Organized and dedicated GRC Policy Analyst Cybersecurity Analyst with years of experience in developing and implementing effective security policies, procedures, and controls to protect organizations from cyber threats. Proven ability to work collaboratively with cross-functional teams to ensure compliance with various security frameworks such as HIPAA, PCI-DSS, TPRM, ISO 27001, SOX, SOC. Skilled in conducting security assessments, risk analyses, and audits to identify vulnerabilities and recommend appropriate controls using National Institutes of Standards and Technology (NIST) Special Publications 800-53, 800-53A, 800-60, 800-30, 800-37, 800-171, FIPS 199, FIPS 200.TECHNICAL SKILLSAssessment and Authorization (A&A) | NIST 800 Series | Plan of Actions and Milestone (POAM) | System Security Plan (SSP) | System Assessment Report (SAR) | Risk Analysis | Risk Assessment | Risk Control & Mitigation Security Life Cycle | Threat Reports | Contingency Planning | Data Security | Developing security plans | Implementing security programs | Wireshark | Nmap | Implementing security controls | Nessus Software | TPRM| ISO 27001 | PCI DSS | Risk Management Framework (RMF) | SOX | HIPAA| SSAE | SIEM Monitoring | JIRA | iOS/OS platform security | Mobile/tablet device security | Penetration testing |Ethical hacking |Vulnerability assessment |Network security |Firewall management |Encryption |Access control and authentication | Log management and monitoring | Microsoft Windows| Microsoft Office Suite (Word, Excel, PowerPoint, Outlook)