Highly qualified proactive and results-oriented professional with over 7 years of experience as vendor Risk Analyst. Experienced in TPRM process optimization, vendor security reviews, and risk mitigation. Good knowledge of governance risk and controls implementation related to various industry standards/compliances. Self-motivated individual with a solid understanding of compliances, such as NIST SP 800 series and ISO 2700. Full understanding of the Federal Risk and Authorization Management Program FEDRAMP, Federal Information Security Management Act (FISMA), Health Insurance Probability and Accountability ACT (HIPAA) and Payment Card Industry Data Security Standard (PCI-DSS). Possess knowledge on the Risk Management Framework (RMF) process. Personal objectives are to protect the information system by using acquired skills acquired to help achieve the Enterprise-wide goal to maintain Confidentiality, Integrity and Availability. TECHNICAL SKILLS & TOOLS Risk Management Framework (RMF) Fed RAMP, OMB, FISMA Vulnerability Scanning Vulnerability Management Regulatory requirements such as GDPR, CCPA, HIPAA, ISO 27001,PCI DSS. Security Assessment Plan (SAP) Security Assessment (SAR) Standard Operating Procedures (SOP) Regulatory requirements such as GDPR, CCPA, HIPAA, ISO 27001,PCI DSS. Knowledge of industry leading security frameworks such as NIST, ISO, and COBIT. System Security Plan (SSP) Plan of Action & Milestone (POA&M).
o Identification of third parties not in the vendor inventory database
o Engaging Vendor Managers and/or vendors for onboarding of third parties
o Onboarding third party engagements including performing/facilitating/documenting all efforts and results
o Conducting assessments on the third parties and identifying potential risk
o Continued monitoring and management of third party engagements, as defined through the help of BitSight, LexisNexis and other relevant tools.
evidence to validate controls implementation.