Anchi Amana
GRC Analyst | Third Party Risk Management | Vulnerability Analyst | Risk Analyst | Compliance Analyst | Cybersecurity Engineer | IAM Engineer
- Role
- Grc Analyst Third Party Risk Management at bp
- Location
- Houston, TX, US
- LinkedIn followers
- 500 followers
About Anchi Amana
I have developed and implemented robust information security programs, specializing in Supplier Risk Management, Disaster Recovery, Business Continuity, Crisis Management, Product Security, and the Software Development Life Cycle. I am proficient in NIST CSF, RMF, SOC, ISO 27001, and GDPR and other authoritative sources, managing audit engagements for frameworks like HITRUST, SOC 2, GDPR, and HIPAA. As a proven GRC Analyst. Proficient in assessing internal/external security vulnerabilities of information systems across multiple business functions. In my role as a Vulnerability Management professional, I have utilized a range of industry-standard tools to fulfill various responsibilities. I enhance security posture, governance, and compliance through strategic risk management and robust policy development. My expertise spans across Azure, GCP, AWS complemented by strong leadership and communication skills. I have achieved significant improvements in data protection and recovery processes, ensuring the confidentiality, integrity, and availability of information systems and data.
Experience
Grc Analyst Third Party Risk Management
Apr 2023 — Present · Houston, TX, US
Respond to security assessments, questionnaires, and audits from clients and third-party business partners in a timely manner. Document and perform assessments as needed.• Lead in the creation and maintenance of security policies, standards, processes, guidelines, and support documentation. Excellent technical writing skills for policies, standards, and communications.• Lead, evaluate, and support processes to ensure IT systems meet the organization\'s cybersecurity and risk requirements, ensuring appropriate treatment of risk, compliance, and assurance.• Serve as a subject matter expert for Information Security consulting to technical and non-technical management and staff.• Manage and support the Third-Party Security Vendor Risk Management program and lifecycle, including managing the exception request process.• Lead the Security Awareness program, developing roadmaps, measuring, and evaluating cyber training/education courses based on instructional needs.• Manage and support GRC technology platforms, conducting evaluations to ensure compliance with published standards.• Conduct enterprise-wide, ongoing risk analysis with Security, Internal Audit, and Compliance Teams. Assess and validate the organization\'s Information Security Program through audits, assessments, and continuous monitoring.• Document and maintain appropriate security control mappings to relevant regulatory compliance and applicable industry frameworks and standards.• Identify and report on information security control deficiencies, working with stakeholders to prioritize and remediate findings.• Fully engaged in change and project management meetings, leveraging strong knowledge of security administration, role-based security controls, vulnerability assessment, and forensic investigation tools.
Education
University of Yaounde
Bachelor's degree
2009 — 2012
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.