Senior Information Technology Analyst, Information Security
Executed a variety of risk management activities to identify and assess controls maturity; identify control gaps; ineffective controls or inefficient processes. Identified Key Control Indicators and Key Risk Indicators to assist technology process owners to detect potential gaps, controls operating effectively or ineffectively. Developed Process Risk Control Matrices or Risk Assessments for cloud engineering, patch management, logging and monitoring, job scheduling and data management.• Developed control dashboards to monitor metrics for early notification of risk trends to alert potential control failures• Served as an advisor to multiple technology process or control owners providing guidance on process design or control documentation, tool or process risk reviews• Reported current risk profile and highlighted emerging issues via annual Risk Assessments, Process Risk Control Matrices or targeted software assets at monthly stakeholder meetings or ad hoc risk reviews. Developed and issued risk dashboards and reports for internal stakeholders. Provided analysis of data to assess program effectiveness for stakeholder strategy decisions• Performed technical risk assessments of security, operational controls and processes, and Systems based of NIST Cybersecurity Framework and Publications, SOX and COBIT5• Risk Lead for several high-profile vulnerability management projects. Used reports generated from Nessus and Kenna Security vulnerability management scanning tools to review and assess• Led the enterprise patch management project. Assessed patch management processes and results to advise on gaps and recommend program or process enhancements• Coordinated with Issue Owners developing remediation plans and milestones to address issues identified by the Regulator Agency, Internal Audit or self-identified and tracked projects to completion• Directed a cross-functional response to a Regulatory Agency inquiry for a cyber-risk management gap analysis