Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Sharon Rau

McKinney,TX

Summary

Knowledgeable professional with 6+ years of cyber security leadership, specializing in compliance and risk. Seeking progression in a GRC setting to broaden skills around audits and risk evaluations with a systematic and diligent approach. Offering exceptional compliance and risk management skills and swift ability to lead audits. Motivated self-leaner with extreme attention to detail and critical thinking skills.

Overview

13
13
years of professional experience
1
1
Certification

Work History

Cyber Assurance Risk Lead

IBM
04.2022 - Current
  • Evaluated risk assessments to include determining threat vector, single loss expectancy, and annualized rate of occurrence. Currently done manually in .xlsx format, but modernizing the process through 1RM and ServiceNow.
  • Created weighted matrices to better assess infrastructure risk which improved overall audit readiness
  • Completed an impact analysis of IBM offices per country following rising geo-political threats in Europe. Analysis included networks, applications, location, and employees through Inventory Management SOS. This was used to determine which applications needed to be supported elsewhere, and evidence to correct user access to mitigate cyber threats.
  • Created process flow for mergers and acquisitions of non-integrated companies. Now applying the same flow to integrated companies. Promoted the idea of a "Risk Review Board" to include leadership from multiped cyber departments for all applications included in the merger.

Program Manager & Compliance Specialist

IBM
04.2020 - 03.2022
  • Lead external audits around the workstation and platform management security of over 450,000 device to maintain IBM's certifications with SOC2 and ISO 27001. Met with auditors on a monthly, and quarterly basis to review security standards and implemented compliance controls.
  • Assisted in creation of IBM's modern compliance reporting tool which ingests data from three MDM solutions (Jamf, Intune, and BigFix) for 450,000+ managed devices. Specifically for de-bugging, user experience improvements, Service Now queue creation, and an automated response Slack channel.
  • Supported audits on IBM's internal compliance controls to include being the lead for workstation security and collecting evidence from multiple security solutions such as mentioned MDMs, CrowdStrike, Azure, and MDE. Frameworks include SOX, GDRP, PCI, HIPAA, FEDRAMP, ITAR, COBIT, and NIST.
  • Promoted to Program Manager by 13th month of employment.
  • Scheduled and facilitated meetings between project stakeholders utilizing agile methodologies to discuss deliverables, schedules and conflicts using Trello, Box, Mural, and Jira.
  • Tracked team member progress to mitigate delays and blockers, and to ensure the team felt supported to mitigate burnout. Created the team's template for playbooks and process flows to prevent single points of failure in team progress.
  • Lead bi-weekly calls with executives and displayed a presentation and the team's progress, and next sprint steps.

Senior Information Systems Administrator (25B)

U.S. Army
03.2013 - Current

Active Duty: 03/2013-02/2019, Reservist 03/2019-current.

  • Performs hands-on and managerial duties in a multi-disciplinary role to include help desk management, IT asset management, risk liaison, lifecycle management, and subject-matter expert on IT devices, their physical security, and information assurance.
  • Lead the DoD RMF review for battalion of over 300 personnel, and 500+ nodes within the Information Assurance scope.
  • Responsible for an inventory of over 1.5 million dollars of IT equipment to include servers, networking devices, security appliances, and cryptographic control devices.
  • While deployed, managed a team of four technicians responsible for diagnosing and remediating devices on secret and unclassified networks for over 300 personnel.

IT Security Analyst

USAlliance Financial
03.2019 - 03.2020
  • Lead third party audits with Bansec and regulatory audits under NCUA to include vulnerability and patch management (Qualys), cyber awareness training (KnowBe4), email security, IT systems management (Azure, Solarwinds, Palo Alto) and IDS/IPS management (SecureWorks).
  • Tested SIEM (QRadar) and EDR (Crowdstrike, Sophos, Varonis, Arctic Wolf) solutions for company use following maturity recommendations of the NCUA.
  • Managed vulnerability scanning, social engineering training, IDS/IPS escalation for over 1000 nodes and 300 employees.

Education

Information Technology

Advanced Leaders Course
Ft. Jackson, South Carolina
12.2019

Information Technology

Basic Leaders Course
Camp Buehring, Kuwait
08.2018

Bachelor of Arts - Geology

SUNY At Buffalo
Buffalo, NY
05.2018

- Information Technology

Information Technology Specialist Academy
Camp Williams, Utah
12.2012

Skills

  • Audit Coordination
  • Compliance Reporting
  • Risk Analysis & Identification
  • Regulatory and Compliance Understanding
  • Cybersecurity Frameworks
  • Project Management
  • Agile Practices
  • Technical Writing
  • Communication & Collaboration
  • Attention to Detail
  • Flexible and Adaptable

Certification

  • CompTIA, Security+ - 06/2018
  • U.S. Secret Clearance - 03/2013
  • ISACA CRISC Course - 03/2021
  • IVMF, (ISC)2 CISSP Course, testing 09/2022

Timeline

Cyber Assurance Risk Lead

IBM
04.2022 - Current

Program Manager & Compliance Specialist

IBM
04.2020 - 03.2022

IT Security Analyst

USAlliance Financial
03.2019 - 03.2020

Senior Information Systems Administrator (25B)

U.S. Army
03.2013 - Current

Information Technology

Advanced Leaders Course

Information Technology

Basic Leaders Course

Bachelor of Arts - Geology

SUNY At Buffalo

- Information Technology

Information Technology Specialist Academy
Sharon Rau