Summary
Overview
Work History
Education
Skills
Certification
Timeline
AWARDS
Generic

Tina Hessel

Dubuque

Summary

Dynamic and proactive professional with extensive expertise in compliance, audit, and risk management, dedicated to cultivating a culture of security and adherence within organizations. Successful in developing and implementing best practices for information security through thorough audits, assessments, and strategic policymaking. Proficient in navigating complex regulatory frameworks, including PCI, SOC 1 and 2, FDA, HITRUST, NIST, ISO 27001, and HIPAA, while ensuring meticulous documentation practices. Committed to driving continuous improvement and enhancing organizational resilience against emerging risks, with a strong focus on identifying and mitigating potential threats through effective risk assessment methodologies.

Overview

17
17
years of professional experience
1
1
Certification

Work History

IT Security Risk Management Analyst

GuideWell Source
Jacksonville, Florida
11.2024 - Current
  • Serve as liaison between IT and business units to identify, understand, and document security risks, impacts, and requirements.
  • Analyze residual risks, vulnerabilities, and exposures, and propose mitigation strategies.
  • Monitor, analyze, and report on security events and trends to support defense capabilities.
  • Assist in developing and supporting security architecture.
  • Develop or maintain security processes, policies, and procedures.
  • Ensure compliance with regulatory requirements.

Risk Consultant

TransUnion
Chicago, Illinois
12.2021 - 12.2023
  • Led business process initiatives for four business groups, providing compliance-related consultation and suppliers for compliance with information security-related requirements in supplier contracts.
  • Partnered with Legal and teams to influence and support the consistent execution of the global compliance program.
  • Co-developed a training program for new team members.
  • Created and updated standardized information-gathering questionnaires for various services.
  • Developed short-term goals and a long-term strategic plan to improve risk control and mitigation.
  • Participated in daily systemwide huddle calls.
  • Presented risk findings with detailed analysis.
  • Conducted assessments of Neustar suppliers for compliance with information security-related requirements in supplier contracts.
  • Assist with ad-hoc customer information security related information requests to ensure tracking, prioritization, engagement of appropriate internal functions/personnel, and timely response to customers.
  • Participate in contract reviews to ensure information security related requirements are accounted for in established controls or if new controls or control changes will be required.

Compliance and Audit Leader

TELEPERFORMANCE
Salt Lake City, Utah
01.2021 - 12.2021
  • Managed overall audit and compliance program, ensuring business operations within policies, procedures, and regulatory guidelines.
  • Facilitated all aspects of audits, such as HITRUST, PCI, SOC 1 Type 2, and SOC 2 Type 1 and 2 audits.
  • Assessed Teleperformance suppliers for compliance with information security-related requirements in supplier contracts.
  • Developed a program for gathering evidence for audits.
  • Cultivated an Agile environment, fostering collaboration with team members and SMEs during audit procedures.
  • Align current business processes with client requirements and external security standards/obligations, such as NIST, FISM, PUB1075, ISO 27001:2013, PCI-DSS, HIPAA/HITRUST, etc., as well as Service Organization Control reporting.
  • Identify, document, and assist in the remediation of security deficiencies and gaps with business suitable controls.
  • Review Statements of Work, Master Service Agreements, and other contracts for security obligations and identify areas of exposure.
  • Serve as a liaison between internal and external customers and management to maximize the adoption of and support for security plans and procedures within the organization.
  • Serve as liaison between the organization's clients and security auditors, concerning information security.
  • Identify and lead the appropriate subject matter experts to participate in the identification and analysis of risk scenarios.
  • Collect and review control evidence.

Regulatory Compliance Administrator

IBM
Dubuque, Iowa
10.2014 - 11.2020
  • Managed and coached the regulatory team to maintain industry knowledge and skills in compliance, audit, and risk management to improve internal processes and practices.
  • Ensured compliance and adherence to state, national, and international requirements, including Sarbanes-Oxley (SOX), PCI, HIPAA, GDPR, ITAR, and CCPA.
  • Responded to external and internal audits, continuous monitoring, penetration tests, and various vulnerability assessments, including ongoing monitoring of compliance control to ensure constant functionality through ongoing infrastructure upgrades and changes.
  • Developed and delivered training content for a division of 30 employees during tenure as administrator.
  • Created document program to eliminate use of hard-copy documents.
  • Oversaw development of Watson Health project.
  • Mentored and coached junior team members, enhancing regulatory, strategic, and operational performance.
  • Facilitated and participated in internal audits by identifying compliance issues.
  • Created and advised team on improving internal controls and processes while preparing for risk assessments during audits.
  • Served as single point of contact for audits which included routing data requests to delivery teams, reviewing responses prior to replying to auditors.
  • Performed qualification and validation activities for document management system used to assign and track IBM and customer regulatory documents.
  • Responded to external and internal audits, continuous monitoring, penetration tests and various vulnerability assessments, including ongoing monitoring of compliance controls to ensure constant functionality through ongoing upgrades and changes.
  • Single point of contact for audits which included routing data requests to delivery teams, reviewing responses prior to replying to auditors.
  • Ensured compliance and adherence to state, national, and international requirements including Sarbanes-Oxley (SOX), PCI, HIPAA, GDPR, ITAR and CCPA.
  • Coordinated corrective actions to respond to audit finding.
  • Conducted internal audits for various accounts.

Security Compliance Analyst

IBM
Dubuque, Iowa
06.2011 - 10.2014
  • Established and maintained security and compliance for assigned accounts.
  • Designed a training program for new team members.
  • Created action plans and responses to all audit observations.
  • Piloted audit readiness reviews by assessing account compliance to contractual requirements, as well as IBM and client security documents and global process documents.
  • Collaborated with other teams while conducting health checks on servers of customers.
  • Created daily, weekly, and monthly reports for the account team's reporting on the status of health check progress.
  • Conducted research on how to create a tool to automate health check process.
  • Produced web page and video for global audience on how to conduct audits.

CMA/Lab Supervisor

Crescent Community Health Center
Dubuque, Iowa
10.2008 - 11.2010
  • Managed the collection, analysis, and interpretation of 100+ lab results daily, ensuring compliance with industry standards and regulations.
  • Managed and oversaw daily clinic laboratory operations, facilitating efficient employee training for a team of 10 staff members.
  • Managed and optimized lab testing procedures, resulting in improved accuracy and increased cost savings.
  • Automated patient data entry and test result processing for billing, streamlining operations and facilitating in-house patient care services.
  • Established relationships with nearby medical providers and facilities to procure appointments for low-income patients, resulting in a 20% increase in patient access to care.
  • Execute Medical Assistant duties to facilitate smooth patient care and workflow, including conducting vitals, EKGs and patient histories in a high-volume clinic setting.

Education

Bachelor of Arts - Theology

Apostolic Bible Institute
St. Paul, Minnesota

Certification - Paramedic

University of Iowa
Iowa City, Iowa

AAS - Nursing

NORTHEAST IOWA COMMUNITY COLLEGE
Peosta, Iowa, US

Skills

  • Risk assessment
  • Compliance auditing
  • Data interpretation
  • Collaborative team management
  • Employee training
  • Quality assurance in documentation
  • Experience in internal auditing
  • Risk assessment expertise
  • Project Management
  • Regulatory oversight
  • Strategic Planning
  • Program Development

Certification

PCI DSS

Timeline

IT Security Risk Management Analyst

GuideWell Source
11.2024 - Current

Risk Consultant

TransUnion
12.2021 - 12.2023

Compliance and Audit Leader

TELEPERFORMANCE
01.2021 - 12.2021

Regulatory Compliance Administrator

IBM
10.2014 - 11.2020

Security Compliance Analyst

IBM
06.2011 - 10.2014

CMA/Lab Supervisor

Crescent Community Health Center
10.2008 - 11.2010

Certification - Paramedic

University of Iowa

AAS - Nursing

NORTHEAST IOWA COMMUNITY COLLEGE

Bachelor of Arts - Theology

Apostolic Bible Institute

AWARDS

ibm-3 manager Choice, IBM-1 Eminence and excellence
Tina Hessel