Summary
Overview
Work History
Education
Skills
Websites
Certification
Accomplishments
Affiliations
Hobbies and Interests
Languages
Work Availability
Work Preference
Quote
Software
Interests
Timeline
Generic

Uwem Essien

Bossier City,LA

Summary

Cybersecurity Analyst with over 6 years of hands-on experience in IT security, risk management, and compliance. Expertise in Security Operations, IT Risk Management, Privacy, and Vendor Risk Management, with a strong understanding of industry standards such as NIST, PCI-DSS, SOX, CCPA, and GDPR. Certified Information Systems Auditor (CISA), CompTIA Security+, and AWS Certified (SAP C02). Proficient in risk management tools (OneTrust, Navex IRM), firewall management, intrusion detection systems, endpoint security, cloud security, and vulnerability scanning. Experienced in conducting risk and vulnerability assessments, penetration testing, control testing, change management, and developing security strategies for diverse environments. Skilled in implementing Security Information and Event Management (SIEM) systems, utilizing penetration testing tools, and performing network analysis. Proven track record of managing multiple projects, leading cross-functional teams, and conveying complex technical concepts to non-technical audiences. Expertise in designing, planning, and executing security frameworks that mitigate risk and ensure compliance. Known for delivering results in fast-paced environments with a focus on continuous improvement and operational excellence. Diligent IT AUDITOR with comprehensive background in identifying and mitigating cybersecurity risks. Adept at developing risk assessments and implementing security protocols to protect sensitive information. Demonstrated expertise in vulnerability management and incident response.

Overview

7
7
years of professional experience
1
1
Certification

Work History

Cybersecurity Risk Analyst

Gelson's Corporation
Santa Fe Springs, California
06.2024 - Current
  • Drive execution and evolution of information security risk management program
  • Work closely with functional teams to assess existing and new processes, providing guidance on control design and risk mitigation
  • Conduct targeted risk assessments to identify strengths and weaknesses related to privacy, security, and compliance frameworks
  • Execute risk-based operational audits focused on Cybersecurity and IT systems according to internal audit plan

Oversee implementation and maintenance of Enterprise GRC tool

  • Collaborate with leads across Information Security team to measure and plan remediation for security risks
  • Document and maintain workflows and procedures to identify gaps in risk posture
  • Create and present risk posture reports and recommendations to leadership
  • Perform ad-hoc assessments as needed
  • Assist IT Audit Manager in risk-based IT audit and advisory activities to assess and provide assurance over IT risk universe
  • Evaluate effectiveness of IT controls via testing to determine if controls are designed appropriately and operating as intended,
  • Perform planning, fieldwork and reporting for IT audits, including preparing audit planning memos, developing and executing test steps, reviewing and analyzing evidence, identifying and assessing risks and control issues, and drafting summary memos and audit reports
  • Be a trusted business advisor by developing business relationships and providing value-add assurance, advice, and insight to management on governance, risk, compliance, control improvement
  • Work regularly and communicate effectively with IT, GRC, Product and Finance organizations, and business process owners to relay findings and recommendations, track and help drive remediation efforts to closure, advise on control requirements in design of new systems and processes, identify trends and insights, and continuously seek improvement opportunities matters, and key Company initiatives
  • Conduct work efficiently and effectively, monitoring and communicating adherence to project timelines and departmental budget
  • Familiarity with COSO, COBIT, NIST, ISO, and CIS frameworks

Cybersecurity Analyst

Air Tech Solutions
05.2018 - 05.2024
  • Perform quantitative security risk analyses and recommend security enhancements to management
  • Ensure IT operations comply with relevant regulations, industry standards, and best practices (e.g., GDPR, SOX, HIPAA)
  • Oversee lifecycle of information security policies, including development, review, approval, and dissemination.
  • Provide mentorship and guidance to peer analysts, supporting of Governance, Risk, and Compliance (GRC) capabilities and processes.
  • Work closely with Senior Cybersecurity Analyst to create and manage security policies and documentation.
  • Manage Vendor Risk Management Program, evaluating third-party vendor risks
  • Evaluate data management processes to maintain data integrity, security, and privacy
  • Communicate security risks and controls clearly and efficiently to both internal and external auditors.
  • Collaborate with Compliance team to ensure accuracy of IT SOX documentation during process redesigns and system implementations
  • Conduct risk assessments of applications and technology vendors based on defined frameworks
  • Identify and assess potential IT risks, including cybersecurity threats, data breaches, and system vulnerabilities
  • Review hardware, software, and network components to ensure they meet organizational and regulatory requirements
  • Develop, coordinate, and implement security strategies to safeguard data from unauthorized access, alteration, or disclosure.
  • Execute risk-based operational audits focused on IT systems and compliance with security requirements
  • Conduct risk assessments and ensure prompt remediation of identified vulnerabilities.
  • Lead review and remediation planning for ineffective information security controls.
  • Review cybersecurity measures, including firewalls, encryption, authentication processes, and backup protocols
  • Collaborate with various departments, including Cybersecurity, Telecommunications, Engineering Operations, Billing, Finance, Legal, Privacy, and Risk Management, to ensure security measures align with organizational goals.
  • Implement, test, and continuously monitor effectiveness of both design and operational information security controls.
  • Examine internal controls related to IT processes, including data access, data protection, and system management practices

Education

Associate of Science - Cyber Security

University of Phoenix
Phoenix, AZ
10.2025

Bachelor of Science (BS) - Information Technology

Ogun State University
Ogun State, Ogun State
01.2017

Skills

  • Problem-solving abilities
  • Data analytic tools & techniques
  • Microsoft Excel
  • GRC Platforms (Vanta, Drata, Secure frame, HIPAA)
  • Desktop publishing tools (Adobe InDesign, QuarkXPress, Scribus)
  • Cybersecurity industry standards (PCI-DSS, SOX, ISO 27001, NIST CSF, FFIEC, 800 series)
  • Antifraud internal controls
  • Strong communication skills
  • Strong leadership and team management abilities
  • Attention to detail
  • (SIEM) tools
  • Scripting languages (SQL -Python, PowerShell)
  • Knowledge of industry-specific regulations and compliance requirements
  • Third-Party Risk Management
  • Intrusion detection systems (IDS)
  • IT Governance
  • ACL
  • Arbutus
  • Oracle ERP
  • SharePoint
  • Compliance & Risk Management
  • Access control
  • COBIT & COSO Framework
  • Security policies
  • Security awareness training
  • Vulnerability assessment

Certification

  • CISA
  • CompTIA Security+++
  • AWS Certified Solutions Architect (SAP CO2)
  • Microsoft Office Specialist
  • Excel Expert 01/01/23

Accomplishments

  • Enhanced Security Posture: Successfully implemented and managed Security Information and Event Management (SIEM) systems, such as Splunk and IBM QRadar, leading to a 40% reduction in incident response time by automating real-time threat detection and incident management processes.
  • Cloud Security Optimization: Deployed and configured advanced cloud security tools (e.g., AWS CloudTrail, Azure Security Center, and Palo Alto Networks Prisma Cloud) to ensure secure cloud environments, resulting in a 35% improvement in cloud security compliance and vulnerability management.
  • Incident Response and Mitigation: Utilized endpoint detection and response (EDR) tools like CrowdStrike and Carbon Black, improving malware detection capabilities by 45%, leading to a reduction in successful cyber-attacks by over 50% and enhancing overall threat mitigation protocols

Affiliations

Gelson's Corporation, Successfully led multiple high-profile IT audits, identifying critical vulnerabilities and recommending solutions.

Hobbies and Interests

  • Community Engagement and Advocacy
  • Technology and Innovation
  • Physical Fitness and Wellness
  • Travel

Languages

English
Full Professional

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Work Preference

Work Type

Full TimePart TimeContract Work

Work Location

RemoteOn-SiteHybrid

Important To Me

Career advancementWork-life balance

Quote

There is a powerful driving force inside every human being that, once unleashed, can make any vision, dream, or desire a reality.
Tony Robbins

Software

Molina Healthcare, Prisma Cloud, Metasploit, Metasploit, Kali Linux, SIEM (Security Information and Event Management):Splunk, IBM QRadar, LogRhythm: ,CrowdStrike Falcon:, COSCO, COBIT, PCI DSS, SOC 27001, SOX ACT, CrowdStrike Falcon, Carbon Black, Nessus, Prisma Cloud (Palo Alto Networks),Wireshark, Nagios

Interests

What excites me most about is the opportunity to continuously learn and tackle new challenges The rapid pace at which technology evolves means that there’s always something new to discover, whether it’s new threats, tools, or methods of securing systems I also find it incredibly rewarding to be part of a team that works to protect sensitive information and maintain trust within organizations

Timeline

Cybersecurity Risk Analyst

Gelson's Corporation
06.2024 - Current

Cybersecurity Analyst

Air Tech Solutions
05.2018 - 05.2024

Bachelor of Science (BS) - Information Technology

Ogun State University

Associate of Science - Cyber Security

University of Phoenix
Uwem Essien