

Dedicated and results-oriented GRC Analyst with 2 years of experience in the pharmaceutical industry. Proven expertise in conducting assessments using NIST CSF and ISO 27001, and developing robust cyber policies for vulnerability management, incident response, SIEM, IAM, and asset management. Adept at providing both quantitative and qualitative value through effective project management and implementation of best practices.
Created and updated the following Security Assessment and Authorization (SA&A) artefacts; FIPS 199, Security Test and Evaluations (ST&Es), Risk Assessments (RAs), Privacy Threshold Analysis (PTA), Privacy Impact Analysis (PIA), E-Authentication, Contingency Plan, Plan of Action, and Milestones (POAMs)
Created Security Assessment and Authorization (SA&A) packages to ensure compliance with NIST SP 800-53 standards for management, operational, and technical security controls.
Collaborated effectively with cross-functional teams to conduct third-party risk assessments, ensuring compliance with industry regulations such as HIPAA, ISO 27001, PCI-DSS, and SOC.
Conducted IT controls risk assessments including reviewing organizational policies, standards and procedures and providing advice on their adequacy, accuracy, and compliance with industry standards.
• Led a successful FFIEC compliance gap assessment at Top Group
Technologies, integrating COBIT principles to align IT strategies with
business objectives and ensuring adherence to GLBA regulations for
safeguarding financial data.
Developed, reviewed, and evaluated Security Plans based on NIST Special Publications 800-18
Investigated possible security breaches identified through review of audit reports and follows up accordingly with departments/management. Prepared and reviewed A&A package for Information Systems.
CompTia Security+ Certifcation
Comptia Security +
CompTia Security+ Certifcation