Samuel B Email and Phone Number
Highly dedicated and results-oriented IT professional with 8+ years of progressive experience in securing information and information systems. Proven expertise in implementing security compliance policies, conducting risk assessments, and developing impactful information security strategies. Skilled in utilizing advanced tools, such as EDR, vulnerability scanning, data loss prevention, and log management. Experienced in effectively managing third-party risks and conducting comprehensive compliance assessments. Possesses strong knowledge of regulatory frameworks and industry standards, including NIST, GDPR, CCPA, NYDFS, COBIT, ISO 27001/2, FedRAMP, HITRUST, PCI-DSS, SOC 1&2, CIS Benchmarks, and FIPS 199/200. Seeking a challenging role as an Information/Cybersecurity analyst to deliver tangible results for this organization.
Transamerica
View- Website:
- transamerica.com
- Employees:
- 15388
-
Snr Governance, Risk And Compliance AnalystTransamericaUnited States -
-
Snr Governance, Risk & Compliance AnalystTransamerica Dec 2023 - PresentBaltimore, Maryland, Us• Maintained security compliance programs within a GRC or compliance automation solution• Tracked audit remediation actions, help develop solutions, and report on the status.• Coordinated with external auditors and Flexential’s operations teams to obtain audit evidence for in-scope IT systems to support the annual audit, such as SOC 1&2, ISO 27001, HITRUST, PCI-DSS. • Developed and maintained flexential’s security policies, standards and guidelines.• Supported Flexential’s response to Regulators, Auditors, Client inquiries, and Due Diligence Questionnaires.• Conducted assessments of third-party vendors and partners to ensure they meet our security and compliance standards• Executed vulnerability scans and coordinate related remediation activities.• Monitored and responded to information security risks related to systems, networks, and applications to ensure internal security controls are operating as intended -
Information Security Compliance AnalystFlexential Aug 2023 - Nov 2023Charlotte, North Carolina, Us• Coordinated with external auditors and operations teams to obtain audit evidence for in-scope IT systems to support the annual audit such as SOC 1&2, ISO-27001, HITRUST, and PCI-DSS.• Supported the development and implementation of a risk register process.• Performed quarterly risk register reviews; managed and monitored remediation and exceptions of cybersecurity risks.• Provided guidance and support to business units on information security matters, including security awareness training and incident response.• Developed and maintained information security policies, standards, and procedures aligned with industry best practices.• Identified and communicated control gaps; evaluated management remediation action plans, and provided ongoing monitoring of resolution.• Maintained awareness of external regulations and industry standards for new or modified requirements (PCI-DSS, NIST 800-53, ISO 27001, etc.). -
Information Security Technical Compliance AnalystArray Feb 2023 - Jun 2023New York, Ny, Us• Conducted comprehensive risk assessments to identify potential security vulnerabilities and threats.• Implemented GRC processes to automate and continuously monitor information security controls, exceptions, risks, and control testing.• Documented incidents and reported them per regulatory requirements.• Conducted incident response activities, including investigation and remediation.• Led external audits with frameworks such as SOC 1&2, ISO 27001, PCI-DSS, HITRUST CSF.• Analyzed security logs to detect suspicious activities.• Collaborated with cross-functional teams for holistic security risk management. -
Lead Risk And Compliance AnalystAir Products Oct 2021 - Oct 2022Allentown, Pennsylvania, Us• Reviewed technical systems controls and report on security weaknesses and communicate significant control and compliance risk to management.• Identified and resolve any issue of noncompliance, with a related standard or framework• Developed and implements information security policies, procedures, and standards to protect the confidentiality, integrity, and availability of information systems and data• Responded to external requests for Security Questionnaires, Due Diligence, Vendor Risk Assessments, and other categories that require responses.• Leveraged GRC tools to efficiently manage external authoritative sources, information technology controls, and risk management workflows.• Actively offered internal security consulting on policies, controls, standards and best practices to business functions and end users.• Supported in vulnerability scan reports interpretation, enabling prompt resolution of identified vulnerabilities. • Conduct security awareness and training programs. -
Information System Security OfficerNational Distribution Centers Jan 2015 - May 2021UsExamine SOC and HITRUST reports, vulnerability assessments, policies, procedures, and standard documents to evaluate compliance. This involves reviewing system configurations, security protocols, access controls, encryption measures, and incident response plans.• Ensure the protection of Confidential Unclassified Information (CUI), the standards outlined in DFARS and NIST 800-171• Prepare a plan of action and milestones based on the findings and recommendations of a security assessment report excluding any remediation actions taken.• Develop/Review deliverables associated with a FedRAMP security authorization package including, but not limited to: System Security Plan, Information System Contingency Plan, Security Assessment Plan, Security Assessment Report.• Supports Security Control Assessments using NIST 800-53A Rev5 as guidance for current federal directives and policies.• Performs System Security Categorizations using FIPS 199 and the NIST 800-60 Vol.11 Rev1 guidelines and templates to select provisional impact level assigned to the Confidentiality, Integrity and Availability (CIA) based on the information type.• Analyzes and updates System Security Plan (SSP), Risk Assessment (RA), Privacy Impact Assessment (PIA), System Security test and Evaluation (ST&E).• Develops and track Plan of Actions and Milestones (POA&Ms) to ensure remediation closure.• Maintains and manages Security Authorization and Assessment packages that include System Security Plans (SSP), Contingency Plans (CP), POA&Ms, SAR, and other relevant security documentations for the system.• Perform security risk assessment and analysis of resources, controls, vulnerabilities, asset decommissioning, and information security threats to the organization’s objective.
Samuel B Education Details
-
Kwame Nkrumah University Of Science And Technology, KumasiGeneral
Frequently Asked Questions about Samuel B
What company does Samuel B work for?
Samuel B works for Transamerica
What is Samuel B's role at the current company?
Samuel B's current role is Snr Governance, Risk and Compliance Analyst.
What schools did Samuel B attend?
Samuel B attended Kwame Nkrumah University Of Science And Technology, Kumasi.
Who are Samuel B's colleagues?
Samuel B's colleagues are Derrick White, Tonya Seaborne, Natalie Zoumis, Gabrielle Aikin, Nikkee (Sheryl) Pierce, Joyce Kelly, Laura Alger.
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial