Cybersecurity and GRC Analyst with 4+ years of experience supporting security control assessments, cyber risk management, compliance auditing, vulnerability management, DLP investigations, phishing response, and remediation tracking across public-sector, consulting, and enterprise environments. Experienced in evaluating controls against NIST SP 800-53/800-53A, CIS Controls, RMF, and security policies. Skilled at reviewing evidence, validating control implementation, identifying compliance gaps, assessing risk, coordinating with stakeholders, and translating technical findings into clear remediation plans that strengthen security posture and support audit readiness.
Overview
1
1
Certification
8
8
years of professional experience
Work History
System Security Analyst
New York State Department of Financial Services
New York
06.2024 - Current
Conducted security risk assessments by reviewing documentation, artifacts, policies, and evidence to evaluate control effectiveness, identify compliance gaps, and support remediation planning.
Assessed 50+ CIS security controls, recommending actions to stakeholders that strengthened remediation efforts and improved overall security posture.
Communicated assessment findings, risk concerns, and remediation recommendations to supervisors, system owners, and business stakeholders to support informed security decisions.
Collaborated with supervisors and cross-functional stakeholders to align security policies, procedures, and control expectations with business needs, regulatory requirements, and best practices.
Monitored and investigated DLP alerts on a weekly basis, identifying potential sensitive data exposure events, validating risk, reducing false positives, and escalating confirmed concerns for remediation.
Developed and executed targeted phishing simulation campaigns in KnowBe4, using realistic threat scenarios to improve employee awareness, reporting behavior, and organizational phishing resilience.
Reviewed and analyzed phishing incident reports for severity and organizational risk, escalating confirmed high-risk events to ITS Legal and Technology teams for prompt containment and remediation, resulting in a 30% increase in phishing reporting during the latest simulation campaign.
Executed security reviews for software requests and travel exception submissions in Jira, evaluating business needs and security risks to inform approval decisions.
Monitored security alerts and supported incident verification, risk analysis, documentation, escalation, and remediation activities.
Information Security Analyst (Security Control Assessor)
Infosys Inc
12.2022 - 03.2024
Oversaw and executed Control Assessments to guarantee that all security controls aligned with the security requirements outlined in the SSP.
Conducted security control assessments through control testing, stakeholder interviews, artifact reviews, and findings documentation, supporting remediation efforts and addressing recurring compliance gaps.
Created security reports summarizing risk assessments and recommending effective solutions to mitigate identified gaps and enhance security posture.
Developed security reports summarizing risk assessments and proposing effective solutions to mitigate identified gaps.
Collaborated with system administrators and security teams to streamline remediation workflows, contributing to a 25% reduction in remediation turnaround time for high-priority findings.
Communicated identified risks to key stakeholders, presenting updates on assessment progress and risk remediation progress.
Analyzed regular vulnerability scan reports using tools like Nessus and Qualys to identify and prioritize vulnerabilities based on severity and potential impact, facilitating timely remediation.
Supported ongoing monitoring activities by coordinating evidence updates, reviewing control status, and assisting Information Assurance teams with assessment and remediation tracking.
Compliance Analyst
Johnson & Johnson (US Tech Solutions)
New Jersey
08.2022 - 12.2022
Supported RMF-based security assessment and authorization activities, including control selection, evidence collection, assessment planning, control monitoring, and remediation documentation.
Tested security risk assessments using a variety of approaches, including scans, interviews, and documentation reviews, making sure that NIST SP 800-53A guidelines were followed.
Performed evidence gathering and quality assurance of the security controls implemented on the system.
Created Security Assessment Plans to document assessment scope, required evidence, tools, personnel, testing approach, and assessment objectives.
Delivered weekly status reports to system stakeholders on activities and assessment progress.
Coordinated security assessment report (SAR) documenting issues, findings, and recommendations from security control assessments.
Collaborated with system owners to identify and implement cost-effective solutions for mitigating system gaps and weaknesses.
Worked collaboratively with system owners to mitigate gaps and weaknesses in the system with cost-effective solutions.
Provided technical recommendations for addressing security vulnerabilities, enhancing compliance posture.
Collaborated in POA&M remediation activities to correct documented findings.
Systems Administrator
NFC Management
New York
06.2018 - 07.2022
Administered and supported hardware, software, operating systems, and end-user environments, ensuring compliance with security policies and access procedures.
Provided system administration and technical support across hardware, software, operating systems, and end-user environments while following established security policies and access procedures.
Provisioned hardware and software for users while following established security policies, access procedures, and configuration standards.
Diagnosed and resolved hardware, software, and operating system issues, enhancing system availability and facilitating business continuity.
Provided technical support to end users, troubleshooting IT issues and assisting with account, device, application, and connectivity concerns.
Executed system maintenance, software installation, and user support in alignment with internal procedures, contributing to secure technology operations.
Education
Bachelor of Science - Information Technology
CUNY Brooklyn College
Brooklyn, New York
06-2018
Associate of Science - Computer Information Systems