Information Security Governance Consultant (Grc)
Currento Cyber Risk Management – Identifying, governing and proactively managing cyber risks of applications & 3rd party Vendors. Assigning and overseeing remediation plans, Exceptions and implementing controls to mitigate risks.o Conducting comprehensive 3rd party vendor risk assessments to evaluate and classify the severity of risks posed & the creation and development of Asset Risk Profiles (ARPs) additionally providing expert guidance to enhance cybersecurity measures and compliance.o Advising and enforcing ISO standards including ISO 27001, ISO 27005, ISO 27035, and ISO 22301 to enhance organisational data protection strategies, ensuring a compliance rate of 98% across all digital platforms.o Extensive experience and management Information Security and event management tools: Identity & Access Management (IAM) & solutions (SailPoint) (SIEM Tools proficient in: Archer, Compliance Buddy, IDM). o Coaching employees on GDPR & NIST frameworks leading to an overall 30% decrease rate in potential vulnerabilities and ensuring compliance.o Developed and executed inhouse phishing simulations targeting key departments, achieving a 45% improvement in phishing awareness and reducing successful phishing attempt rates by 15% through strategic training initiatives.o Managing + applying SOX Controls to enforce compliance across operational processes and employees.o Spearheading the creation and continuous improvement of security policies, standards, processes and documentation.o Performing audits, maintaining detailed records of findings and ensuring corrective actions are implemented in alignment with security standards.o Designing and executing robust cyber security architecture frameworks to aid security landscape goals.o Facilitating the pen testing scope, conducting security assessments and closely collaborating with developers to address identified vulnerabilities found.