Risk And Compliance Manager
Extensive expertise in NIST 800-53 Rev5, IRS Pub 1075, CJIS, SSA, ISO 31000, HIPAA, and ePHI obtained through federal and state external audits, risk assessments, vendor evaluations, solution assessments, ATO deliveries, contract reviews, and other security assessments. Implemented multiple GRC tools by conducting testing, establishing workflows, and developing metrics. Utilized several security tools to assess risks, conduct gap analysis, and create metrics and dashboards for technical experts. Developed policies, processes, procedures, and metrics to optimize team operations, including audit repository, POA&M tracking, ERM, SSPs, DRPs, SOPs, risk acceptance, exceptions, and executive leadership metrics.