Driven Vendor Risk Management Analyst from OneTrust with a proven track record in enhancing information security and regulatory compliance. Expert in documentation and strategic planning, I've significantly improved third-party risk assessments and security reviews. My collaborative approach and ability to forecast trends have fostered key industry relationships, ensuring compliance and safeguarding against potential risks.
●Knowledge of information security, technology, and regulatory frameworks (PCI DSS, ISO, NIST etc.).
●Collect evidence for SOC 1, SOC2, and HITRUST re-certifications annually conduct third-party risk assessments and security review of third-party agreements
●Develop and maintain third-party risk management program documentation and templates such as risk assessment processes, security questionnaires, security requirements in third-party agreements, assessment reports
●Maintain (IT) security and compliance policies and standards.
Assist team members, and external audit firms, contractors, and vendors to execute on GRC plans and initiatives
●·Manage incoming vendor risk assessments queries and oversee that due diligence evaluations of vendors are being performed and documented in the vendor risk management tool (Onspring).
●Review vendor files for completeness and work with business units to update the files accordingly (quality assurance).
●Leading efforts to define and develop vendor management methods, governance, processes, and metrics.
●Completing due diligence regarding risk of third party and negotiate as needed.
●Evaluate information security posture of potential and existing vendors by reviewing SOC1 and SOC2 reports or security questionnaires to ensure compliance.