
Results-driven Cybersecurity GRC professional with over 10 years of expertise in governance, compliance, and operational risk management within regulated manufacturing settings. Skilled in enhancing control maturity and regulatory readiness through effective vendor oversight, incident analysis, and data-driven compliance monitoring. Experienced in implementing NIST CSF, ISO 27001, and compliance reporting to strengthen security frameworks.
· Supported Sr. ISSO by assisting the implementation of NIST RMF (via 800-37) ensuring accurate categorization (FIPS-199 and 800-60).
· Meticulously evaluated over 18 controls of the NIST Cybersecurity Framework (CSF) for the cybersecurity posture for a potential acquisition company in an acquisition deal.
· Reviewed, evaluated, and identified additional business High Value Assets/Crown Jewels on Energy & Environmental Management, and updated applicable documents.
· Successfully led the revalidation of HVA risk management categorization based on CIA impact on business continuity, using High Water Mark analysis/rule.
· Successfully updated Access Control on energy and environmental emissions reporting system for policy and procedures, account management and account enforcement.
· Managed vendor performance by tracking 5 deviations from SOW and contracts of two major vendors to drive accountability on commitments mainly by reviewing deliverables against due dates and tasked to be performed.
· Maintained 100% compliance with integrity and regulatory requirements on energy and environmental pollution prevention and control, demonstrating strong control monitoring, documentation, and governance discipline.
· Implemented digital KPI dashboards enabling real-time monitoring of compliance and operational risk metrics, improving executive reporting and proactive governance oversight.
· Led cross-functional investigations into operational events, driving root cause analysis, corrective action tracking, and recurrence prevention to strengthen enterprise governance processes.
· Led governance and operational compliance for a 30-person operations team within a semiconductor manufacturing environment, strengthening control discipline, Health & Safety regulatory and compliance culture, and risk-aware decision making through structured coaching and performance management.
· Reviewed vendor’s draft security test case and exit criteria against NIST 800-5three Rev 5 controls and noted 3 discrepancies that required an update to the test cases.
· Reviewed, updated and implemented operation’s identification and authentication (IA), Personally Identifiable Information Process and Transparency (PT), and Access Control (AC) policy to ensure full compliance.
· Reviewed over 150 information security and environmental task assigned to engineers in Smartsheet and excel, ensuring they are entered concise and complete, while monitoring progress against due date and elevating risk where delays appear imminent.
· Managed sensitive data types such as HRIS, PII, PHI, and financial data
· Produced content for an Incident Response Procedure to help improve response time, and workflow standardization, demonstrating strong capabilities in process governance, risk assessment, and operational control management.
· Contributed to the generation of a bi-weekly Executive-level status report on key areas of risks associated with environmental reporting and process safety reporting tools migration.
· Improved compliance maturity by increasing annual employee health physical and IT training, and OSHA training compliance from 70% to 82%, strengthening internal control adoption and reducing operational and compliance risk.
Security Architecture: COBIT, CMMI, ISO 27001, NIST RMF, NIST CSF, Zero Trust
Regulatory Compliance: HIPAA, FISMA, NIST 800-53 R5, NIST 800-171, NIST RMF, NIST CSF, FedRAMP, SOX 404, SOC 2, PCI, GDPR, GLBA, SANS
Audited: Oracle E-Business Suite, Oracle 9i/10g, PeopleSoft, SAP, Azure, AWS, SQL Server, Active Directory, Windows, Routers, Firewalls, CrowdStrike, Splunk, SIEM, Vulnerability/Patch Management, NOC/SOC, JIRA
Applications: Microsoft Office (MS Word, Excel, Outlook, PowerPoint, Copilot), Visio, SmartSheet, CSAM, SharePoint, Remedy
Programming: SQL, PL/SQL, ChatGPT