Information Security Analyst, Sr. Director
Current• Manage and assist a team who processes Information Security Due Diligence/Vendor Risk Management Questionnaires, RFPs, and RFIs in support of a client’s third-party assessment efforts• Map our enterprise and application security controls to various frameworks as requested by the client• For information gathering, utilize various resources like Shared Assessment’s Standardized Information Gathering (SIG) Tool, SME responses, knowledge databases, policies, and standards • Supply documentation in support of client assessment efforts (e.g., Diagrams/Procedures/Policies)• Maintain and utilize a knowledge base repository (Remedy RKM, Archer, RFPIO)• Communicate with various stakeholders (e.g., Sales, Account Management, Technology Teams) who support the various products/services offered by Broadridge • Provided audit support for internal and external audit activities (SSAE18, SOX, and FFIEC)• Collaborated with stakeholders in remediating and tracking audit exceptions and findings• Provided Identity Access Management (IAM) Governance on the Mainframe and iSeries systems• Reviewed existing security controls and support procedures for Access Management (Role Based Access, Access Authorization, Access Reviews, Privilege Account Management, Access Reviews, and Monitoring)• Collaborated with stakeholders in the research, development, and maintenance of security policies, standards, and procedures • Worked on a project to map controls, policies, and procedures to Cobit 5.0• Utilize RSA Archer for knowledge management and issues/remediation tracking