I am and experienced GRC Analyst. I have worked on projects such as mapping frameworks such as NIST 800-53 and ISO 27001. I Developed remediation planning and action items for multiple business units. I have conducted several Privacy impact assessments, data governance risk assessments, and third-party risk assessments. I have been instrumental in carving out cyber strategy and resilience for many organizations.
· Conduct compliance evaluations against ISO27001, PCI DSS, GDPR, and NIST standards
· Perform risk and control assessments aligned with corporate Cyber security Framework
· Develop and review security policies, procedures, and internal controls
· Lead security awareness training initiatives
· Assess security of projects and third-party vendors
· Maintain and update Security Risk Register
· Conduct gap analysis and security assessment reviews using ISO 27001
· Provide guidance on continuous risk identification, assessment, and mitigation
· Conducting audit on third parties to test the effectiveness of security controls in place in line with business requirements (ISO 27001, Cyber Essentials, and GDPR).
Accomplishments
· Successfully reviewed IT Security Policy with cross-functional team
· Developed Cloud Security Audit Guidelines using Microsoft Cloud Security Benchmark and Cloud Control Matrix
· Contributed to enhancing overall security posture through policy reviews and control assessments
· Managed the safety and compliance of critical infrastructure systems, with a specific focus on telecom base station power infrastructures.
· Conducted thorough risk assessments and implemented robust safety measures during commissioning activities, ensuring adherence to safety protocols and regulatory standards.
· Diagnosed and rectified control equipment faults with precision, prioritizing safety protocols and operational efficiency.
· Provided comprehensive training sessions to personnel on safety procedures and emergency response protocols, fostering culture of safety consciousness and preparedness.
· Spearheaded safety initiatives to proactively identify and mitigate workplace hazards, contributing to an enhanced overall safety culture within the organization.
· Responsible for technical support to subcontractors, project implementation, testing and commissioning, Diesel generators, 33KV/415V substation, 11KV grid network, handover/takeover, site survey, maintenance and trouble shooting.
· Developed and executed planned preventative maintenance plans (PPM) utilizing CMMS software, integrating safety improvements to enhance equipment reliability and minimize downtime.
· Coordinated inventory and spare parts management strategies using CMMS tools, optimizing resources and reducing costs while ensuring uninterrupted operations.
• Maintain and oversee HVAC, plumbing, and mechanical systems for facility functionality and safety.
• Identify and implement efficiency improvements in mechanical systems to reduce energy usage.
• Diagnose and resolve malfunctions in mechanical systems promptly and efficiently.
• Ensure compliance with safety and environmental regulations for all site.
• Manage projects involving installation, upgrades, or renovations of Telecommunication.
• Maintain detailed records and reports for maintenance schedules and system modifications.
• Ensured installations consistently met design specifications.
• Streamlined maintenance procedures, reducing downtime.
• Improved client communication and trust by delivering comprehensive site reports.
Risk Assessment & Management
Regulatory Compliance (NIST, ISO 27001, GDPR)
Security Policy Development
Incident Response & Management
Cross-Functional Collaboration
Security Awareness Training
Cloud Security
Stakeholder Management
Cyber security Essentials implementation
Microsoft Office (Word, Excel, PowerPoint)
Vulnerability Management: Assessment, Patching, Risk Mitigation
Excellent analytical, problem-solving, and communication skills
Security+, CompTIA
OneTrust Certified GRC Professional
Tech Risk Compliance Professional
Introduction to Cyber security Cisco
CISSP® - Certified Information Systems Security Professional Simple Learn (Training)
CGRC - Governance, Risk And Compliance Certification Udemy®
GDPR Stage One & Two careskills learning
Introduction to GDPR by Pembroke Privacy
Completed the ISC2 Certified in Cyber security course