• Specialize in all key aspects of Data Privacy, Security, Cybersecurity, Governance, Risk andCompliance, heavily focused in the Life Sciences and Healthcare space• Evaluate and enhance security controls in order to ensure Confidentiality, Integrity and Availability• Follow Risk Management frameworks, standards, methodologies, and best practices, including NIST SP800-30, SP800-37, SP800-39, SP800-53, SP800-66, SP800-144 and related, NIST CSF, FISMA, FIPS, SIMM-5300-A/B/C, SAM-530 and related, ISO/IEC 27001 | 27002, AICPA SOC 1/2/3, COBIT, PCI-DSS, US-CERT, DoD IA–DIACAP to ensure corporate and legal compliance• Implement and Enhance HIPAA controls, HHS Security and Privacy Rules – Protected Health Information (PHI), Personally Identifiable Information (PII), Personal Health Record (PHR), Electronic Health Record (EHR); Breach Notification controls – Health Information Technology for Economic and Clinical Health Act (HITECH); Meaningful Use (MU), under the American Recovery and Reinvestment Act (ARRA), and HIPAA Omnibus Final Rule • Critical Data Systems Auditing and Controls in the areas of Privacy and Security / Cybersecurity Compliance – Sarbanes-Oxley §404 and §302, OCC Financial standards, Federal Financial Institutions Examination Council (FFIEC), and California Consumer Privacy Act (CCPA) • Planning and Execution cycles - Scoping, Risk Assessment, Documentation, Implementation, Testing, Remediation, Monitoring of Access Controls, Physical Controls, Data Center Controls, Network Controls, Operations, Change Management, BCP/DR and SDLC• Versed in Anti-Money Laundering (AML) and Countering Terrorist Funding (CTF) investigative functions, Suspicious Activity Reports (SARs) in support of Bank Secrecy Act (BSA), Financial Crimes Enforcement Network (FinCEN) and USA PATRIOT Act• Versed in Homeland Security Planning and Preparedness, Incident Command System (ICS) and National Incident Management System (NIMS) as per standards, guidelines and compliance protocols prescribed by Dept. of Homeland Security (DHS) / Federal Emergency Management Agency (FEMA) through the National Integration Center (NIC)• Proficient with various Audit, Risk Assessment and GRC risk register platforms, including IBM OpenPages, RSA Archer eGRC, Allgress and Zen GRC• Resourceful, innovative and excellent technical capabilities• Communicate and interface effectively with clients, peers, support groups, and all tiers of management, including C-level• Excellent written and oral communication skills• Veteran, U.S. Naval Security Group Command / NSA / CSS
Listed skills include Information Security, Information Technology, Governance, Risk Assessment, and 45 others.