Information Security Engineer
CurrentAs an Information Security Engineer for Acorns, I managed and matured many aspects of Acorns' Information Security. Developed major portions of the Governance, Risk, and Compliance (GRC) domains and managed them to maturity. Embraced cross-functional collaboration with multiple teams to establish security processes and accountability; consequently, built-in information security awareness into Acorns' culture. - Governance and Audits: Managed external audits, vendor SOC report reviews, and risk assessments. Developed and streamlined Audit/Assessment processes and artifact gathering.- Risk Management through the Risk Register: Developed and managed Acorns' Risk Register. Provided Key Performance and Risk Indicators to executive management and metrics related to Acorns' strategic goals.- Third-Party Risk Management: Created, Developed, and managed the entire life cycle of the Third-Pary Risk Management program. - Policies and Standards: Matured the initial formal Policies and Standards for Acorns.- Physical Security: Assessed and implemented Physical Security processes and procedures for Acorns offices.- Business Continuity Program and Disaster Recovery: Created the Business Impact Analysis and BCP for Acorns. Researched every business unit of the Acorns' organization and built a program that can enhance the maturity of the BCP/DR on a regular basis. - Security Awareness and Training: Developed and managed Acorns' Onboarding, Annual, and Clicker Phishing training. Perform quarterly Simulated Phishing tests.