Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Lola Oyeyemi

Edmonton

Summary

Accomplished Information Security and Risk Management Leader with over 9 years of experience in designing and implementing robust security frameworks that protect organizational assets, mitigate risks, and ensure compliance with industry regulations. Recognized for developing and executing global security strategies that align with enterprise objectives and regulatory standards, with proven success in driving risk reduction and fortifying cybersecurity postures. Expert in delivering high-impact consulting and advisory services on Technology Controls, Information Security policies, and risk mitigation strategies. Respected for a strategic vision that fosters a culture of security awareness, operational efficiency, and continuous improvement within highly regulated environments. Adept at leading cross-functional teams, optimizing incident response protocols, and enhancing third-party risk management to safeguard business integrity and continuity. Known for an analytical approach to risk assessment, skilled communication of complex security concepts to executive and non-technical stakeholders, and a proactive approach to regulatory compliance. Proficiency in a wide range of industry standards and tools, including ISO 27001, NIST, CRI, RSA Archer, and OneTrust.

Overview

12
12
years of professional experience
1
1
Certification

Work History

Senior Analyst, IT Risk and Security

Co-operators Insurance
07.2023 - Current
  • Develop and lead implementation of Technology Controls and Information Security policies, advising on risk management and guiding cross-functional teams on mitigation strategies to protect organizational assets, reducing risk exposure.
  • Provide high-level consultation on risk assessment, vulnerability management, and control design, leading risk assessments for critical applications and delivering control gap analyses that inform the organization’s risk posture and remediation priorities.
  • Oversee quarterly SOX certification ensuring accurate and timely control certification and provision of adequate control evidence.
  • Managed annual Internal and External Audit exercise, providing control evidences and liaison on possible verbal enhancement and/or business issues.
  • Oversee global security management strategy, aligning security measures with Enterprise Architecture to proactively identify and address control gaps and ensure compliance with regulatory standards.
  • Manage ongoing Technology Risk reporting and metrics, analyzing trends to track control effectiveness, optimize resource allocation, and support decision-making at the executive level.
  • Enhance cybersecurity awareness by advising on enterprise frameworks, influencing a risk-aware culture, and conducting regular reviews of internal processes to drive continuous improvement.
  • Strengthen regulatory compliance efforts by consulting on regulatory requirements and coordinating audit readiness, leading to a 42% reduction in audit findings year-over-year.

Senior Governance, Risk, and Compliance Analyst

Intact Insurance
07.2021 - 07.2023
  • Conducted exhaustive security assessments aligning with ISO27001 and CIS frameworks, enhancing organizational compliance and security posture.
  • Led engagements involving comprehensive interviews with stakeholders to identify and understand security vulnerabilities, facilitating precise risk assessment and mitigation strategies.
  • Facilitated crucial risk discussions, fostering stakeholder alignment on risk profiles and mitigation plans, ensuring informed decision-making and risk management.
  • Drove comprehensive vendor management initiatives, meticulously reviewing SOC2 reports and conducting thorough assessments to gauge 3rd party risk exposure, ensuring alignment with stringent security standards and minimizing potential vulnerabilities in external partnerships.
  • Collaborated extensively across IT, Security, and Finance/Risk teams to prioritize and implement control enhancements, harmonizing them with strategic objectives.
  • Oversaw risk stemming from third-party collaborations, executing risk analyses and mitigation plans, and safeguarding against potential vulnerabilities in partnerships.
  • Provide risk control, and self-assessments (RCSA) according to policies and standards and recommend changes to ensure compliance.

Underwriter (Commercial Lines)

Peace Hills Insurance
12.2020 - 07.2021
  • · Negotiated coverage, policy pricing, and service delivery during meetings with customers, agents, or brokers.
  • · Assessed new and renewal applications for financial liabilities and risk levels.
  • · Maintained compliance with regulatory requirements by staying informed of changing laws and adjusting procedures.
  • · In-depth risk analysis as well as providing timely and accurate quotations for new and existing transactions

Governance, Risk and Compliance Associate

AXA
03.2015 - 10.2019
  • Led enterprise risk management initiatives including corporate governance framework, risk management, and regulatory compliance services offerings for clients across various industries.
  • Conducted thorough regulatory compliance evaluations and audits, ensuring adherence to industry standards like SOC2, ISO27001, and NIST.
  • Guided clients on regulatory obligations, facilitating compliance with legal requirements and industry best practices.
  • Performed detailed risk assessments, offering strategic recommendations tailored to clients' needs, and enhancing their risk management strategies.
  • Documented and prepared final assessment reports (risk statements) at the end of each project, including findings with their risk levels, management responses, and remediation recommendations with the target completion date.
  • Managed end-to-end third-party cybersecurity risk, conducting in-depth assessments, and diligently reviewing attestation reports like SOC 2 and penetration test reports to ensure continual compliance with desired security posture.
  • Played a pivotal role in responding to cybersecurity incidents, collaborating with external vendors for swift resolution, and fortifying security measures effectively.
  • Monitored risk indicators, aligning them with predefined thresholds, and reported breaches, adhering to organizational policies and frameworks.

Financial Analyst

AXA
12.2012 - 03.2015
  • · Prepared monthly and quarterly profitability reports to assess the company's performance and presented them to management.
  • · Proactively monitored and contributed to delivering cost targets and investment results using the monthly Operating Performance Report (OPR) as a tool which drove down costs by 5%
  • · Assessed budgetary performance weekly and monthly to keep departments in line with standards
  • · Developed and monitored relevant KPIs for teams and analyzed portfolio performance.
  • · Prepared product profitability reports and recommended product discontinuance/review to management.
  • · Maintained a robust yearly industry database and peer review for the top 10 insurance companies to highlight and compare relative performance and made recommendations where required
  • monthly variance analysis reviews between actual results and budget/forecast expectations..
  • Facilitated smooth month-end close processes by efficiently reconciling accounts and addressing discrepancies promptly.
  • Streamlined financial reporting for better decision-making with clear, concise analysis and presentation.
  • Trained junior analysts on best practices in financial modeling, contributing to a stronger overall team performance.

Education

Bachelor of Science - Statistics

Olabisi Onabanjo University
Nigeria
04-2009

Skills

  • Comprehensive Knowledge of compliance frameworks and standards such as SOC 1 & 2, ISO 27001/27002, PCI DSS, and CRI Profile, NIST CSF framework
  • Proficiency in 3rd party risk assessment
  • Knowledge in GRC tools like RSA Archer and OneTrust
  • Proficiency in Microsoft Office and SharePoint
  • Risk Assessment & Management Proficiency
  • Threat Intelligence & Incident Response

Certification

  • CISSP - Certified Information Systems Security Professional -In progress
  • Certified in Information Security Management (CISM)-In progress


Timeline

Senior Analyst, IT Risk and Security

Co-operators Insurance
07.2023 - Current

Senior Governance, Risk, and Compliance Analyst

Intact Insurance
07.2021 - 07.2023

Underwriter (Commercial Lines)

Peace Hills Insurance
12.2020 - 07.2021

Governance, Risk and Compliance Associate

AXA
03.2015 - 10.2019

Financial Analyst

AXA
12.2012 - 03.2015

Bachelor of Science - Statistics

Olabisi Onabanjo University
Lola Oyeyemi