Summary
Overview
Work History
Education
Skills
Certification
Timeline
background-images

Joshua Obiossai

San Antonio,Texas

Summary

Dynamic Shipping Analyst with expertise in compliance management and risk assessment at GXO Logistics. Proven track record in streamlining audit processes and enhancing vendor performance metrics. Skilled in utilizing OneTrust and JIRA, while fostering team collaboration to implement effective remediation strategies. Committed to maintaining data confidentiality and operational excellence.

Overview

10
10
years of professional experience
1
1
Certification

Work History

Shipping Analyst & Compliance

GXO Logistics
06.2024 - Current

Joshua Obiossai is a highly qualified Certified Information Systems Auditor (CISA) and GRC professional with nine years of experience specializing in the documentation and communication of complex cybersecurity requirements. His background is a near-perfect match for this role, as he possesses the necessary technical depth to analyze security controls and the practical experience to create easily accessible policies, procedures, and assorted documentation for the Integrated Security Department.

GRC Analyst

United Health Group
03.2022 - 05.2024
  • Perform gap analyses to identify security control deficiencies.
  • Lead comprehensive assessments of high-risk vendors, analyzing various risk aspects and conducting periodic reassessments to monitor changes.
  • Streamline audit processes for HITRUST, SOC 2, and HIPAA.
  • Proactively manage policy/control exceptions, prioritizing compliance and confidentiality.
  • Collaborate with teams to refine incident response protocols.
  • Continuously monitor vendor performance against contracts, SLAs, and industry standards, escalating critical issues.
  • Offer actionable mitigation strategies to vendors.
  • Oversee risk metrics, reported data, and maintain documentation in OneTrust, ensuring complete data upload and assisting in Trust Portal setup.
  • Employ standardized methods (SIG and IRQ) for accurate risk assessments.
  • Utilize JIRA and Knowbe4 to manage tasks and employee training.
  • Develop and maintain information security program documentation.
  • Identify gaps in third-party vendor controls and implement remediation plans.
  • Review and evaluate compliance assessment results and document corrective actions.
  • Assist sales and product teams with answering security questionnaires.

Third-Party Risk Analyst

Wells Fargo
06.2019 - 02.2022
  • Conducted risk and control assessments for medium and high-risk third-party service providers, ensuring the effectiveness of their control environments.
  • Evaluated the security posture of vendors through the analysis of SOC reports, penetration test results, and Business Continuity/Disaster Recovery/Incident Response Plans.
  • Reviewed critical vendor documentation, including financial statements, credit reports, legal contracts, and business licenses, to assess overall risk.
  • Performed thorough due diligence on prospective vendors, analyzing their financial stability, regulatory adherence, and potential risk exposure.
  • Collaborated with internal stakeholders to effectively navigate and mitigate risks across critical business areas, including supply chain, distribution channels, and regulatory compliance.
  • Proactively identified and documented potential risks associated with new organizational initiatives and evolving operational landscapes.
  • Developed and implemented standardized methodologies for collecting comprehensive vendor data, significantly improving data accuracy and operational efficiency.
  • Successfully expanded the third-party risk management program to international operations, adapting processes to comply with diverse regional regulations.
  • Utilized RSA Archer to efficiently track assessment progress, manage identified findings, and generate key risk metrics for presentation to senior leadership.

Cybersecurity Analyst

MoneyGram
03.2016 - 05.2019
  • Led evidence collection for annual NIST 800-53 assessments, ensuring all control requirements were met.
  • Orchestrated the annual evidence collection process, ensuring flawless adherence to control requirements.
  • Conducted analysis on logs, reports, and configuration data.
  • Developed and managed a comprehensive system for both internal and external access.
  • Produced reports and presentations for assessors, highlighting findings, remedial actions, and compliance progress.
  • Managed the coordination of remediation activities, monitored progress, and ensured timely completion.
  • Collaborated with risk owners, security engineers, system owners, and management on remediation plans and implementation.
  • Provided training and support to internal stakeholders on requirements and evidence collection procedures.

Education

Bachelor of Arts - HISTORY AND INTERNATIONAL RELATIONS

Lagos State University

Skills

  • Compliance Management
  • Risk Management
  • Due Diligence
  • Risk Assessment
  • Audit and Control Management
  • Audit Processes
  • Penetration Testing
  • Incident Response
  • Security Monitoring and Analysis
  • Security Fundamentals
  • Shipping Documentation
  • Supplier Communication
  • Inspection and Quality Control
  • Hazmat and International Shipping
  • Warehouse Safety
  • Analytical Thinking
  • Team Collaboration
  • RSA Archer
  • OneTrust
  • Knowbe4
  • Shipping documentation
  • Microsoft Sentinel
  • Wazuh
  • Google Chronicle
  • Google Cloud
  • Microsoft Defender
  • Microsoft 365
  • ServiceNow
  • Jira/Confluence
  • SharePoint
  • Teams
  • Google Docs
  • Windows
  • SQL
  • Python
  • Microsoft Office
  • SOC 2 (Type 1 & 2)
  • PCI-DSS
  • HIPAA
  • GRC
  • SIG
  • HITRUST
  • ISO 27001/2
  • NIST 800 series
  • FedRAMP
  • Vendor/Supplier Security Audit
  • FIPS 199
  • FISMA
  • Cybersecurity Technical Writing (Policies, Standards, Procedures)
  • Third-Party Risk Management
  • Business Continuity & Disaster Recovery (BC/DR)
  • SDLC Security Controls Implementation
  • Supplier Management
  • Risk Assessment & Mitigation Analysis
  • Access Control Management
  • Contingency Plan
  • Policy Review
  • Continuous Monitoring
  • Artifacts Gathering
  • Remediation

Certification

  • Certified Information Systems Auditor (CISA), 2024
  • CompTIA Security+ ce Certification, 2024
  • CISM, In-View
  • Certified SAFe 5 Scrum Master, 2023
  • Professional Scrum Master I (PSM I), 2021

Timeline

Shipping Analyst & Compliance

GXO Logistics
06.2024 - Current

GRC Analyst

United Health Group
03.2022 - 05.2024

Third-Party Risk Analyst

Wells Fargo
06.2019 - 02.2022

Cybersecurity Analyst

MoneyGram
03.2016 - 05.2019

Bachelor of Arts - HISTORY AND INTERNATIONAL RELATIONS

Lagos State University
Joshua Obiossai