- Lead PCI DSS audits and support IT SOX control testing.
- Develop and maintain data inventory and data flow diagrams.
- Map and implement controls across frameworks like NIST CSF.
- Orchestrate quarterly and semi-annual user access reviews.
- Monitor provisioning and deprovisioning processes.
- Maintain a year-round Security Awareness Training program.
- Execute phishing simulations and analyze fail rates.
- Execute the Third-Party Risk Management program.
- Maintain and update the corporate risk register.
- Deploy AI tools to scale the GRC program and automate reporting.
Artificial IntelligenceRisk Management