Compliance Analyst
CurrentMy role includes:• Identification of risk and control assessment throughout development phases. Areas include networks, operating systems, databases, security, disaster recovery and BCP. • Ensuring compliance with data confidentiality, integrity and availability. • Carrying out periodic due diligence and ongoing monitoring using Security Scorecard• Execute threat modelling exercise to determine higher likelihood threat events to inform cybersecurity risk modelling• Documentation gathering from all stakeholders and labelling to aid audit• Carrying out of walkthroughs• Testing of controls and compilation of Audit report • Ensuring compliance of PCI DSS standards• Develop concise, tailored cybersecurity awareness content, therefore improving targeted end-user cyber awareness• Continuous development of cybersecurity awareness content for emerging threats to reduce operational risk to tailored audiences• Ensure policy documents are aligned with business objectives, implementable, and practical for compliance • Ensuring purpose, scope, authority, and policy statements incorporate operational perspective and constraints• Reporting on audit of subset of NIST SP 800-53 cybersecurity controls to include interview, document review, and testing of systems to support compliance audit activities.• Ensuring risk is residual and properly managed