Enthusiastic security practitioner with a passion for the proactive nature of GRC. Has shown proficiency in auditing, assessing risk, and developing governance according to NIST frameworks and relevant regulations, such as HIPAA and Sarbanes-Oxley.
-Performed an audit against a subset of 100 NIST SP 800-53 security controls that included interviews, document review, and system testing as evidence of compliance
-Performed a semi-quantitative risk assessment using the NIST SP 800-30 methodology to identify high-risk vulnerabilities within a system
-Developed an information security policy appropriate for SMEs