Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

SCHNEIDER FONCHAM

Summary

IT Security Professional highly regarded for demonstrated experience assessing technical solutions. High Expertise in directing Risk, Audit and Compliance Management initiatives while establishing, implementing, and enhancing key information security objectives and control frameworks. Maximize productivity skills and experience in reviewing and implementing internal control policy and procedures to ensure efficiency to mitigate risks gained over a 6 plus years period of professional record. Good knowledge of governance risk and controls related to various compliance Proficient in determining system requirements. I am looking to use my skills and expertise to help achieve security for Enterprise-wide information risk goals and objectives of Privacy, Confidentiality, Integrity and Availability (CIA).

Overview

11
11
years of professional experience
1
1
Certification

Work History

Risk/Audit/Compliance Analyst

BANK OF AMERICA (WTS)
01.2019 - Current
  • Responsible for analyzing all new vendor contracts and pointing out areas of improvement to management. Develop, Implement, and maintain policies, procedures, standards, and guidelines per applicable regulations including NIST 800-171 Framework Controls, ISO 27001, GDPR, CCPA PCI DSS, and HIPAA
  • Review Information Security Audit reports such as SOC 1 or SOC 2 Reports & SIG questionnaire to make sure it complies with company’s control standards.
  • Analyze the information to identify information security weaknesses or non-compliance with industry standards such as NIST. PCI-DSS, ISO 27001, NYDFS, etc.
  • Acts as a liaison during organization internal and external audit Conducted reviews of security documents updated by the ISSO to ensure FISMA compliance, reviewing and validating of items uploaded into the POA&M tracking tool in support of remediated findings and work on mapping the SIG and control standards to the VRA Questionnaire
  • Prior experience working with Data Management applications, Statistical Data Analysis systems, Clinical Data Entry applications, Electronic data capture systems. Familiarity with regulated systems (GxP, CFR 21 Part 11) and systems validation; Life Sciences, Biotech or pharmaceutical industry experience preferred Comfortable with project methodologies, and familiarity with tools including MS Project and Excel
  • Ensure all vendor relationships are documented in the VRM system and all contracts related to vendors that provide outsourced services are uploaded in the system in accordance with the VRM policy.
  • Manage the functionality of the VRM system which is the central repository for vendor contracts and related documents and is the record of all vendor due diligence and issue management and remediation.
  • Work with the, Legal, Compliance, Information Risk Management, Purchasing, and Internal Audit to ensure consideration of Third-party risk within their own risk domain framework.
  • Advise clients on software configuration recommendations, complete configurations, and lead the configuration efforts with staff completing the configurations Training the client team on their new software usage based on custom configurations completed and Take the lead in defining issues and ideas to be studied as well as the approach (methodological and technical) to be used in addressing studies and projects. Creates and/or develop new methods of analysis, database design and performance measurement or, in some cases, adaptation of existing solutions to new areas.
  • Ensure all vendors are classified and assessments completed in accordance with the VRM policy.
  • Familiar with sig tools such as JIRA, Splunk, and Bit sight,maintain effective communication with vendor relationship manager during continuous monitoring of vendors qualify application responses by facilitating meetings with business owners and third- party contacts. Assessed Vendor risk profile to determine the C.I.A rating, conduct assessment of vendors and prepare VRA Report.
  • Coordinate with stakeholders to initiate scope and plan controls assessments of new and existing vendor engagements.
  • Responsible for analyzing all new vendor contracts and pointing out areas of improvement to management.
  • Using GRC tools like Practical Threat Analysis (PTA) and The GRC Stack, which aims at synchronizing information and activity across governance, risk management and compliance in order to operate more efficiently, enable effective information sharing, more effectively report activities and avoid wasteful overlaps.
  • Assess completed questionnaire and supporting documentation to validate vendor appropriate implementation of information security controls.
  • Communicate vendor information security issues to stakeholders, ensuring their understanding of associated risks and actions needed to remediate those risks.
  • Validate evidence from vendors before remediation plans are closed.

Risk Analyst

Ebay (Remote)
09.2017 - 07.2019
  • Act as remediation analyst with vendors in remediating findings discovered during or after assessments.
  • Making sure that vendors are following regulatory requirements and information security policy, applicable procedures, processes, and standards.
  • Supports Third Party onboarding, ongoing monitoring, and Third Party off-boarding.
  • Answering any internal stakeholder questions related to ongoing assessments.
  • Create and institute policies and procedures to conduct Vendor Risk Assessments (VRA).
  • Worked with the project leadership and technical team to develop strategies and plans to enforce security requirements and address identified risks.
  • Ensured all identified gaps and results are documented.
  • Ensured adherence to all federal, state and local laws regulations including but not limited to the FISMA, HIPAA and other compliance framework.
  • Assisted in designing and implementing risk mitigation strategy to foster organization cyber resilience.
  • Translated security vulnerabilities, assessed risks, developed mitigation plans, tracked and documented any accepted residual risks.
  • Gather evidence for internal control assessment and also for ISO 27001 Audit.

IT Compliance Analyst

Computer Information System Health Care
Maryland
07.2015 - 08.2017
  • Responsible for conducting vendor risk assessments, with a focus on Information Security and Privacy.
  • Reviewed vendor compliance from a BCP/DR and Data Security perspective.
  • Worked with the appropriate business users and technology owners to ensure that for any identified risks that require mitigating actions are plans, developed and executed.
  • Reviewed services provided by vendor and defined scope of assessment based on the Standard Information Gathering (SIG) questionnaire.
  • Identified the top human risks to the organization and the behaviors that need to change to mitigate those risks.
  • Assessed operational fitness of assigned third parties through due diligence reviews.
  • Articulate writing skills to support development content and communicating information security principles at all levels from executives to non-technical employees.
  • Reviewed and analyzed SOC 1, SOC 2 reports of third parties/vendors and other evidence provided during a risk assessment.
  • Reviewing vendor contracts, onboarding, and monitoring vendors performances.
  • Daily activities include performing vendor risk assessments, reviewing attestation documentation (e.g. SOC 2), and completing vendor/supplier security questionnaires.
  • Coordinate audit activities with audit clients and interact with store support and management staff while maintaining departmental goals, policies, and initiatives.

Junior Security Analyst

AT&T
12.2014 - 07.2015
  • Assisted in the development, implementation and maintenance of policies, procedures, standards, and guidelines in accordance with applicable regulations including NIST 800-53 Framework Controls and HIPAA.
  • Carried out HIPAA Risk Assessment on Third Party Vendors and identified gaps on these assessments.
  • Created information security documentation and workflows to assist with incident response, audits, and vendor requirements.
  • Assisted management in overseeing security incident handling efforts in response to a detected incident and coordinated with other stakeholders as directed.
  • Directed the creation and organization of a comprehensive workflow, training, and security awareness for the department.
  • Assisted the CISO with any ancillary projects needed, including creation of Visio workflows, document review and legal research.

Education

Bachelor’s Degree - computer science

University of Buea
01.2014

Skills

  • Microsoft Suit, Analytical skills, Documentation
  • Due diligence, SOC 1, 2 Audit, SIG Questionnaire, Vendor Risk/ Third Party Security Risk Management
  • ISO 27000 / PCI DSS / HIPAA / NIST / FISMA / HITRUST / NYDFS
  • Plan of Action and Milestones (POA&M), Corrective Plan of action
  • Risk Assessment, Vulnerability Management , Archer eGRC Platform or any other Similar Platform, IT Audit, Privacy, / JIRA/ GDPR/CCPNA/AWS/CLOUD SERVICES/Splunk, New-York Financial Regulation/ Share point site, Experience in Application controls and risk assessments

Certification

  • CompTIA Security+ Certified
  • Certify Information System Auditor (CISA) Certified
  • Certified Information Systems Security Professional (CISSP) in progress

Timeline

Risk/Audit/Compliance Analyst

BANK OF AMERICA (WTS)
01.2019 - Current

Risk Analyst

Ebay (Remote)
09.2017 - 07.2019

IT Compliance Analyst

Computer Information System Health Care
07.2015 - 08.2017

Junior Security Analyst

AT&T
12.2014 - 07.2015

Bachelor’s Degree - computer science

University of Buea
SCHNEIDER FONCHAM