As a Cyber Security Governance, Risk Management, and Compliance (GRC) specialist, my expertise lies in enabling organizations to establish and maintain robust cybersecurity measures. My focus is on evaluating their current security protocols, identifying potential risks, and devising and implementing effective policies and procedures to mitigate them. My ultimate aim is to ensure that my clients comply with industry standards and regulations, including but not limited to PCI DSS, HIPPA, ISO 27001, and NIST, while simultaneously helping them develop a resilient cybersecurity/info security/technology security program that safeguards their valuable assets and reputation. Leveraging my extensive knowledge of cyber threats and industry best practices, I collaborate closely with my clients to ensure their success.GRC - Governance, Risk and ComplianceHIPAA, NIST 800-53 (Fed Systems Controls), NIST 800-59, NIST 800-171 (Non-Fed Systems), ISO 27001, ISO 27002, SOC2, GDPR, FISMA, CybersecurityNetwork SecurityInformation SecurityAnalytical SkillsSecurity Information and Event Management (SIEM)Penetration TestingVulnerability AssessmentLeadershipCommunicationLinuxAWSAzsureInformation TechnologyTroubleshooting
-
Cyber Security AnalystKaiser Permanente Apr 2019 - PresentOakland, California, UsCYBER SECURITY GRC CONSULTANT• IT Security Program: Contribute to IT Security Program maturity and compliance assessments based upon industry standards and best practices including HIPAA, ISO, NIST, and HITRUST Cert.• Policies and Standards: Identify, develop, implement, and maintain consistent and standardized international security processes and policies, to mitigate risk and safeguard the enterprise worldwide.• Risk Assessments: Assist with security risk assessments that are in line with our corporate policy to ensure that KP assets are properly protected.• Risk Assessments for M&A: Assist in ensuring appropriate due diligence is conducted for merger and acquisition activities by conducting a thorough risk assessment.• Data Governance: Proactively advise the business on how to maintain data privacy as they relate to regulatory requirements (e.g., EU GDPR, CCPA).• Compliances: Hands-on knowledge of regulatory compliance initiatives e.g., New York DFS cybersecurity regulation (NYDFS), Payment Card Industry (PCI), and Health Insurance Portability and Accountability Act (HIPAA).• Vendor Risk Management: Validate and monitor gaps identified during the vendor risk assessments, due diligence, and ongoing monitoring to support adherence to vendor risk management policies.• Cloud Security: Design the security governance for both hybrid and non-hybrid cloud solutions in Azure.• Vulnerability Assessments: Work with the Threat and Vulnerability Manager and the Security Operations team to develop and maintain a threat and vulnerability intelligence process that monitors for emerging systems vulnerabilities and cyber threats.• PCI Compliance: Experienced in leading projects related to PCI Compliance, including network security audits, access controls, and encryption audits. -
Consultant Application & Security GovernanceNyu Langone Health Apr 2015 - Mar 2019New York, Ny, Us• Manage Epic Applications Implementations & Program Governance.• Developed and maintained the Business Continuity and Disaster Recovery program to ensure critical applications and infrastructure have documented downtime/recovery procedures and are tested annually.• Developed and managed the enterprise security risk assessment program including penetration testing, application security, HIPAA/CSF security assessments, vendor security, biomedical device security.• Developed and maintained the security education and awareness program that delivers role-based security education, is based on gamification concepts and leads to measurable improvement in building a risk aware culture at all levels. Created and delivered information security concepts in simple and engaging manner through newsletters, social media, blogs, video, new employee orientation, townhalls and in person.• Understood the opportunities and challenges facing business, mission, IT, and operational groups and be able to balance institutional risk with business and mission objectives. Designed and implemented mechanisms to monitor adherence to strategies and policies and take corrective action as needed.• Adhered to NIST Cyber Security Framework, HIPAA, Joint Commission, Promoting Interoperability.• Responsible for implementing an GRC tool to manage cyber risks.• Maintained a formal risk register which drives security governance and ensures security funding is aligned with business objectives.• Worked collaboratively with the other Managers, Directors, CMIO, CIO, Service Line Leads, Steering Committees and other key partners to manage Cyber Security risks. -
Lead Clinical ApplicationsKeck Medicine Of Usc Nov 2009 - Mar 2015Los Angeles, Ca, UsBuild & Configuration of Clinical Applications. Implementations of Clinical Applications.Role-based Application security awareness
Atif Sheikh M. Education Details
-
London Metropolitan UniversityInformation Systems & Development
Frequently Asked Questions about Atif Sheikh M.
What company does Atif Sheikh M. work for?
Atif Sheikh M. works for Kaiser Permanente
What is Atif Sheikh M.'s role at the current company?
Atif Sheikh M.'s current role is Actively Looking! - AWS Administrator.
What schools did Atif Sheikh M. attend?
Atif Sheikh M. attended London Metropolitan University.
Free Chrome Extension
Find emails, phones & company data instantly
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial