Governance Risk and Compliance (GRC) Analyst
- Produced a risk register and audit-ready deliverables across policy, controls, vendor risks, incident response and SOC 2 readiness.
- Defined SOC 2 audit scope across six architecture layers, built an asset inventory and designed four-tier Data Classification Standard (Public, Internal, Confidential, Restricted).
- Developed Information Security Policy with 11 testable requirements and Vendor Risk Management Policy with 9 requirements, ensuring clarity for auditor testing through precise 'must' language.
- Built a control library and mapped to SOC 2 crosswalk, produced TOD/TOE workpapers, and completed a POA&M tracker with severity ratings.
- Executed vendor DPA as part of retroactive vendor formalisation/onboarding, closing confirmed GDPR compliance gap.
- Wrote an Incident Response Plan with three severity levels, named roles, and pre-approved 72-hour GDPR notification templates.
- Facilitated tabletop exercise simulating exfiltration of 1,247 health records, enhancing incident response preparedness.
- Delivered SOC 2 readiness memo evaluating programme areas; produced 90-day post-observation plan addressing fieldwork support, management responses, and board presentation.
- Tiered all vendors as Critical/High/Medium, mapped the AWS SOC 2 CUECs to existing controls and built a customer questionnaire response library.
- Classified all vendors as subprocessors/subservice organisations, identified missing vendor DPA despite processing active Special category data - Health Data.
- Built Policy Exception Register, compensating controls, named approvers, and documented two active exceptions.
- Completed a structured GRC engagement for TechFlow Solutions, a cloud analytics company processing health, financial and customer data for 150 regulated clients.
- Provided cloud analytics services to process health, financial, and customer data for 150 regulated clients.
- Mentored junior analysts, providing guidance and support to foster professional development.
