GRC Professional with CISSP, CISM, CISA, CEH, ECSA, Security+, ITIL Foundations achieved certifications.IT Security Compliance liaison with internal audit, compliance, risk, legal, finance, IT, HR, as well as, the lines of business, executive suite, and the Board of Directors. Determine if the company business information security objectives and policy comply with rapidly changing government laws and regulatory requirements. Design and develop - strategies, policies, standards, tools, and controls which are most suited to protect data and privacy. Appropriate data protection everywhere it is hosted, accessed, stored, processed, transmitted, reviewed, reported on, and received. Evaluate and improve the enterprise security environment - policy, standards, operational procedures, controls, monitoring, reporting, response, and awareness. Proactively identify viable threats and existing, exploitable vulnerabilities then focus on implementing the appropriate and most cost-effective security solutions that remain within budget. Design, develop, and implement Governance, Risk, and Compliance controls and processes to achieve business and audit objectives. Manage design, automation, and integration teams to computerize manual processes.Unified Compliance Framework - Collect evidence once for overlapping audit requirements to streamline the process, increase efficiency, reduce cost, and save valuable time for all the organizations involved. Comply with multiple regulations and standards efficiently by leveraging harmonized mappings towards a ‘test once, comply with many’ approach. Technical Toolset: OneTrust, SailPoint, Archer, Modulo, MetricStream, ServiceNow, Microsoft Azure, Amazon Web Services, SolarWinds, Cisco, Juniper, Fortinet, Guardium, Qualys, Nitro, Unix, Linux, Microsoft Office Suite, IBM OS/390-AS400, TSO/ISPF …
Listed skills include Security, Disaster Recovery, Information Security, Data Center, and 31 others.