• Developed concise, tailored cybersecurity awareness content, improving targeted end-user base cyber hygiene
• Developed Just-In-Time cybersecurity awareness content for emerging threats to reduce operational risk to tailored audiences
• Prepared, executed, and reported on audit of subset of NIST SP 800-53 cybersecurity controls to include interview, document review, and testing of systems to support compliance audit activities.
• Knowledgeable on NIST Cybersecurity Framework and how the Identify, Protect, Detect, Respond, and Recover categories comprise and facilitate an information security program
• Semi-quantitatively analyzed cybersecurity risk using NIST SP 800-30 methodology to identify highest risk weaknesses for a system
• Executed threat modeling exercise to determine higher likelihood threat events to inform cybersecurity risk modeling
• Developed Information Security policy to establish authorized access management and authenticator management for internal and third-party personnel.
• Ensured policy documents are aligned with business objectives, implementable by the organization, and practical for compliance by ensuring purpose, scope, authority, and policy statements incorporate operational perspective and constraints