Summary
Work History
Education
Skills
Referees
Timeline
Generic

Selina Ndungu

NP20,Newport

Summary

MSc Cybersecurity, Risk and Resilience graduate with hands-on GRC portfolio experience spanning SOC 2 readiness, ISO 27001-aligned policy frameworks, vendor risk management, incident response planning, access control reviews, phishing simulation design, and compliance auditing. Published researcher and ICCS 2025 conference presenter on cybersecurity governance and risk management for SMEs.

Work History

Governance Risk and Compliance (GRC) Analyst

TechFlow Solutions
Newport, Gwent
02.2026 - 08.2026
  • Produced a risk register and audit-ready deliverables across policy, controls, vendor risks, incident response and SOC 2 readiness.
  • Defined SOC 2 audit scope across six architecture layers, built an asset inventory and designed four-tier Data Classification Standard (Public, Internal, Confidential, Restricted).
  • Developed Information Security Policy with 11 testable requirements and Vendor Risk Management Policy with 9 requirements, ensuring clarity for auditor testing through precise 'must' language.
  • Built a control library and mapped to SOC 2 crosswalk, produced TOD/TOE workpapers, and completed a POA&M tracker with severity ratings.
  • Executed vendor DPA as part of retroactive vendor formalisation/onboarding, closing confirmed GDPR compliance gap.
  • Wrote an Incident Response Plan with three severity levels, named roles, and pre-approved 72-hour GDPR notification templates.
  • Facilitated tabletop exercise simulating exfiltration of 1,247 health records, enhancing incident response preparedness.
  • Delivered SOC 2 readiness memo evaluating programme areas; produced 90-day post-observation plan addressing fieldwork support, management responses, and board presentation.
  • Tiered all vendors as Critical/High/Medium, mapped the AWS SOC 2 CUECs to existing controls and built a customer questionnaire response library.
  • Classified all vendors as subprocessors/subservice organisations, identified missing vendor DPA despite processing active Special category data - Health Data.
  • Built Policy Exception Register, compensating controls, named approvers, and documented two active exceptions.
  • Completed a structured GRC engagement for TechFlow Solutions, a cloud analytics company processing health, financial and customer data for 150 regulated clients.
  • Provided cloud analytics services to process health, financial, and customer data for 150 regulated clients.
  • Mentored junior analysts, providing guidance and support to foster professional development.

Education

GRC Portfolio Builder - Course -

The Tech Academy
Maryland
08-2026

BSc Forensic Science - Relevant Coursework, Computer Programming

Kenyatta University
Nairobi, Kenya
04-2013

MSc Cybersecurity, Risk & Resilience - Security Management & Incident Response, Leadership and Transformational Changes In a Digital Era, Networking Technologies, Legislation, Risk & Governance in Cybersecurity, Crisis & Operational Resilience, Protecting Critical & National Infrastructure, Dissertation: Risk Management based on Penetration Testing & Attack Surface Analysis — cybersecurity dashboard deliverable

University of South Wales
Newport, UK
01-2026

Skills

  • SOC 2 TSC
  • GDPR
  • NIST CSF
  • ISO 27001
  • PCI-DSS
  • NIST SP 800-30
  • ISO 27005
  • Risk register construction
  • Policy & standard writing
  • Control library development
  • Vendor risk management
  • POA&M & IR plan management
  • Compliance auditing
  • Audit evidence packaging
  • Access control & onboarding reviews
  • Phishing simulation design

Referees

Available upon request

Timeline

Governance Risk and Compliance (GRC) Analyst

TechFlow Solutions
02.2026 - 08.2026

GRC Portfolio Builder - Course -

The Tech Academy

BSc Forensic Science - Relevant Coursework, Computer Programming

Kenyatta University

MSc Cybersecurity, Risk & Resilience - Security Management & Incident Response, Leadership and Transformational Changes In a Digital Era, Networking Technologies, Legislation, Risk & Governance in Cybersecurity, Crisis & Operational Resilience, Protecting Critical & National Infrastructure, Dissertation: Risk Management based on Penetration Testing & Attack Surface Analysis — cybersecurity dashboard deliverable

University of South Wales
Selina Ndungu