Information Security Consultant
Current☁︎ Gathered evidence and justified processes during multiday Internal and External Audits against the ISO 27001 standard;☁︎ Led the annual risk assessments based on the risk methodology plan, identifying risks requiring mitigation and their respective risk treatment plans;☁︎ Created a mobile device policy to mitigate BYOD risks associated with confidentiality, integrity, and availability, increasing the company’s cybersecurity posture;☁︎ Developed, implemented, maintained and monitored policies and procedures in compliance with ISO27001 and HITRUST, assisting the organization in certification efforts;☁︎ Frequently reviewed user access lists and privileged access rights, following company policy and procedure;☁︎ Populated and led the asset inventory listing and mobile device listing, ensuring accurate data was recorded and properly labeled based on information classification;☁︎ Ensuring company asset configurations were installed according to policy related to password management, time synchronizations, anti-virus, and more;