Summary
Overview
Work History
Education
Skills
Certification
References
Accomplishments
Timeline
Generic
Sammy Addo

Sammy Addo

Www.linkedin.com/in/sammy-addo-36958463
Worcester,MA

Summary

Dedicated and results-oriented GRC Analyst with 2 years of experience in the pharmaceutical industry. Proven expertise in conducting assessments using NIST CSF and ISO 27001, and developing robust cyber policies for vulnerability management, incident response, SIEM, IAM, and asset management. Adept at providing both quantitative and qualitative value through effective project management and implementation of best practices.

Overview

3
3
years of professional experience
1
1
Certification

Work History

Information Security Analyst

Top Group Technologies
03.2021 - Current

Created and updated the following Security Assessment and Authorization (SA&A) artefacts; FIPS 199, Security Test and Evaluations (ST&Es), Risk Assessments (RAs), Privacy Threshold Analysis (PTA), Privacy Impact Analysis (PIA), E-Authentication, Contingency Plan, Plan of Action, and Milestones (POAMs)


Created Security Assessment and Authorization (SA&A) packages to ensure compliance with NIST SP 800-53 standards for management, operational, and technical security controls.

Collaborated effectively with cross-functional teams to conduct third-party risk assessments, ensuring compliance with industry regulations such as HIPAA, ISO 27001, PCI-DSS, and SOC.

Conducted IT controls risk assessments including reviewing organizational policies, standards and procedures and providing advice on their adequacy, accuracy, and compliance with industry standards.
• Led a successful FFIEC compliance gap assessment at Top Group
Technologies, integrating COBIT principles to align IT strategies with
business objectives and ensuring adherence to GLBA regulations for
safeguarding financial data.

Developed, reviewed, and evaluated Security Plans based on NIST Special Publications 800-18
Investigated possible security breaches identified through review of audit reports and follows up accordingly with departments/management. Prepared and reviewed A&A package for Information Systems.

  • Implemented security measures to reduce threats and damage related to cyber attacks.
  • Administered and monitored firewalls, intrusion detection systems and anti-virus software to detect risks.

Education

Associate of Arts -

Quinsigamong Community College

Skills

Cyber policy developmentVulnerability managementIncident response planningSecurity Information and Event Management (SIEM)Identity and Access Management (IAM)Asset management

Certification

CompTia Security+ Certifcation

References

Available upon request.

Accomplishments

    Comptia Security +

Timeline

CompTia Security+ Certifcation

01-2024

Information Security Analyst

Top Group Technologies
03.2021 - Current

Associate of Arts -

Quinsigamong Community College
Sammy AddoWww.linkedin.com/in/sammy-addo-36958463