Professional Summary
Overview
Work History
Education
Skills
Accomplishments
Affiliations
Certification
Languages
Timeline
Membership

Nini-Fua C. CHOFOR

SUMITOMO MITSUI Banking Corporation MANUBANK
Fayetteville,NC
2
Languages
1
Certification
12
years of professional experience

Senior Information Security Specialist with 8+ years of experience in Governance, Risk, Compliance, and Data Privacy. Strengthens organizational security posture through strategic planning, cross‑functional collaboration, and rigorous control assurance. Holds a Bachelor’s in Law and an MBA, offering a unique blend of legal, business, and technical expertise. Skilled in interpreting and implementing key regulatory frameworks including NIST 800‑53, ISO 27001, PCI‑DSS, CCPA, GLBA, and FFIEC.

Proven ability to translate regulatory requirements into actionable governance processes that enhance operational performance, reduce risk exposure, and improve audit outcomes. A strong communicator and analytical problem‑solver recognized for adaptability, continuous learning, and delivering high‑quality results that elevate enterprise security maturity.

Work History

Vice President - Sr. Specialist- GRC Operations

3 Years 11 Months
SUMITOMO MITSUI Banking Corporation MANUBANK | 10.2022 - Current
  • Spearheaded a SOC compliance readiness initiative driven by our clients' strategic requirements; coordinated engagement requirements between external consultants and internal business leaders through a comprehensive scope outline, control mapping, scheduled meetings and remediation process to achieve a fully audit-ready state
  • Designed and delivered executive KPI and KRI dashboards for Senior Management and board reviews, incorporating complex metrics across the organization into actionable insights that guided corporate strategy and investment decisions.
  • Directed the design and creation of a Cybersecurity Target Operating Module (TOM) leveraging the NIST CSF framework; guided the cyber team through a rigorous evaluation of the active threat landscape and existing defense layers to establish an audit ready future-state security posture.
  • Directed vendor risk governance and procurement reviews for critical vendors; critically evaluated RFP submissions to ensure third-party security postures aligned with the organization's policies and strategic goals.
  • Operationalized a multi-channel cyber security awareness program aligned with the FFIEC IT Examination Handbook, delivering targeted training initiatives and monthly executive blogs to internal staff and customers, significantly hardening the organization against social engineering threats.
  • Directed the comprehensive SOC review process for third-party entities, systematically identifying vendor-side vulnerabilities and ensuring absolute compliance with regulatory requirements and internal policies.
  • Conducted and finalized the enterprise GLBA Safeguards Rule Assessment, authorizing a strategic Executive Summary Report, and an Information Security Program for the Board of Directors, and Audit Committee, to define compliance status and future risk-mitigation roadmaps
  • Orchestrated cross-functional response efforts with the cyber engineering and operations teams to strategically address, remediate and close outstanding findings from both internal audits and external regulatory examinations.
  • Negotiated and finalized the scope of engagement for internal and regulatory Cyber audits, serving as the primary liaison to external examiners and Internal Audit, while mobilizing internal teams to collect, validate and present technical compliance evidence.
  • Governed the end-to-end annual review, refinement, and distribution of organizational policies and technical standards; successfully adapted operational language and procedural frameworks to maintain strict compliance with the evolving landscape prior to publication.
  • Standardized internal department workflows by architecting comprehensive team procedures, creating centralized, universally accessible documentation that reduced onboarding times by 60% across all Cyber teams

Information Security Analyst

4 Years 5 Months
Wescom Credit Union | 05.2018 - 10.2022
  • Conducted extensive research and guided the adoption of key information security standards and regulatory frameworks (NIST, ISO/IEC 27001, PCI‑DSS), strengthening the organization’s security posture and aligning controls with industry best practices.
  • Continuously refined incident response standards and guidelines, updating the full incident response lifecycle to align with evolving risk levels, attack vectors, and required response actions.
  • Maintained and updated the Cybersecurity Incident Response Team (CSIRT) address book and coordinated cross‑functional tabletop exercises as the designated facilitator. Produced detailed meeting minutes, after‑action reports, and lessons‑learned summaries for board and audit review, strengthening organizational readiness and governance.
  • Reviewed emerging information security laws and drafted targeted recommendations for the Information Security Committee, driving updates to controls and procedures that improved regulatory alignment and reduced compliance gaps by strengthening organizational readiness.
  • Developed comprehensive data flow diagrams for critical banking systems to pinpoint interdependencies, sensitive data movement, and user interaction points, increasing system visibility and improving risk‑based decision‑making across teams.
  • Promoted security awareness through enterprise-wide phishing campaigns and interactive learning sessions, significantly increasing employee engagement in threat identification.
  • Authored monthly security blogs for 2,000+ employees, reinforcing governance expectations by educating staff on threat recognition, incident reporting protocols, and their responsibilities within the organization’s security framework, resulting in improved policy adherence and more consistent reporting behaviors.
  • Assessed vendor security during procurement by conducting SOC reviews and validating completion of required cybersecurity compliance audits, ensuring 100% of identified findings were remediated within established timelines.
  • Led proof‑of‑concept evaluations for critical systems leveraged by the Information Security team such as RIVIAL Data Security, to automate key GRC workflows and reduce manual review effort. Assessed capabilities to enhance User Entity Control reviews by validating test‑of‑design and test‑of‑operating‑effectiveness requirements, increasing control assurance accuracy and improving audit reliability while cutting review time through automation‑driven efficiencies.
  • Strengthened third‑party governance by enforcing alignment with company policies and industry best practices, reducing onboarding‑related security gaps and improving overall vendor risk posture.
  • Analyzed SIEM logs daily to identify potential threats and executed immediate response protocols, reducing incident response time and improving detection efficiency across critical systems.
  • Conducted comprehensive risk assessments to identify control weaknesses and operational vulnerabilities, ensuring full alignment with regulatory requirements and industry standards including FFIEC, PCI DSS, NIST, ISO 27001, and GLBA. Delivered actionable remediation guidance that reduced identified risks and strengthened overall compliance posture across critical business functions.
  • Monitored and reviewed violations of computer security procedures, developing effective mitigation plans which assisted in the reduction of risk exposure.
  • Leveraged AlgoSec Firewall Analyzer to perform structured firewall audits, identifying configuration gaps and policy violations that reduced exposure to unauthorized access. Collaborated with the Networking team to remediate 100% of identified issues within defined timelines, strengthening firewall governance and improving overall network security posture.

Junior Information Security Analyst

1 Year 11 Months
Delta ADT | 05.2016 - 04.2018
  • Prepared and reviewed documentation for security awareness training, security standards, procedures, System Security Plans, and Incident Response/Training plans
  • Coordinated stakeholder meetings for documentation and evidence gathering during internal and external audits, ensuring compliance with regulatory standards
  • Utilized data gathering techniques such as questionnaires, interviews, and surveys to assemble Certification & Accreditation (C&A) and Assessment & Authorization (A&A) packages
  • Collaborated with stakeholders to develop and track the Plan of Action and Milestones (POA&M) addressing findings from regulatory and compliance assessments
  • Provided ongoing support, training, and education to staff, enhancing risk awareness culture across organization
  • Conducted tailored risk reporting for diverse audiences, including the board of directors, to communicate significant risks effectively
  • Utilized security tools such as NESSUS and Nexpose for conducting vulnerability assessments, leading to improved organizational security posture
  • Analyzed and prepared remediation reports on vulnerabilities identified during vulnerability scanning exercises
  • Held meetings with the Chief Information Security Officer (CISO) and system stakeholders to define the scope of engagement for planned audits.
  • Specialized in Vendor Risk Assessments, conducting gap analyses to identify deficiencies within Vendor Management programs, and presenting findings with recommendations for optimization.
  • Performed continuous Vendor Risk Assessments for over 40 prospective and current vendors to ensure control effectiveness and compliance with industry standards.
  • Performed risk analyses to identify tailored security countermeasures that align with organizational needs.
  • Developed data flow diagrams for critical systems, clarifying interdependencies, sensitive data movement, user interaction points, and authorization boundaries.

Project Management Assistant/Risk Assessor

1 Year 5 Months
JETPLAY Consulting | 09.2014 - 02.2016
  • Coordinated cross‑functional teams to strengthen collaboration and accelerate project delivery, improving communication flow and contributing to consistent on‑time completion of key initiatives.
  • Ensured effective implementation of company initiatives by monitoring adherence to internal regulations, standards, and procedural requirements, reinforcing organizational governance and supporting consistent, compliant execution across business functions.
  • Assisted in the development of critical plans, including Contingency Plans, Disaster Recovery Plans, Incident Response Plans, and Configuration Management Plans
  • Developed and maintained a comprehensive Plan of Action and Milestones (PO&M) for all accepted risks post-risk assessment, ensuring proactive risk management
  • Conducted training and awareness programs as part of the project management team, enhancing organizational understanding of security protocols
  • Supported the project manager in implementing policies related to change management, specifically in partnerships with external organizations and best value reports.
  • Provided comprehensive administrative support across departments, including IT, HR, procurement, production, commercial, and finance
  • Supervised administrative support teams, prioritizing workloads and ensuring high-quality output and achievement of deadlines
  • Scheduled meetings and coordinated appointments for the Project Manager while managing confidential documentation with discretion, ensuring seamless workflow and secure handling of sensitive information.
  • Maintained organized filing systems, records, and databases to ensure efficient information retrieval, while composing routine correspondence that supported clear communication and streamlined daily operations.
  • Facilitated communication and collaboration on major projects across business units, fostering teamwork and effective project execution
  • Aided in developing detailed scopes of work that clearly defined deliverables, timelines, and success criteria, strengthening accountability within the organization, and ensuring projects were executed in alignment with organizational expectations and compliance requirements.

Education

MBA - International Business

University of Gloucestershire | United Kingdom, UK | 08-2013

Bachelor of Law - Common Law

University of Yaoundé II SOA | Cameroon, Cameroon | 08-2010

Skills

Risk management
Technical Proficiency
Team leadership
Reporting documentation
Stakeholder engagement
Best practices
Strategic planning
Team leadership
Decision-making
Critical thinking
Networking skills
Team leadership

Accomplishments

  • Led the implementation of the Rivial Data Security platform, reducing manual work, minimizing human error, and streamlining evidence collection for audits. The automated regulatory update feature assisted with keeping the organization compliant with evolving cyber laws while enhancing risk-to-control mapping and compliance reporting. Facilitated the assessment of user entity control considerations as part of SOC reviews under the Vendor Management program. Developed user guides tailored to GRC activities within the organization.
  • Developed and automated the policy exception process for the organization with the help of Microsoft forms. This involved a qualitative risk based approach for obtaining different levels of Senior management's approval prior to granting policy exceptions to users.
  • Collaborated with Cybersecurity and Info Security team in the development of internal procedures. Successfully leveraged Jira to complete annual reviews, revision and tracking of existing procedures.
  • Used shared assessments Vendor Risk Management's Maturity (VRMM) program to evaluate the organizations risk management program for effectiveness by measuring against a baseline to achieve the desired state of the Vendor Risk Management program
  • Streamlined the approach undertaken by the organization to maintain compliance with the GLBA Safeguard Rule 501(B) section 314.4. This involved cross collaboration with relevant departments to ensure internal processes aligned with the 9 elements defined under the Safeguard Rule.
  • Achieved the adoption of Information Security Policies and Standards. This involved effective communication and coordination with subject matter experts on document reviews, feedback,updates and approvals.
  • Created internal team procedures and reduced reliance on verbal instructions minimizing misunderstandings and operational risk.
  • Worked on providing monthly cybersecurity tips for over 2500+ employees. This included the research, and leveraging of prominent cyber publications, obtaining approval from the compliance and legal teams, and creating monthly security blogs on the organizations intranet

Affiliations

Active Professional Member of ISACA, contributing to the global community of GRC and cybersecurity practitioners.

Certification

  • CompTIA Security+ SY0-401
  • Certified Banking Vendor Management Specialist (CBVM)
  • Certified in Risk and Information System's Control (CRISC)

Languages

French
Native or Bilingual
English
Native or Bilingual

Timeline

Vice President - Sr. Specialist- GRC Operations

SUMITOMO MITSUI Banking Corporation MANUBANK
10.2022 - CurrentRead More

Information Security Analyst

Wescom Credit Union
05.2018 - 10.2022Read More

Junior Information Security Analyst

Delta ADT
05.2016 - 04.2018Read More

Project Management Assistant/Risk Assessor

JETPLAY Consulting
09.2014 - 02.2016Read More

University of Yaoundé II SOA

Bachelor of Law from Common Law
Read More

University of Gloucestershire

MBA from International Business
Read More

Membership

Active member of the International professional association focused on IT governance

Nini-Fua C. CHOFOR