Grc Analyst (Cybersecurity Control Assessor)
Current- Spearheaded the achievement and maintenance of FedRAMP compliance and Authority to Operate (ATO) for cloud-based systems, enabling smooth system operations for high-impact environments.- Delivered comprehensive FISMA compliance assessments, leveraging NIST SP 800-37 Risk Management Framework (RMF) to ensure system security across multiple government contracts.- Developed and reviewed critical security documentation (e.g., System Security Plans, Security Assessment Plans, POA&Ms), streamlining the ATO process for multiple clients.- Conducted high-level FedRAMP and FISMA-based security risk assessments, producing actionable reports and out-briefings to ensure continuous compliance.- Led vulnerability testing using Nessus-Tenable, identifying and mitigating risks across cloud and application systems, reducing potential exposure by 20%.- Collaborated with cross-functional teams to address audit findings, enhance security policies, and ensure remediation measures met stringent deadlines.Key Achievements:- Played a key role in maintaining 100% compliance for FedRAMP and FISMA-regulated systems, significantly reducing security audit findings.- Proactively identified and closed 50+ POA&Ms, ensuring that all systems met compliance requirements ahead of schedule.