Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Romanus Orock

Beltsville,MD

Summary

As an experience Compliance and Third-Party Risk Analyst, I bring over five years of expertise in Proficient in managing the entire vendor life cycle, From preparation to authorization (ATO) Extensive knowledge in SIG/VSQ (Vendor Security Questionnaire) Risk and Security Assessment, Remediation, and Continuous Monitoring. Ability to Effectively Review (SOC) Report, Penetration Test Report, Run and Analyze Vulnerability Scan Report. Strong Knowledge and Experience in NIST 800series, PCI-DSS, ISO 27001, HIPPA, GDPR, GRC Archer, One Trust to achieve Confidentiality, Integrity, Availability of Information System Vendor Classification as well as Vendor Selection. A Result professional with hands-on experience in reviewing security documentations and evidence, risk assessment reports and risk treatment plans. Proactive, dynamic, detail oriented, good listener, fast learner, comfortable working in a team and independent with ability to adapt in diverse environments.

Overview

5
5
years of professional experience
2
2
Certification

Work History

IT Risk/Compliance Analyst

Navy Federal Credit Union
09.2019 - Current

· Work in Partnership with Teams such as Business, Procurement, Security and Legal during vendor intake process.

· Act as liaison during organizations internal and external audits by gathering evidence and responding to security questions related to third parties.

· Create collaboration with information security team, documentation and workflow to assist with vendor Cyber events.

· Daily monitoring vendor Network security posture using BITSIGHT as reference tool.

· Collaborate with procurement team in developing IRQ for vendor’s response to classify suppliers into Low, Limited and High Risks base on risk factor.

· Conduct vendor security review by sending VSQ/SIGs requesting evidence, per supplier management standards.

· Develop findings for issues identified such as non-completion of security assessment and vulnerabilities observed during documentation review.

· Collaborate with suppliers, Business Unit and Upper management to resolve any roadblocks observed assessments as part of escalation activities processes.

· Evaluated responses and analyzed supporting evidence such as SOC Report Pen Test, Vulnerability Scan, information security Policy and procedure to identify any gap within the vendors control environment.

· Update risk registry and engage with vendor to obtain risk treatment plan, for all gaps and made recommendations.

· Create Vendor Risk Assessment Report to escalate issues when necessary.

· Create findings for issues identified during daily monitoring of onboarding supplier.

· Periodically checked supplier contract agreement for expiration, COIs, Performance and provide report to Business unit manager.

· Ability to communicate vendor security issues to stakeholders, ensuring proper understanding of emerging risks associated with vendor engagement.

· Performed Continuous monitoring and reassessment with experience using BITSIGHT and security scorecard to make sure vendor controls are properly implemented hence maintaining data security.

Reexamined and made recommendations on organization-wide polices and procedures to ensure organization maintain good security posture, meet requirements and compliance with

Security Analyst

Freshly Inc.
10.2018 - 09.2019
  • Conducted security audits to identify vulnerabilities.
  • Maintained up-to-date knowledge of emerging threats by attending professional development events and staying informed on industry trends.
  • Streamlined incident response procedures for quicker threat mitigation and improved system uptime.
  • Analyzed log files for anomalies, identifying potential intrusions or malicious activity before significant damage occurred.

Education

Bachelor of Science - Computer And Information Sciences

University of Nchang
Nchang-Cameroon
08.2011

Skills

Financial Management,

Operational Efficiency,

Risk Identifications,

Data Classification,

training Documentations

Team Player Organizational Systems

Microsoft Office 365

Certification

· CompTIA Security + certified

· Certified Information Security Auditor (CISA)



TOOLS

JIRA

CSAM

NESSUS TENABLE

BITSIGHT

PROCESS UNITY

VEN MINDER

ZEN GRC

ONE TRUST

Timeline

IT Risk/Compliance Analyst

Navy Federal Credit Union
09.2019 - Current

Security Analyst

Freshly Inc.
10.2018 - 09.2019

Bachelor of Science - Computer And Information Sciences

University of Nchang
Romanus Orock