PROFESSIONAL SUMMARY
Overview
Work History
Education
Skills
Certification
Timeline

NADIAN SONIA TANGOACHA

Empyrean Solutions
Dallas
1
Certification
7
years of professional experience

Governance, Risk, and Compliance (GRC) professional with experience strengthening IT controls, managing technology risk, and supporting organizations through complex audit and compliance requirements. Brings hands-on expertise across IT audits, risk assessments, control testing, third-party risk management, remediation tracking, and audit readiness, with working knowledge of frameworks including ISO 27001, NIST, SOC 1 & 2, PCI DSS, HIPAA, SOX, and GDPR. Proven ability to identify control gaps, organize audit evidence, improve compliance processes, and translate regulatory requirements into practical actions for technical and business teams. Known for partnering effectively across IT, security, business stakeholders, and external auditors to improve control effectiveness, strengthen governance, and maintain sustainable audit readiness.

Work History

IT COMPLIANCE AUDITOR

1 Year 7 Months
Empyrean Solutions | 01.2025 - Current
  • Perform IT compliance audits and control reviews based on ISO 27001, SOC 2, NIST, PCI DSS, HIPAA, and other applicable requirements.
  • Conduct risk assessments of IT systems, cloud environments, and business applications to identify control and compliance gaps.
  • Review controls and collaborate with responsible teams to address identified issues and track remediation activities.
  • Collect, organize, and maintain audit evidence and documentation for internal and external audit requests.
  • Support SOC 2 audit activities, including evidence collection, control testing, and communication with external auditors.
  • Review policies, procedures, and control documentation and recommend updates when requirements change.
  • Prepare audit reports and summarize findings and recommendations for management.
  • Work with IT, security, and business teams to address compliance requirements related to cloud and SaaS technologies.
  • Help maintain audit readiness by monitoring open requests, evidence submissions, and remediation items.
  • Key Achievements
  • Supported the company’s first SOC 2 Type II audit with zero major findings.
  • Helped improve audit testing processes, reducing manual effort by approximately 25%.

RISK & COMPLIANCE ANALYST

2 Years 6 Months
Calicode | 06.2022 - 12.2024
  • Performed risk and compliance assessments to identify control gaps and areas requiring remediation.
  • Supported third-party risk activities by reviewing vendor security documentation, questionnaires, and compliance information.
  • Evaluated vendors against requirements including GDPR, SOX, PCI DSS, and internal security standards.
  • Worked with cloud security teams to review risks associated with third-party cloud services.
  • Maintained risk registers and documentation for policies, procedures, and internal controls.
  • Tracked open risks and remediation activities and provided status updates to management.
  • Assisted with internal and external audits by gathering evidence and responding to audit requests.
  • Supported GDPR compliance activities related to data protection and privacy requirements.
  • Collaborated with business and technical teams to resolve identified compliance issues.
  • Helped improve the third-party due diligence and vendor compliance tracking process.
  • Contributed to a 30% reduction in audit findings through improved risk identification and control implementation.

GRC ANALYST

2 Years 3 Months
NTT DATA | 01.2020 - 04.2022
  • Performed risk assessments covering operational, security, and compliance risks.
  • Maintained the organization’s risk register and tracked mitigation activities.
  • Assisted with control assessments and testing to determine whether controls met internal and external requirements.
  • Gathered documentation and evidence for internal and external audits.
  • Followed up with stakeholders on outstanding remediation activities and compliance issues.
  • Reviewed and maintained policies, procedures, and control documentation.
  • Assisted with third-party risk assessments and vendor security questionnaires.
  • Prepared risk and compliance reports for management and other stakeholders.
  • Collaborated with IT, security, legal, and business teams to address identified risks.

Education

Bachelor of Science - Computer Science

Catholic University | Camerron | 01-2019

Skills

Governance
Risk & Compliance (GRC)
IT Risk Assessments
IT Audits
Control Testing
Regulatory Compliance
Third-Party Risk Management
Security Controls
Audit Preparation
Evidence Collection
Risk Registers
Remediation Tracking
Compliance Reporting
Policy & Procedure Management
Internal Controls
Process Improvement
Cross-Functional Collaboration
Frameworks: ISO 27001
NIST
SOC 1
SOC 2
PCI DSS
HIPAA
SOX
GDPR
GRC & Risk Tools: RSA Archer
MetricStream
ServiceNow
RiskWatch
LogicManager
Audit Tools: AuditBoard
ACL
Cloud: AWS
Azure; working knowledge of cloud security
risk
and compliance concepts.
Business Tools: Microsoft Excel
Word
PowerPoint
SharePoint
Jira
power BI
Tableau.

Certification

  • CompTIA Security+
  • Certified Information System Auditor (CISCA) In progress

Timeline

IT COMPLIANCE AUDITOR

Empyrean Solutions
01.2025 - CurrentRead More

RISK & COMPLIANCE ANALYST

Calicode
06.2022 - 12.2024Read More

GRC ANALYST

NTT DATA
01.2020 - 04.2022Read More

Catholic University

Bachelor of Science from Computer Science
Read More
NADIAN SONIA TANGOACHA