Results-driven IT Compliance & Security Analyst with 6 years of experience spanning IT Support, Cybersecurity, and
Governance. Skilled in regulatory compliance (HIPAA, PCI DSS, SOX, ISO 27001, NIST CSF), audit readiness, risk
assessment, and threat analysis. Proven ability to leverage security tools and cross-functional communication to
enhance IT security posture.
• Conducted quarterly access reviews and entitlement certifications across O365, AWS, and AD, identifying and resolving over 200 excess privilege cases.
• Coordinated third-party risk assessments, improving vendor compliance scorecards and reducing onboarding delays by 20%.
• Led 10+ audits (ISO 27001, SOC 2, NIST CSF) with zero major findings by aligning processes to compliance frameworks.
• Implemented real-time evidence tracking in ServiceNow GRC, cutting compliance gaps by 25% and improving audit visibility.
• Partnered with InfoSec to close 90% of audit findings within deadline, increasing SOC 2 control maturity.
• Developed and maintained a centralized control library aligned with NIST and ISO standards, enhancing cross-functional visibility and supporting continuous compliance initiatives. (ISO 27001, SOC 2, NIST CSF) with zero major findings by aligning processes to compliance frameworks.
• Executed 75+ Qualys/Nessus scans and remediated critical vulnerabilities within SLA.
• Reduced incident response time by 40% using Splunk, CrowdStrike, and streamlined IR playbooks.
• Led IAM reviews across AWS and AD, eliminating 35% of overprivileged accounts.
• Supported 300+ users and achieved 85% first-call resolution by improving troubleshooting processes.
• Managed Office 365 and Active Directory access, developing core IAM and audit skills.
• Authored self-service guides that reduced repeat ticket volume by 20%.
CompTIA Security
Vulnerability Management (Nessus & Qualys)
EDR (CrowdStrike Falcon & Microsoft Defender)
Email & Threat protection (Proofpoint)
SOC1 & 2
SIEM (Splunk & Wireshark)
Jira & Confluence
Data & Reporting tools (Power BI & Excel)
Certified Information Systems Auditor
Google Cybersecurity Certificate
GRC & Risk Platforms (RSA Archer, AuditBoard, OneTrust, ServiceNow)
Cloud & IDM (AWS IAM, Azure, GCP, Active Directory)
Data Privacy Project
Goal: Develop and implement a comprehensive global data privacy program to ensure compliance with all applicable data protection regulations.
Scope: The project covers all aspects of data privacy, including policy development, employee training, data handling procedures, data classification, compliance auditing, and incident management across all global offices.
Key Tasks
Policy and Guidance Development:
Training and Awareness:
Collaboration with Key Departments:
Compliance and Auditing:
Monitoring and Adapting to Industry Trends:
Incident Management:
Outcome:
the project ensured compliance and embedded a strong data privacy culture within the organization, contributing to its overall success.
Risk Assessment and Mitigation Project
Goal: Conduct a comprehensive risk assessment and develop a mitigation plan to identify, evaluate, and address potential risks to the company's data, systems, and operations.
Scope: The project encompasses all business units and regions, focusing on identifying risks related to data privacy, cybersecurity, regulatory compliance, and operational continuity.
Key Tasks
Risk Assessment Planning:
Identification and Evaluation of Risks:
Risk Mitigation Strategy Development:
Collaboration and Integration:
Monitoring and Continuous Improvement:
Outcome
The project safeguarded the company's assets and operations and positioned it as a leader in risk management among competitors.