GRC Analyst | Information Security Analyst with experience developing and testing security framework for cloud-based software. Knowledge in Information security, Risk Management Framework (RMF) process, FIPS, FISMA, NIST compliance, vulnerability management, threat intelligence, and extensive experience developing and testing security framework for ATO approval. Proficient with additional frameworks such as HIPAA, PCI-DSS, ISO 27001, SOX, SOC.Risk Management Framework (RMF) | SIEM Monitoring | NIST 800 Series | Plan of Actions and Milestone (POAM) | System Security Plan (SSP) | System Assessment Report (SAR) | Assessment and Authorization (A&A) | Data security | HIPAA | PCI-DSS |ISO 27001|SOX| SOC| Developing security plans | Implementing security programs | Implementing security controls | Nessus | Software Programing and Administration | Windows | AppScan | Wireshark | Web Inspect | Nmap | Snort | Microsoft Office Suite (Word | Excel | PowerPoint | Visio | Outlook) | Microsoft Server Administration (Windows 2000 | 2003 | 2008) | SQL Server Database