Compliance Analyst
Current+ Analyzed and conducted security assessments of over 100 vendor SOC2 Type2 Reports to determine compliance with applicable security controls and standards (NIST SP 800-53 Revision 5.1) to ensure controls were implemented correctly, operating as intended and producing the desired outcomes in relation to applicable regulatory and industry requirements. + Designed, implemented and coordinated the compliance reporting process for external vendors. Responsible for building and maintaining a strong level of customer service provided support to state agencies for mandated compliance in screening outside vendors for conformity with applicable state regulatory and industry requirements for information security. Developed tracking documentation to manage received SOC2 Type2 Reports, organize reviews and maintain artifacts and documentation using approved system tools.+ Developed infrastructure and IT Process assessments for use across organization’s computing environment. Identified areas for business improvements. Performed systems security evaluations, audits, and server logging reviews to verify secure operations. Applied Risk Management Framework (RMF) using NIST as guide for assessments and CM.+ Conducted risk assessments by analyzing SOC2 Type2 reports to mitigate the risk of information loss and determine gaps in information processes and procedures.+ Assisted with Security and Information Systems management, the Legal department, Fraud department, Human Resources and law enforcement agencies to manage security vulnerabilities or inquiries. Ensured security controls were implemented correctly, executed per design and provided appropriate results.