Senior Information Security Compliance Analyst Resume
2.00/5 (Submit Your Rating)
SUMMARY
- A strategic, strong result oriented adaptive, creative and pragmatic cyber security professional enabling the success of others by simplifying the complex, cutting costs, saving time, to deliver impactful services, products and capabilities.
- Professional with 17+ years of work experience in the IT field and specialized in information security and knowledge all IT values chain, cybersecurity, network security and Internet technology. Strong qualified in information security management and working as a security consultant in credit card corporations and in major Confidential performing risk assessment and leading projects related to the information security and certification CISSP.
PROFESSIONAL EXPERIENCE
Confidential
Senior Information Security Compliance Analyst
Responsibilities:
- Responsible for design of information security policies, standards, procedures and continuously improve security aspects of operating processes based in ISO27K, PCI - DSS and NIST.
- Deep understanding and experience developing, documenting, revising, and assessing security controls for certification programs such as SOC 2 Type II, ISO27K, and PCI.DSS.
- Support on security reviews over third party cloud providers for security risks to determine if implemented security and control practices are aligned with the organization and industry best practices including support to Privacy program (GDPR and CCPA);
- Assist for driving efforts to prevent, monitor and respond to information and mitigate risk by analyzing the root cause of issues, impacts to business, and required corrective actions and develop security solutions data breaches and cyber-attacks;
- Identify significant IS threats and vulnerabilities, and define appropriate controls for discovered threats, documenting the business response;
- Perform vendor security assessment activities including evaluation of vendor controls and practices, process enhancements, performing onsite assessments, reviewing independent audit service reports.
Confidential
Information Security Officer
Responsibilities:
- Understand the impact of the compliance requirements on systems and data to determine risk and recommend appropriate mitigation;
- Support the efforts to apply risk management processes in the business-critical projects to identify and track risks, recommend solutions, validate remediation plans and facilitate implementation;
- Deep understanding of network security controls and web security development, following frameworks as OWASP, NIST Cybersecurity and National Cyber Security Centre (NCSC).
- Monitor, evaluate and ensure the resolution of moderately complex security incidents and interactions with the security operations center and security investigations teams;
- Assisting in the classification and protection of data resources by providing guidance on secure and cost-effective implementation of security policies and standards;
- Performed 6 awareness security campaigns in the organization for more than 1500 employees about cybersecurity principles and concepts; Liaise with local and international security teams, and participate in reviews that pertain to compliance with security policies and regulatory security controls; Support security assessment for internal and SaaS applications, Physical assessment and digital solutions (mobile application, IoT, website, and social networking); Assists the businesses in the completion of the security assessments and other IT compliance processes, ensuring that they are completely understood and appropriate controls are embedded in the operation, and remediation of non-compliance with IAPP is documented and addressed;
Confidential
IT Security Risk Lead
Responsibilities:
- IT Risk Management Process, Information Security Risk, Risk Assurance and IT Audit Risk;
- Creating and maintaining risk register for the IT LATAM departments;
- Studying and assessing the appropriate risk response options and risk mitigation;
- Risk assessment with frameworks COBIT, PCI, ISO 27001, 27002, 27005, 2000 and SSAE 16;
- Developing and maintaining KRIs (Key Risk Indicators) for management from IT perspective;
- Providing Monthly KRI Status Reports to management;
- Developing Business Continuity Management (BCP);
- Risk Internal Control Coordination;
- Utilizing the Information Risk Management tool (RSA Archer, Risk Manager and worksheet) to register all identified risks.
