Grc Analyst
Current• Delivered comprehensive ISMS metrics, audit results, and risk trend analyses to senior management, enhancing informed decision-making.• Executed ISO/IEC 27001:2013 and SOC 2 Type I and II internal audits, ensuring compliance with external assessments.• Expanded ISMS scope to new sites, updating documentation to align with compliance requirements.• Conducted 15+ risk assessments, developed risk treatment plans, and reduced vulnerabilities by 30%.• Spearheaded third-party security assessments and formalised audit findings into actionable reports.• Led a Business Impact Analysis, identifying critical departmental processes and improving operational resilience.