Information risk and compliance analyst with experience in conducting audits, performing risk assessments, and managing third-party vendor risk. Expertise in implementing ISO 27001, NIST, and GDPR frameworks to enhance compliance and governance. Proven ability to reduce organizational risk through effective risk management strategies.
Overview
5
5
years of professional experience
Work History
Third Party Risk Specialist
Connexus Credit Union
Wausau, Wisconsin
10.2025 - Current
Own and execute the end-to-end Third-Party Risk Management process, ensuring vendors meet security, regulatory, and contractual requirements throughout the lifecycle
Perform 30+ in-depth vendor risk assessments annually, analyzing SOC reports, security policies, insurance coverage, and BC/DR plans to evaluate control effectiveness
Identify control gaps and clearly document risk findings, partnering with stakeholders to drive remediation and reduce overall vendor risk exposure
Continuously monitor vendor security posture using Bitsight, proactively escalating risks and tracking issues through resolution
Work closely with relationship managers and business owners to streamline due diligence, improve turnaround times, and strengthen accountability
Information Risk and Compliance Analyst
Dinsmore & Shohl
Cincinnati, Ohio
02.2025 - 09.2025
Supported the daily execution of the Vendor Risk Management program, ensuring alignment with internal policies and external regulatory requirements
Conducted risk assessments and documented detailed findings, helping strengthen control visibility and support audit readiness
Assisted in developing and refining security policies, procedures, and documentation to improve overall governance practices
Collaborated with cross-functional teams to address risk gaps and align compliance efforts with business operations
Contributed to incident response and business continuity efforts, supporting timely identification and mitigation of potential risks
Information Risk and Compliance Analyst
Robert Bosch
Farmington Hills, Michigan
10.2021 - 02.2025
Led and supported risk assessments to identify security vulnerabilities, providing actionable recommendations to improve control effectiveness
Played a key role in ISO 27001 audits by coordinating evidence collection, validating controls, and supporting remediation of audit findings
Conducted impact assessments to evaluate data protection controls and identify gaps in security and risk management practices
Developed and delivered security awareness training, increasing employee understanding of security risks and best practices
Served as a trusted point of contact for business units, advising on security, risk, and compliance matters
Education
Bachelor of Arts - Cyber Defense and Information Assurance