Experienced GRC Analyst and Information Security Analyst specializing in the development and testing of security frameworks for cloud-based software. Strong knowledge in information security, Risk Management Framework (RMF), FIPS, FISMA, NIST compliance, vulnerability management, and threat intelligence. Extensive experience in developing and testing security frameworks to achieve ATO (Authority to Operate) approval. Proficient in additional compliance frameworks, including HIPAA, PCI-DSS, ISO 27001, SOX, and SOC. I am dedicated to helping organizations safeguard sensitive data and meet regulatory requirements. I am passionate about bridging the gap between security, risk, and governance, and I excel at aligning security practices with business objectives. Whether it’s working with internal teams or third-party vendors, I focus on building strong security postures that protect organizational systems and data.
Top Group Technologies Consultant.
-
Information Security AnalystTop Group Technologies Consultant. Jan 2022 - PresentLargo, Md. Managed and documented risks in alignment with NIST SP 800-30 and SP 800-37, utilizing a nine-step process to assess threats, vulnerabilities, and security controls surrounding information systems, including evaluating the likelihood and potential impact of exploits on system operations. Ensured compliance with information security policies by guiding and coaching internal teams on the proper use of information technology and best practices for safeguarding organizational… Show more Managed and documented risks in alignment with NIST SP 800-30 and SP 800-37, utilizing a nine-step process to assess threats, vulnerabilities, and security controls surrounding information systems, including evaluating the likelihood and potential impact of exploits on system operations. Ensured compliance with information security policies by guiding and coaching internal teams on the proper use of information technology and best practices for safeguarding organizational systems. Prepared and reviewed Authorization to Operate (ATO) packages for over 1,200 systems and facilities, including key documents such as SSP, RA, CMP, ISCP, DRP, IRP, and PIA. Collected and evaluated assessment artifacts to ensure compliance with NIST SP 800-53 rev 4 control requirements. Contributed to the FIPS 199 security categorization process and selected appropriate technical, operational, and managerial controls according to NIST SP 800-60 guidelines. Developed Plan of Action and Milestones (POA&M) to address corrective actions stemming from System Test and Evaluation (ST&E). Show less
-
It Security/ Litigation Support Analyst.Matstar Tech Services. Jan 2020 - Feb 2022United States Reviewed A&A (Assessment and Authorization) packages to ensure they were up-to-date and that security operations adhered to NIST 800-53 standards, HIPAA, FISMA, and organizational policies and procedures. Assisted in developing, defining, and maintaining HIPAA-compliant information security policies, standards, and procedures, focusing on management, operational, and technical controls. Identified deficiencies, discrepancies, misinformation, and compliance issues within loan… Show more Reviewed A&A (Assessment and Authorization) packages to ensure they were up-to-date and that security operations adhered to NIST 800-53 standards, HIPAA, FISMA, and organizational policies and procedures. Assisted in developing, defining, and maintaining HIPAA-compliant information security policies, standards, and procedures, focusing on management, operational, and technical controls. Identified deficiencies, discrepancies, misinformation, and compliance issues within loan documentation to determine eligibility or rejection, returning non-compliant packages to teams for resolution. Ensured compliance with and enforcement of applicable laws, following relevant rules and regulations. Provided legal services to the agency, including drafting and perfecting legal documents. Managed litigation efforts by liaising with external solicitors and the Federal Ministry of Science and Technology. Oversaw contract and agreement management for both national and international engagements. Managed the agency’s litigation portfolio, ensuring efficient resolution of legal matters. Show less
-
Project Manager/Scrum MasterSchlumberger Plc May 2016 - Jan 2020Houston, Texas, United States
Christopher John Education Details
-
Ideal Professional Institute.Professional Nursing
Frequently Asked Questions about Christopher John
What company does Christopher John work for?
Christopher John works for Top Group Technologies Consultant.
What is Christopher John's role at the current company?
Christopher John's current role is Information Security Analyst | Third Part Risk | GRC Analyst | Security Auditor | Cyber Security Analyst |.
What schools did Christopher John attend?
Christopher John attended Ideal Professional Institute..
Not the Christopher John you were looking for?
-
Christopher J.
Helping Businesses Harness The Power Of Ai To Transform Operations, Increase Efficiency, And Drive Innovation.United States2gmail.com, randrealtyllc.com -
Christopher John
Greater Boston5gmail.com, getingegroup.com, getinge.com, fujifilm.com, evariant.com4 +185757XXXXX
-
Christopher J.
Customer Success Manager | Real Estate Transaction Manager | Proptech | Sales & Marketing Manager | Project Manager | Relationship Manager | Client ManagerPhoenix, Az -
Christopher John
A Seasoned Quality Assurance Professional Actively Looking For Opportunities In Test Automation |Ctfl|Ctal-Tm| Ex-TcsNew York, Ny -
4yahoo.com, netzero.net, manh.com, smartpmtech.com
5 +177065XXXXX
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial