Security And Compliance Professional
CurrentEngaged with technical personnel, management, and director-level management to define deliverables, requirements, scope of work, statement of work, and strategy of the engagement. Performed as an individual contributor, lead consultant, or project manager working with internal staff, as well controlling third-party resources. Conducted organizational information security program assessments based on the NIST Cybersecurity Framework, ISO/27001, ISO/27002, COBIT 5 and COBIT 5 for Information Security, and ITIL v3. Performed risk assessments using ISO/27005, ISO/31000, NIST SP800-30/53, and Custom/Hybrid Combinations. Assessed organizational risk management programs based on ISO/27001, ISO/27002, ISO/27005, ISO/31000, NIST SP800-37/39, and the NIST Risk Management Framework. Performed Risk Assessments and Risk Management for the internal corporate environments, as well as third-party servicers. Completed compliance requirements of logical and physical controls for Graham-Leach-Bliley Act (GLBA) Safeguards Rule, Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule, Sarbanes-Oxley Act (SOX) Section 404, and the Statement on Standards for Attestation Engagements (SSAE) SOC2 Type 2 Audit Reports. Analyzed and assessed security programs for data protection environments for the confidentiality, integrity, and availability of information assets, whether it be logical and/or physical. Assessed data classifications, data authorizations, and data access controls. Compared and related findings to generally accepted best practices, frameworks, and standards for compliance requirements and regulations. Reviewed and provided recommendations for improvements to information security policy sets, including the creation of privacy policies and privacy management programs. Dictated requirements for compliance to privacy laws and regulations.