Summary
Overview
Work History
Education
Skills
Timeline
Generic

Nancy Ndifor

Capitol Heights

Summary

Performance driven GRC Analyst with experience implementing governance risk management and compliance strategies. proficient in regulatory frameworks including GDPR, HIPPA, COBIT, COSO, HITRUST, and SOX and IT Security Frameworks ISO27001, GLBA, NIST, SOC2, CIS Control and PCI-DSS, ensuring compliance and risk management strategies. Enhanced operational efficiency by 25% through the implementation of automated compliance monitoring systems. directed successful audits leading to a 98% compliance rating. Recognized for conducting risk assessments and developing mitigation plans, resulting in a 30% reduction in security incidents.

Overview

4
4
years of professional experience

Work History

GRC Analyst

ExcelMindCyber
11.2025 - 12.2025

• Participated in a comprehensive GRC training program, enhancing my understanding of Governance, Risk, and Compliance.
• Gained insights into the critical frameworks necessary for effective GRC implementation in organizations.
• Developed skills to assess and apply GRC principles across various business environments.

CYBERSECURITY FUNDAMENTAL

IBM
12.2025 - 12.2025
  • Cryptography
  • Cyber Attacks
  • Cybersecurity
  • Cybersecurity Processes
  • Cybersecurity Risk Management
  • Cyber Threat Analysis
  • Cyber Threat Intelligence
  • Incident Response
  • Information Security
  • PWID-B0454800
  • Security Strategies
  • Social Engineering
  • Threat Analysis
  • Threat Detection
  • Vulnerability Management

CYBERSECURITY ANALYST INTERN

TaTa Forage
11.2025 - 12.2025
  • Documented processes related to security incident handling and malware analysis techniques.
  • Maintained awareness of current industry trends in information technology security.
  • Developed and implemented IT security policies, procedures, and standards to ensure secure systems operations.
  • Performed regular reviews of system access rights to ensure compliance with organizational policies.
  • Collaborated with other teams within the organization to resolve complex technical problems.
  • Performed risk assessments and executed tests of data processing system to ensure functioning of data processing activities and security measures.

IT Auditing & GRC Bootcamp

Thinkcloudly
10.2025 - 11.2025

Participated in an intensive boot camp focused on IT auditing and Governance, Risk, and Compliance (GRC).
• Gained comprehensive knowledge of essential frameworks applicable to IT auditing in various organizations.
• Developed skills in risk assessment and compliance evaluation, enhancing my ability to contribute to organizational integrity.

  • Proven ability to learn quickly and adapt to new situations.
  • Excellent communication skills, both verbal and written.
  • Worked well in a team setting, providing support and guidance.
  • Passionate about learning and committed to continual improvement.
  • Organized and detail-oriented with a strong work ethic.

ADMINISTRATION ASSISTANT

Cross Country Nurses
08.2021 - 03.2023
  • Helped managers in other departments with projects as needed.
  • Handled phone calls in a professional manner and responded to customer inquiries promptly.
  • Created spreadsheets and maintained databases utilizing Microsoft Excel.
  • Processed invoices accurately in accordance with company policy and procedures.
  • Composed emails, letters and other correspondence on behalf of senior management team.
  • Served as primary point of contact for facilitating operational and administrative inquiries.
  • Greeted visitors warmly and professionally upon arrival at the office premises.
  • Organized office operations and procedures, such as filing systems, data entry, mail distribution and bookkeeping.
  • Assisted with staffing, including finding staff when employees called out on short notice.

Education

Bachelor of Science (B.S.) - Cybersecurity

American Public University System
CharlesTown, WV

Skills

  • Governance Risk & Compliance (GRC)
  • Risk Assessment & Mitigation
  • Strategic Compliance Management
  • GRC Framework Implementation
  • Risk Management
  • ISO 27001
  • Policy & Procedure Development
  • Vulnerability Assessment
  • Regulatory Compliance
  • Microsoft office
  • Analytical thinking
  • MS Excel
  • Time management
  • NIST Framework
  • HIPPA

Timeline

CYBERSECURITY FUNDAMENTAL

IBM
12.2025 - 12.2025

GRC Analyst

ExcelMindCyber
11.2025 - 12.2025

CYBERSECURITY ANALYST INTERN

TaTa Forage
11.2025 - 12.2025

IT Auditing & GRC Bootcamp

Thinkcloudly
10.2025 - 11.2025

ADMINISTRATION ASSISTANT

Cross Country Nurses
08.2021 - 03.2023

Bachelor of Science (B.S.) - Cybersecurity

American Public University System
Nancy Ndifor