Having a foundation in the ๐๐ข๐ฌ๐ค ๐๐๐ง๐๐ ๐๐ฆ๐๐ง๐ญ ๐ ๐ซ๐๐ฆ๐๐ฐ๐จ๐ซ๐ค (๐๐๐ ) and a solid understanding of ๐๐๐๐ ๐ฌ๐ญ๐๐ง๐๐๐ซ๐๐ฌ, including ๐๐๐ฌ ๐๐๐ ๐๐ ๐๐๐ ๐๐ ๐๐๐ ๐๐ ๐๐๐ ๐๐ & ๐๐๐ ๐๐ง๐ ๐๐๐ ๐๐ I have refined my skills in developing and implementing security programs that align with federal regulations and industry best practices.Throughout my journey I have consistently excelled in roles that require a comprehension of regulatory frameworks, risk management and the ability to bridge the gap, between technical complexities and business objectives.One area that particularly interests me is managing risks associated with ๐ญ๐ก๐ข๐ซ๐ ๐ฉ๐๐ซ๐ญ๐ฒ ๐ฏ๐๐ง๐๐จ๐ซ๐ฌ . I have evaluated and mitigated risks tied to vendors by ensuring their ๐๐จ๐ฆ๐ฉ๐ฅ๐ข๐๐ง๐๐ with requirements and adherence to stringent security standards. I firmly believe that effective third party risk management is crucial for a encompassing cybersecurity strategy.Moreover my expertise extends to creating security documents such as ๐๐ฒ๐ฌ๐ญ๐๐ฆ ๐๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ ๐๐ฅ๐๐ง๐ฌ (๐๐๐๐ฌ) ๐๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ ๐๐ฌ๐ฌ๐๐ฌ๐ฌ๐ฆ๐๐ง๐ญ ๐๐๐ฉ๐จ๐ซ๐ญ๐ฌ (๐๐๐๐ฌ) ๐๐ง๐ ๐๐ฅ๐๐ง๐ฌ ๐จ๐ ๐๐๐ญ๐ข๐จ๐ง ๐๐ง๐ ๐๐ข๐ฅ๐๐ฌ๐ญ๐จ๐ง๐๐ฌ (๐๐๐&๐๐ฌ). Additionally I have played a role, in obtaining Authorization to Operate (ATO) for systems.I take pride in my approach to work as well as my ability to function independently or as a valuable ๐ญ๐๐๐ฆ ๐ฉ๐ฅ๐๐ฒ๐๐ซ.I excel in challenging work settings that require problem solving and effective project management skills.My objective, on LinkedIn is to connect with professionals share knowledge and make contributions to the constantly evolving domain of cybersecurity and risk management. Lets ๐ ๐ ๐ ๐ ๐ ๐ ๐ ฃ and discover ways we can work together to๐ฌ๐ญ๐ซ๐๐ง๐ ๐ญ๐ก๐๐ง ๐ฌ๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ ๐ฆ๐๐๐ฌ๐ฎ๐ซ๐๐ฌ, ๐ฆ๐ข๐ญ๐ข๐ ๐๐ญ๐ ๐ซ๐ข๐ฌ๐ค๐ฌ ๐๐ง๐ ๐๐ง๐ฌ๐ฎ๐ซ๐ ๐๐๐ก๐๐ซ๐๐ง๐๐ ๐ญ๐จ ๐ซ๐๐ ๐ฎ๐ฅ๐๐ญ๐ข๐จ๐ง๐ฌ, in this changing landscape of threats.
Dynamic Education Services, Inc. (U.S Dol)
-
It Compliance AnalystDynamic Education Services, Inc. (U.S Dol) Mar 2023 - PresentDayton, Ohio, United Statesโข Conduct comprehensive risk assessments to identify potential hazards and vulnerabilities within the center's operations and facilities.โข Develops and updates Standard Operating Procedures (SOPs), System Security Plans (SSPs), and other policies to ensure alignment with industry standards and regulatory requirements.โข Ensuring that all risk management policies and procedures adhere to Department of Labor (DOL) regulations, maintaining a proactive stance on compliance.โข Establishing systems for incident reporting, conduct thorough analyses of incidents, and recommend corrective actions plans to prevent future occurrences.โข Proactively identifying areas for improvement in risk mitigation strategies and recommend enhancements to existing processes, fostering a culture of continuous improvement.โข Ensuring that policies, standards, and procedures is reviewed, relevant and updated.โข Supervise all aspects of departmental audit processes, including SOC 2 Type 2, SOC 2 Type 1, and future compliance frameworks.โข Gathering technical evidence and artifact requirements and communicate with relevant parties of ongoing compliance requirements.โข Ensuring adequate and timely resolution to all internal and external audit and risk assessment findings/issues.โข Provides support on regulatory and compliance initiatives.โข Coordinates and perform IT risk-based audits to identify control gaps and areas for improvement.
-
Information Technology AuditorComcast May 2019 - Feb 2023โข Executed day-to-day deliverables that support the ongoing compliance needs as well as any new regulatory requirements.โข Executed ITGCs and IT Application controls (ITAC) testing, determining design appropriateness and operating effectiveness of controls.โข Participated in the evaluation and risk assessment of business and IT processes, to identify risks and development recommendations for remediation.โข Performed compliance IT audits in accordance with COSO and COBIT internal control framework.โข Participated in all phases of IT audit process from planning, fieldwork, reporting and follow-up if required based on the result of the audit work.โข Performed SDLC pre and post implementation reviews, identify control deficiencies and provide recommendations to fix it. โข Conducted Business Continuity and Disaster Recovery audit.โข Identified information, people, process, and technology risks and weaknesses.โข Conducted assessment of the security and privacy controls to determine the overall effectiveness of the controls and the vulnerability state of components, applications and databases residing within the system boundary. โข Liaised with statutory auditors for compliance audits, corporate internal audit team, and IT management throughout the annual compliance life cycle.โข Planned and led IT complex Controls in areas of system development, information security, change management, business continuity, and disaster recovery. โข Identified and communicated control weaknesses, proposes remediation possibilities, and reaches agreement in a timely manner with Management, taking into consideration the wholistic impact to the business and root cause.โข Developed strategies, tools, and methodologies to measure, monitor, and report risks. -
Third Party Risk Cybersecurity Risk AssessorNordcloud, An Ibm Company Jul 2014 - Jan 2019โข Conducted periodic reviews of the Third-party risk management programs to identify areas for improvement and help ensure alignment with key business risks, regulatory requirements, and industry frameworks; revised program documentation as required.โข Partnered with 3rd parties to acquire applicable due diligence material relating to service(s) being provided.โข Reviewed due diligence material (policies and procedures, audit reports, certifications, BCP results, network scans, vulnerability assessments, etc.)โข Conducted vulnerability assessments on the organization's infrastructure with Nexpose in configuring and running scans, analyzing scan results, prioritizing vulnerabilities based on risk, and tracking remediation efforts.โข Reported findings and issues to all leadership levels within the organization.โข Effectively tracked inherent risk and residual risk; established repeatable and sustainable processes around risk management of third parties/suppliers to reduce the overall enterprise risk exposure.โข Conducted a comprehensive assessment of third partiesโ security controls and practices.โข Performed pre-contract due diligence review and post-contract ongoing monitoring activities based on specific third-party risk profile, country, and business requirements.โข Performed gap analyses on various third parties and risk program standards to improve the business control environment, identify weak or broken controls and recommend ways to fix and strengthen controls.โข Analyzed evidence and processes to assess controls enforced at third parties.โข Performed audit of IT general and application controls, information security, system development, change management, business continuity, disaster recovery and computer operations.
Randy P Education Details
Frequently Asked Questions about Randy P
What company does Randy P work for?
Randy P works for Dynamic Education Services, Inc. (U.s Dol)
What is Randy P's role at the current company?
Randy P's current role is Strategically Managing Third-Party Risks | FISMA and NIST Expertise | Championing Data Security.
What schools did Randy P attend?
Randy P attended Kwame Nkrumah University Of Science And Technology, Kumasi, University Of Ghana.
Not the Randy P you were looking for?
-
3bellsouth.net, lycos.com, cabinc.com
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records ร $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial