I'm an Experienced GRC Analyst with a background in the financial and pharmaceutical industries. Adopt in conducting compliance assessments using NIST CSF and ISO 27001. I am skilled in developing cyber policies for vulnerability management, incident response, SIEM, IAM, asset management, risk management, third-party risk management, data governance, policy compliance, and HIPAA compliance—proven ability to identify risks and develop effective strategies to mitigate them.
Overview
4
4
years of professional experience
1
1
Certification
Work History
GRC Analyst
Vertex Pharmaceutical Inc
08.2022 - Current
Conduct assessments using NIST CSF and ISO 27001 frameworks to evaluate cybersecurity posture
Develop cyber policies for vulnerability management, incident response, SIEM, IAM, and asset management
Identify gaps in existing policies and procedures and recommend improvements to enhance security posture
Collaborate with cross-functional teams to implement security controls and mitigate identified risks
Project Summaries: Problem: Identified significant vulnerabilities in the organization's IT infrastructure, increasing cybersecurity risks
Resolution: Developed and implemented a comprehensive vulnerability management policy, resulting in a 30% reduction in critical vulnerabilities within six months
Enhanced patch management processes led to a 50% decrease in patching time.
GRC Analyst
SECOND Family Inc
02.2021 - 06.2022
Conduct risk assessments and audits to ensure industry regulations and standards compliance
Develop and maintain cyber policies and procedures related to vulnerability management, incident response, SIEM, IAM, and asset management
Collaborate with IT and business units to identify security requirements and implement appropriate controls
Monitor and analyze security events to promptly detect and respond to potential threats
Project Summaries: Problem: Lack of clear cyber policies and procedures led to inconsistencies in vulnerability management practices across the organization
Resolution: Developed and implemented standardized vulnerability management policies and procedures, resulting in a 25% improvement in vulnerability remediation time
Enhanced reporting capabilities gave stakeholders better visibility into the organization's security posture.
GRC Analyst
Rocket Pharmaceuticals Inc
New York, NY
03.2020 - 01.2021
Conduct assessments using NIST CSF and ISO 27001 frameworks to evaluate and improve security controls and risk management processes
Develop cyber policies for vulnerability management to enhance detection, assessment, and mitigation of vulnerabilities
Design and implement incident response procedures and manage SIEM systems for better threat detection and response
Implement IAM solutions and develop asset management strategies
Ensure compliance with PCI DSS and NERC CIP standards through regular audits and assessments
Implement data privacy policies to protect sensitive information and evaluate risks associated with third-party vendors
Project Summaries: SIEM Optimization and Incident Response Enhancement: Problem: High false positive rates and delayed response times
Resolution: Analyzed and refined SIEM rules and implemented a new incident response playbook, resulting in a 40% reduction in false positives and a 30% improvement in response times
Vulnerability Management Program Development: Problem: Inefficient vulnerability management processes
Resolution: Developed and implemented a comprehensive vulnerability management program, leading to a 50% decrease in critical vulnerabilities.
Education
Master of Science in Information Technology -
IGlobal University
01.2020
Bachelor of Business Administration -
Ajayi Crowther University
01.2015
Skills
Risk Assessment & Management
Policy Development
Incident Response
Security Information and Event Management (SIEM)
Identity and Access Management (IAM)
Asset Management
Compliance (PCI DSS, NERC CIP)
Data Privacy (GDPR, CCPA)
Third-Party Risk Management
Vulnerability Management
Inherent Risk Questionnaire (IRQ) administration using ServiceNow GRC
Business performance analysis
Compliance frameworks and guidelines: OCC-2013, HIPAA, GLBA, FFIEC, OFAC