintain the control inventory and control mappings to security compliance frameworks such as NIST CSF/800-53
  • Conduct regular risk-based compliance testing of information security controls, reporting exceptions and monitoring remediation efforts
  • Act as a consultant to the information security and information technology departments, providing guidance and helping to mature the overall security posture of the organization
  • Audit the effectiveness of the Saia information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies and regulations
  • Document, maintain and audit Saia Business Continuity Plan, policies, and procedures
  • Work with Internal Audit, and coordinate and track all information technology and security related audits including scope of audits, business units involved, timelines, auditing agencies and outcomes

IT Security Analyst

Intec Logic Global, LLC
11.2017 - 01.2022
  • Assisted with analysis and documentation of audit remediation actions related to security for business associates
  • Helped manage compliance with HIPAA, ISO 27001, NIST, SOC 2 Type II requirements
  • Conducted security assessment on vendors to identify a risk that includes potential exposure areas and helped develop strategies to mitigate risks
  • Completed internal risk assessments against regulatory requirements and audit preparation
  • Assist in our security compliance programs, including ISO27001, ISO27701, PCI-DSS, GDPR, and related local cybersecurity and privacy regulations
  • Evaluate technical and organizational controls to ensure effectiveness and compliance, including managing the control remediation efforts

Information Security Analyst

Walmart Inc
01.2015 - 07.2017
  • Involve in information security risk identification that includes Cloud services, security assessment, and risk ranking
  • Uses SIG (Standardized Information Gathering) questionnaire, Cloud Security Alliance control matrix, and reviewed security policies, SOC (Service Organization Control) 2 Type II reports
  • Ensure that all third parties adhered to all compliance requirements based on the OCR protocol, NIST SP 800-66 rev 1
  • Document findings, engaged in remediation, and did follow ups to ensure identified gaps were remediated
  • Analyze risk to identify the vulnerabilities and created and implemented plans to remediate the identified risk
  • Perform security risk assessments on systems, using the HIPPA, ISO 27001, NIST 800-53rev5 and NIST cybersecurity frameworks
  • Engage vendors in remediation activities making sure all identified findings are remediated on time
  • Ensure that vendors continue to provide acceptable security to minimize risks to the organization
  • Provide recommendations to the business units to add to contracting agreements with the vendors
  • Escalated complex issues with vendors to management.

Sales Specialist

Apple Inc
01.2012 - 01.2015
  • Uncovering customers' needs then following with enlightening solutions
  • Advising, selling, and helping customers set up their products
  • Interacting and discovering customers passions and aligning that with the product that suits their needs
  • Assisted Customers as an at home advisor
  • Certification:
  • Working toward CRISC and CISM
  • CompTIA Security

Education

Bachelor of Science - Health Administration

University of Houston - Clear Lake
Houston, TX
12.2020

Skills

  • Third Party/Vendor Risk Assessment
  • Internal Security Risk Assessment
  • Risk Mitigation
  • Vulnerability Analysis
  • Use Cases
  • Security Implementation
  • Risk Management Framework
  • Information Protection
  • Plan of Actions & Milestones (POA&M)
  • Compliance Training
  • Information Auditing
  • Leadership Development
  • Threat Hunting
  • Business Continuity
  • Risk Management Evaluations
  • Compliance with Security Requirements
  • Training Programs
  • Data security

Certification

CompTIA Security +

Timeline

Senior Information Security Analyst

Saia LTL
05.2022 - Current

IT Security Analyst

Intec Logic Global, LLC
11.2017 - 01.2022

Information Security Analyst

Walmart Inc
01.2015 - 07.2017

Sales Specialist

Apple Inc
01.2012 - 01.2015

Bachelor of Science - Health Administration

University of Houston - Clear Lake
Emmanuel Boateng