GRC Analyst with over 5 years of expertise in developing and implementing governance, risk management, and
compliance strategies. Proficient in deciphering complex regulatory requirements to deliver practical solutions.
Demonstrated success in mitigating risks, cultivating compliance, and promoting ethical business practices. Achieved
a 15% reduction in compliance violations over the past year, emphasizing a commitment to organizational well-being
and strategic GRC leadership.
Enhanced and refined security controls, ensuring adherence to industry standards and regulatory
requirements.
Developed and implemented technology rules, fostering compliance and smooth operations across the
organization.
Managed exceptions to technology rules, maintaining proper documentation and obtaining necessary
approvals.
Communicated regularly with stakeholders, clarifying responsibilities and promoting accountability for
compliance.
Contributed to the development and maintenance of IT policies and standards, aligning with legal and
regulatory frameworks.
.
Conducted security assessments and audits to identify vulnerabilities and recommend remedial actions.
Developed and implemented security policies and procedures to safeguard company systems and data.
Monitored and investigated security incidents, ensuring timely resolution and implementing preventive
measures.
Collaborated with cross-functional teams to perform risk assessments and implement appropriate
controls.
Assisted in the evaluation and selection of security technologies and solutions to enhance the overall
security posture.
Conducted security awareness training sessions for employees, promoting a culture of security
awareness.
Assisted in regulatory compliance efforts, ensuring adherence to relevant industry standards and
regulations.
Conducted in-depth risk assessments of third-party vendors, evaluating their financial stability,
information security practices, regulatory compliance, and business continuity plans.
Developed and implemented risk mitigation strategies to address identified vulnerabilities and gaps in
vendor relationships.
Collaborated closely with cross-functional teams, including Legal, Procurement, and IT, to ensure
compliance with internal policies and industry regulations.
Reviewed and negotiated contracts with vendors, incorporating appropriate risk provisions and
ensuring alignment with company standards.
Monitored vendor performance and conducted periodic audits to assess ongoing compliance with
contractual obligations and risk management frameworks.
Risk Assessment & Management
Regulatory Compliance (GDPR, HIPAA, SOX, PCI-DSS)
Security Audits & Assessments
Vendor Risk Management
ServiceNow Proficiency
Cross-Functional Collaboration
Project Management
Security Testing and Evaluation (ST&E)
Security Awareness Training
Incident Response Planning
Data Privacy Management
Policy Development and Implementation
IT Security Frameworks (NIST, ISO 27001)
Data Analysis and Interpretation
Certified Information Systems Auditor (CISA)
· Pioneered a series of timely compliance initiatives that resulted in a 20% reduction in potential compliance violations within the first six months.
· Enhanced security controls, improved compliance, and streamlined operations, resulting in a significant reduction in security incidents, positive audit feedback, and increased employee awareness and compliance.
· Streamlined compliance reporting process by implementing advanced data analytics tools, resulting in a 25% decrease in manual data entry and reporting errors; saved 10+ hours per week for the team.
· Collaborated with cross-functional team to optimize and streamline company's compliance monitoring system, resulting in a 40% improvement reporting efficiency, ensuring regulatory compliance and mitigating risks.