Senior Grc Analyst
CurrentLead role in continuous development, monitoring and ensuring Zillow compliance to ISO27001, NISTCSF, GLBA, NIST 800-53 and a supporting role on PCIDSS, NACHA and Privacy compliancemaintenance.• Point person for internal reviews, gap analysis and updating of internal policies, standard and procedureper changes in regulatory requirement and internal operational changes.• Facilitated the alignment of organizational policies and controls with ISO27001, NIST CSF, GLBA,NIST 800-53, ISO 27001, frameworks and standards, and SOC 2 audit requirements.• Carry out quarterly gap analysis efforts by identifying non-compliance issues, crafting corrective actionsplans, and work with subject matter expert (SME) and stakeholders to remediate gaps while trackingprogress in a risk register, fostering a culture of security and compliance across the organization.• Developed and implemented risk management plans in accordance with NIST and ISO 27001guidelines.• Monitored risk factors and provided detailed reports, actionable insights, and recommendations to seniormanagement.• Zillow SME in risk assessments, crafting risk factors, identifying, triaging, assessing, andprioritising risks, and documenting findings in the risk register.• Active role in internal organization’s audit initiatives, ensuring compliance with internal and externalregulatory requirements, in preparation of ISO27001, NIST CSF, GLBA, NIST 800-53, PCIDSS,NACHA, SOC2 and Privacy external audit.• Organize annual training sessions, quarterly phishing campaign trainings to educate staff on compliance standards, and general cybersecurity best practices leveraging NIST 800-53, OWASP updates &New compliance• Advised management and team members on technology-related risks, improving security posturethrough strategic implementation,• Carry out monthly vulnerability scan in accordance with Zillow Information security policy• Coordinated with internal and external teams to address threats and risks