Analytical and collaborative Cybersecurity Team Lead/Risk Management Analyst with 5+ years’ total experience Product and Enterprise Security and Operational Technology (OT) within Medical Technology and Manufacturing industries. As Risk Analyst within Governance Risk and Compliance team, performed 50+ technical risk assessments on medical device products, and enterprise software/cloud-based hosted solutions to protect Confidentiality, Integrity, and Availability. Measured solutions against Security Control List to ensure Compliance with NIST and ISO Standards. Identified security gaps and suggested mitigations to development teams. Lead process development activities for special Cybersecurity Initiatives including M&A and Vulnerability Disclosures, meeting KPI goals, and working with Federal government to achieve joint objectives. Strong leadership and problem-solving abilities, able to think outside of box, and simplify complex workflows.Cybersecurity Industry Standards: Proficient in International Organization Standard 27001, National Institute of Standards and Technology (NIST 800-53); U.S Department of Defense Cybersecurity Maturity Model Certification (CMMC); U.S. Federal Risk and Authorization Management Program (FedRAMP); Service Organization Control 2 (SOC2).Areas of Expertise: Product Security, Business Risk Management, Leadership, Cloud/Application Security, Technical Risk Management, Cross-functional Collaboration, Enterprise Security, Third-Party Risk Management, Project Management, Operational Technology Security, Cybersecurity Maturity Models, Process DevelopmentSelected Accomplishments:Part of team to develop OPSS Standard Operating Model for M&A Integrations to mitigate business risk.Led PSIRT M&A Integration Project Plan Implementations to align security incident response policies.Assessed Software Changes and determined Risk Assessment Need with Regulatory & Privacy.Designed Vulnerability Disclosure Process to enable customers to mitigate risk using Crawl, Walk, Run Strategy.Ensured MFA Guidelines for Software/Hardware Environments were aligned with industry standards.Developed a Root Cause Analysis Program using 5 Whys Model to recommend long term corrective actions.Led Communications Efforts amidst Cyber Crisis including authoring public vulnerability disclosures.
Listed skills include C++, Unix, Hadoop, Assembly Language, and 5 others.