Gana R

Gana R Email and Phone Number

Third Party Risk and Compliance Analyst @ SHEIN Technology LLC
Washington, DC, US
Gana R's Location
Washington DC-Baltimore Area, United States, United States
About Gana R

An experienced cyber security professional specializing in information security and Third Party Risk management with over 6 years of professional record focusing on information risk management, IT audit, and policy management. I am a confident, innovative, and hardworking individual with some leadership skills working with a team or independently with little or no supervision. Experience in supporting security audits, continuous monitoring, control assessment, developing risk assessment reports, and managing risk mitigation, focusing on delivering efficient and cost-effective solutions.

Gana R's Current Company Details
SHEIN Technology LLC

Shein Technology Llc

View
Third Party Risk and Compliance Analyst
Washington, DC, US
Website:
sheingroup.com
Employees:
159
Gana R Work Experience Details
  • Shein Technology Llc
    Third Party Risk And Compliance Analyst
    Shein Technology Llc
    Washington, Dc, Us
  • Shein Technology Llc
    Third Party Risk/Compliance Analyst
    Shein Technology Llc Jan 2022 - Present
    Los Angeles, Ca, Us
    • Conduct third-party risk assessments including operational risk, financial risk, security risk, and legal risk for potential third-party agreements.• Identify security risks and exposures, determine the root causes, and recommend a plan of action to improve the security posture.• Prepare risk assessment reports to inform risk treatment decisions.• Track and monitor remediation and risk management activities to closure.• Develop and maintain third-party risk management program documentation and templates such as risk assessment processes, security questionnaires, security requirements in the vendor agreements, and assessment report templates.• Work closely with technology and legal partners and business units to ensure appropriate security and data protection requirements are incorporated into third-party engagements.• Maintain a current and comprehensive understanding of relevant industry standards to incorporate into the third-party risk management strategy, framework, and program.• Support integration and maturation of policy, compliance, and risk frameworks.• Generate technical and executive metrics for visibility and continuous improvement for the TPRM.• Response to day-to-day ServiceNow ticketing from the Global Security Risk Management to provide information security advice to ensure information risk management decisions. • Document and maintain procedures related to third-party risk management.• Contributes to creating and maintaining the library of information, policies, and standards based on ISO 27001 and other industry’s best practices.• Supports termination of vendors' contracts (end of life).
  • Vertiv
    Risk, Compliance Analyst Consultant
    Vertiv Aug 2021 - Dec 2021
    Columbus, Oh, Us
    • Perform documentation support services.• Enhance cyber awareness with vendors and project teams.• Collaborating with vendors to gauge priorities and extract insights for strategic planning activities. • Helping vendors identify business process improvements and gathering requirements to achieve efficiency, and improved oversight.• Identifying key stakeholders and other necessary engagement plans for organizational activities.• Develop plans for engaging with and communicating with stakeholders. • Designing appropriate analysis for diagnostics and implementation, analyzing, and interpreting ambiguous and complex information and relationships• Proactively engaging with vendors to identify challenges, recommend solutions, and manage expectations.• Support integration and maturation of policy, compliance, and risk frameworks to support business operations of the organization.• Maintaining processes and documentation and supporting the implementation and communication of policy• Participates in meetings and provides input into operational plans to identify policy needs and implications.
  • Quest Diagnostics
    Third Party Risk Analyst
    Quest Diagnostics Sep 2018 - Aug 2021
    Secaucus, Nj, Us
    ▪ Create, review, and/or update required security policies, standards, and procedures.▪ Conduct categorization/scoping of new vendors/suppliers.▪ Perform third-party security risk assessments for all new vendors and reassessments for high-risk vendors.▪ Review vendor's VSQs/SIG response and supporting documentation to validate vendor-appropriate implementation of information security controls such as SOC2 type I, ISO, HIPPA, and HITRUST, and Scan reports to identify gaps or exceptions.▪ Create a Risk Assessment Report (RAR) including findings and recommendations.▪ Develop an innovative approach to resolve and manage risk-related issues to minimize business impact.▪ Review vendor contracts and ensure security concerns are addressed.▪ Run internal and external vulnerability assessment scans.▪ Perform continuous monitoring▪ Monitor, and track TPRM lifecycle activities (identity, due diligence, risk assessment contract negotiation, ongoing monitoring, and termination)▪ Monitor and oversee alerting systems/services for early warnings of outbreaks or attacks.▪ Collaborate with IT personnel to monitor and maintain approved security solutions.▪ Develop a risk treatment plan to ensure vulnerabilities are remediated satisfactorily within the milestone.▪ Research on vulnerability in OWAPs, NVD, and US-CERTS to develop remediation plans.▪ Conduct awareness and training using Proofpoint/KnowBe4▪ Perform Cloud assessment. ▪ Act as a liaison during audits (gather evidence, attend meetings, respond to related questions).▪ Support other cross-operational duties assigned to me.▪ Develop and design department-wide risk assessment questionnaires across various domains.▪ Evaluated IT compliance gaps and worked with management to recommend solutions to improve policies.▪ Develop and publish security GRC dashboards and reports for internal stakeholders.

Gana R Education Details

  • University Of Buea
    University Of Buea
    Computer Sciences

Frequently Asked Questions about Gana R

What company does Gana R work for?

Gana R works for Shein Technology Llc

What is Gana R's role at the current company?

Gana R's current role is Third Party Risk and Compliance Analyst.

What schools did Gana R attend?

Gana R attended University Of Buea.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.