Information Security Specialist with a strong passion for aligning security architecture plans and processes with security standards and business goals. Extensive experience developing web applications and testing security frameworks to ensure regulatory compliance. Versed in robust network defense strategies and threat hunting.
Overview
8
8
years of professional experience
4
4
Certification
Work History
Virtual Internship (Job Simulation)
PwC (US) theForage.com
08.2024
Successfully completed a PwC Digital Assurance & Transparency job simulation, focusing on client engagement to evaluate and enhance digital processes
Utilized workpapers to rigorously test control samples, ensuring the effectiveness of internal controls
Conducted a comprehensive deficiency analysis, interpreting client-provided data to identify and address control gaps, contributing to stronger data assurance and information system auditing practices.
IT & Cyber Security Analyst (Contractor/Freelancer)
Vizdio Cyber Agency
Houston, TX
01.2019 - Current
Lead the secure development and deployment of web applications, ensuring compliance with information security best practices and regulatory requirements across multiple client projects
Conduct comprehensive security assessments and risk evaluations, identifying vulnerabilities in web applications and implementing targeted remediation strategies to mitigate potential threats
Design and enforce robust security policies, access controls, and encryption protocols, safeguarding client data in accordance with industry standards, including NIST 800-53, GDPR, HIPAA, and PCI DSS
Spearhead incident response initiatives, efficiently identifying, analyzing, and resolving security breaches, while maintaining meticulous documentation for auditing and compliance purposes
Train business owners and stakeholders on security awareness, enterprise risk management, and compliance requirements, driving a culture of security and ensuring sustained compliance within client organizations
Manage continuous monitoring and timely patching of software vulnerabilities, fortifying digital assets and aligning with governance frameworks such as NIST RMF and ISO 27001
Remain at the forefront of cybersecurity advancements by staying updated on emerging technologies and trends, actively training individuals, and promoting security awareness through social media, professional settings, and community events.
Data Surveillance Specialist
Texas Department of State Health Services
07.2017 - Current
Manage the data integrity of notifiable disease reporting systems, implementing robust relational database solutions that ensured secure, efficient data storage and organization in full compliance with state policies and procedures
Develop and execute complex queries and advanced data analysis tools, extracting critical insights while maintaining stringent security measures, including access controls, user permissions, and encryption protocols to safeguard sensitive information
Serve as a subject matter expert and liaison, facilitating collaboration between the state government and external vendors, system developers, and IT professionals
Evaluate ongoing projects and IT systems to ensure compliance with internal policies, industry standards, and regulatory requirements
Conduct public health interviews for risk assessment and mitigation, and lead educational sessions for healthcare professionals on secure data-handling best practices, ensuring the protection of public health data in alignment with the latest IT tools and cybersecurity regulations
Lead internal auditing efforts, preparing the department for external audits by ensuring regulatory compliance, identifying areas for improvement, and protecting Personally Identifiable Information (PII) in accordance with HIPAA regulations during data collection and surveillance activities
Deliver presentations at industry conferences and train stakeholders on reporting notifiable conditions, ensuring adherence to state laws through clear, impactful public speaking and educational initiatives
Proactively pursue professional development by attending specialized training sessions and maintaining active membership in relevant professional organizations, staying at the forefront of industry trends and best practices.
Data Integrity Analyst (Team Lead)
Thomas Jefferson University Hospital
04.2017 - 06.2018
Developed and implemented rigorous data quality assurance processes, ensuring the accuracy, completeness, and reliability of healthcare data through regular audits, data validation checks, and prompt resolution of discrepancies
Partnered with senior management to establish and enforce robust data governance policies, proactively identifying and mitigating risks to data integrity, such as breaches, unauthorized access, and data corruption
Conducted in-depth analysis of healthcare data to uncover trends, patterns, and anomalies, creating insightful reports and dashboards that informed data-driven decision-making, enhanced patient care outcomes, and supported compliance with regulatory requirements
Delivered targeted training and education to healthcare staff on data integrity best practices and data entry standards, reinforcing the importance of maintaining high data quality and supporting the development of test protocols to verify equipment operation and performance standards
Played a key role in the recruitment and training of new staff, meticulously documenting test results and communicating any deviations or issues to stakeholders, ensuring adherence to equipment specifications, manufacturer guidelines, and regulatory standards
Collaborated with cross-functional teams to design and execute comprehensive research projects, contributing to the development of study objectives, methodologies, and data analysis plans that drove evidence-based decision-making and achieved targeted research outcomes.
Education
Master of Epidemiology and Biostatistics -
Temple University
Philadelphia, Pennsylvania
01.2014
Skills
GRC and Audit Control
GRC TOOLS: Splunk, Qualys
Frameworks and Standards: PCI DSS / ISO 27001 / FedRamp / NIST/ SOC
Threat Hunting
Data protection
CYBER-SECURITY TECHNOLOGIES
OSINT
Vulnerability Assessment
Intrusion Test Oversight
Data Encryption
Network Security
Security analysis
Compliance Monitoring
Incident Response
Certification
CompTIA CySA +
CompTIA Security+ Certified CE
ISC2 Certified in Cybersecurity
Certified Cybersecurity Awareness Specialist
CISA (In Progress)
Training
NIST SP 800-53, SP 800-53A, SP 800-53B
Digital assurance and transparency job simulation in forage - PwC - 2024
GRC Bootcamp - ThinkCloudly - 2024
GRC Training - Better Cyber Career - 2024
AWS Cloud Practitioner - 2024
Penetration Testing - 2024
Coreproficiencies
Cyber-Security
Information Security
Security Advisory
Risk Assurance
Cloud Security
Policy Creation
Incident Response
Governance
Risk Management
Supply Chain Security Management
Compliance Management
Awareness Training
Team Building & Training
Risk Analysis & Mitigation
Threat Hunting
Timeline
Virtual Internship (Job Simulation)
PwC (US) theForage.com
08.2024
IT & Cyber Security Analyst (Contractor/Freelancer)