Randy P

Randy P Email and Phone Number

Strategically Managing Third-Party Risks | FISMA and NIST Expertise | Championing Data Security @
Randy P's Location
Dayton Metropolitan Area, United States
About Randy P

Having a foundation in the ๐‘๐ข๐ฌ๐ค ๐Œ๐š๐ง๐š๐ ๐ž๐ฆ๐ž๐ง๐ญ ๐…๐ซ๐š๐ฆ๐ž๐ฐ๐จ๐ซ๐ค (๐‘๐Œ๐…) and a solid understanding of ๐๐ˆ๐’๐“ ๐ฌ๐ญ๐š๐ง๐๐š๐ซ๐๐ฌ, including ๐’๐๐ฌ ๐Ÿ–๐ŸŽ๐ŸŽ ๐Ÿ๐Ÿ– ๐Ÿ–๐ŸŽ๐ŸŽ ๐Ÿ‘๐ŸŽ ๐Ÿ–๐ŸŽ๐ŸŽ ๐Ÿ‘๐Ÿ• ๐Ÿ–๐ŸŽ๐ŸŽ ๐Ÿ“๐Ÿ‘ & ๐Ÿ“๐Ÿ‘๐€ ๐š๐ง๐ ๐Ÿ–๐ŸŽ๐ŸŽ ๐Ÿ”๐ŸŽ I have refined my skills in developing and implementing security programs that align with federal regulations and industry best practices.Throughout my journey I have consistently excelled in roles that require a comprehension of regulatory frameworks, risk management and the ability to bridge the gap, between technical complexities and business objectives.One area that particularly interests me is managing risks associated with ๐ญ๐ก๐ข๐ซ๐ ๐ฉ๐š๐ซ๐ญ๐ฒ ๐ฏ๐ž๐ง๐๐จ๐ซ๐ฌ . I have evaluated and mitigated risks tied to vendors by ensuring their ๐œ๐จ๐ฆ๐ฉ๐ฅ๐ข๐š๐ง๐œ๐ž with requirements and adherence to stringent security standards. I firmly believe that effective third party risk management is crucial for a encompassing cybersecurity strategy.Moreover my expertise extends to creating security documents such as ๐’๐ฒ๐ฌ๐ญ๐ž๐ฆ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐๐ฅ๐š๐ง๐ฌ (๐’๐’๐๐ฌ) ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐€๐ฌ๐ฌ๐ž๐ฌ๐ฌ๐ฆ๐ž๐ง๐ญ ๐‘๐ž๐ฉ๐จ๐ซ๐ญ๐ฌ (๐’๐€๐‘๐ฌ) ๐š๐ง๐ ๐๐ฅ๐š๐ง๐ฌ ๐จ๐Ÿ ๐€๐œ๐ญ๐ข๐จ๐ง ๐š๐ง๐ ๐Œ๐ข๐ฅ๐ž๐ฌ๐ญ๐จ๐ง๐ž๐ฌ (๐๐Ž๐€&๐Œ๐ฌ). Additionally I have played a role, in obtaining Authorization to Operate (ATO) for systems.I take pride in my approach to work as well as my ability to function independently or as a valuable ๐ญ๐ž๐š๐ฆ ๐ฉ๐ฅ๐š๐ฒ๐ž๐ซ.I excel in challenging work settings that require problem solving and effective project management skills.My objective, on LinkedIn is to connect with professionals share knowledge and make contributions to the constantly evolving domain of cybersecurity and risk management. Lets ๐Ÿ…’๐Ÿ…ž๐Ÿ…๐Ÿ…๐Ÿ…”๐Ÿ…’๐Ÿ…ฃ and discover ways we can work together to๐ฌ๐ญ๐ซ๐ž๐ง๐ ๐ญ๐ก๐ž๐ง ๐ฌ๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐ฆ๐ž๐š๐ฌ๐ฎ๐ซ๐ž๐ฌ, ๐ฆ๐ข๐ญ๐ข๐ ๐š๐ญ๐ž ๐ซ๐ข๐ฌ๐ค๐ฌ ๐š๐ง๐ ๐ž๐ง๐ฌ๐ฎ๐ซ๐ž ๐š๐๐ก๐ž๐ซ๐ž๐ง๐œ๐ž ๐ญ๐จ ๐ซ๐ž๐ ๐ฎ๐ฅ๐š๐ญ๐ข๐จ๐ง๐ฌ, in this changing landscape of threats.

Randy P's Current Company Details
Dynamic Education Services, Inc. (U.S DOL)

Dynamic Education Services, Inc. (U.S Dol)

Strategically Managing Third-Party Risks | FISMA and NIST Expertise | Championing Data Security
Randy P Work Experience Details
  • Dynamic Education Services, Inc. (U.S Dol)
    It Compliance Analyst
    Dynamic Education Services, Inc. (U.S Dol) Mar 2023 - Present
    Dayton, Ohio, United States
    โ€ข Conduct comprehensive risk assessments to identify potential hazards and vulnerabilities within the center's operations and facilities.โ€ข Develops and updates Standard Operating Procedures (SOPs), System Security Plans (SSPs), and other policies to ensure alignment with industry standards and regulatory requirements.โ€ข Ensuring that all risk management policies and procedures adhere to Department of Labor (DOL) regulations, maintaining a proactive stance on compliance.โ€ข Establishing systems for incident reporting, conduct thorough analyses of incidents, and recommend corrective actions plans to prevent future occurrences.โ€ข Proactively identifying areas for improvement in risk mitigation strategies and recommend enhancements to existing processes, fostering a culture of continuous improvement.โ€ข Ensuring that policies, standards, and procedures is reviewed, relevant and updated.โ€ข Supervise all aspects of departmental audit processes, including SOC 2 Type 2, SOC 2 Type 1, and future compliance frameworks.โ€ข Gathering technical evidence and artifact requirements and communicate with relevant parties of ongoing compliance requirements.โ€ข Ensuring adequate and timely resolution to all internal and external audit and risk assessment findings/issues.โ€ข Provides support on regulatory and compliance initiatives.โ€ข Coordinates and perform IT risk-based audits to identify control gaps and areas for improvement.
  • Comcast
    Information Technology Auditor
    Comcast May 2019 - Feb 2023
    โ€ข Executed day-to-day deliverables that support the ongoing compliance needs as well as any new regulatory requirements.โ€ข Executed ITGCs and IT Application controls (ITAC) testing, determining design appropriateness and operating effectiveness of controls.โ€ข Participated in the evaluation and risk assessment of business and IT processes, to identify risks and development recommendations for remediation.โ€ข Performed compliance IT audits in accordance with COSO and COBIT internal control framework.โ€ข Participated in all phases of IT audit process from planning, fieldwork, reporting and follow-up if required based on the result of the audit work.โ€ข Performed SDLC pre and post implementation reviews, identify control deficiencies and provide recommendations to fix it. โ€ข Conducted Business Continuity and Disaster Recovery audit.โ€ข Identified information, people, process, and technology risks and weaknesses.โ€ข Conducted assessment of the security and privacy controls to determine the overall effectiveness of the controls and the vulnerability state of components, applications and databases residing within the system boundary. โ€ข Liaised with statutory auditors for compliance audits, corporate internal audit team, and IT management throughout the annual compliance life cycle.โ€ข Planned and led IT complex Controls in areas of system development, information security, change management, business continuity, and disaster recovery. โ€ข Identified and communicated control weaknesses, proposes remediation possibilities, and reaches agreement in a timely manner with Management, taking into consideration the wholistic impact to the business and root cause.โ€ข Developed strategies, tools, and methodologies to measure, monitor, and report risks.
  • Nordcloud, An Ibm Company
    Third Party Risk Cybersecurity Risk Assessor
    Nordcloud, An Ibm Company Jul 2014 - Jan 2019
    โ€ข Conducted periodic reviews of the Third-party risk management programs to identify areas for improvement and help ensure alignment with key business risks, regulatory requirements, and industry frameworks; revised program documentation as required.โ€ข Partnered with 3rd parties to acquire applicable due diligence material relating to service(s) being provided.โ€ข Reviewed due diligence material (policies and procedures, audit reports, certifications, BCP results, network scans, vulnerability assessments, etc.)โ€ข Conducted vulnerability assessments on the organization's infrastructure with Nexpose in configuring and running scans, analyzing scan results, prioritizing vulnerabilities based on risk, and tracking remediation efforts.โ€ข Reported findings and issues to all leadership levels within the organization.โ€ข Effectively tracked inherent risk and residual risk; established repeatable and sustainable processes around risk management of third parties/suppliers to reduce the overall enterprise risk exposure.โ€ข Conducted a comprehensive assessment of third partiesโ€™ security controls and practices.โ€ข Performed pre-contract due diligence review and post-contract ongoing monitoring activities based on specific third-party risk profile, country, and business requirements.โ€ข Performed gap analyses on various third parties and risk program standards to improve the business control environment, identify weak or broken controls and recommend ways to fix and strengthen controls.โ€ข Analyzed evidence and processes to assess controls enforced at third parties.โ€ข Performed audit of IT general and application controls, information security, system development, change management, business continuity, disaster recovery and computer operations.

Randy P Education Details

Frequently Asked Questions about Randy P

What company does Randy P work for?

Randy P works for Dynamic Education Services, Inc. (U.s Dol)

What is Randy P's role at the current company?

Randy P's current role is Strategically Managing Third-Party Risks | FISMA and NIST Expertise | Championing Data Security.

What schools did Randy P attend?

Randy P attended Kwame Nkrumah University Of Science And Technology, Kumasi, University Of Ghana.

Not the Randy P you were looking for?

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.