GRC Analyst
I am an IT Governance, Risk & Compliance (GRC) and IT Audit professional with 6 years of experience supporting enterprise governance, technology risk management, regulatory compliance, IT General Controls (ITGC), information security controls, and audit readiness across financial services, healthcare, and consulting environments. My experience includes IT risk assessments, control testing, audit evidence collection and validation, logical access reviews, change management controls, policy and procedure management, compliance monitoring, gap analysis, remediation tracking, risk registers, and governance reporting. I have experience supporting compliance and control environments aligned with PCI DSS, SOX, ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, HIPAA, and enterprise information security requirements. Core areas of expertise include: • IT Governance & GRC • IT Audit & ITGC Testing • Technology Risk Assessments • Risk & Control Assessments • Audit Readiness & Evidence Management • Logical Access & IAM Controls • Change Management Controls • PCI DSS & SOX Compliance • ISO/IEC 27001 & NIST CSF • Policy & Procedure Management • Gap Analysis & Remediation Tracking • Vulnerability & Patch Management • Governance Reporting & Risk Registers I work collaboratively with technology, cybersecurity, infrastructure, audit, compliance, and business stakeholders to identify control gaps, strengthen governance processes, improve audit readiness, and reduce technology risk. Currently pursuing CISA, CISM, and ISO/IEC 27001 Lead Auditor certifications.
Member Since
August 19, 2026
Last Active
7 days ago