Arreko Gibbs
Senior Cybersecurity Engineer @LexisNexis Risk Solutions
Signup · Get unlimited contacts
WORK HISTORY
Senior Cybersecurity Engineer @LexisNexis Risk Solutions
US
Key Leadership and Strategic Contributions • Led the enterprise Third-Party Risk Management program, completing 145 vendor assessments in 20•••14 Tier A, 31 Tier B), achieving 100% SOC/ISO compliance for all approved vendors.• Reduced third-party risk exposure by 15% through high-quality assessments, control validation, and the rejection of 8 high-risk vendors, preventing material security and operational exposure.• Designed and delivered enterprise governance frameworks, including the LNRS Third-Party Security Standard Assessment SOPs, and Vendor Governance Guidelines used by cross functional teams.• Built and matured the LNRS Risk Management Program, integrating risk scoring, continuous monitoring, and annual review practices aligned with NIST, ISO, and SOC standards.AI, Automation, and Operational Excellence • Drove AI-enabled automation projects using OpenAI, Copilot, Claude, and custom n8n.io workflows that improved high risk vendor detection accuracy by 30% and reduced manual review time by 40%.• Implemented three automation initiatives, resulting in a 5% team productivity gain and $250K in cost savings through optimized vendor with a more consistent risk review process.• Created dashboards and executive level reporting for leadership level decision making and audit readiness.Cross-Functional Leadership and Governance • Partnered with Legal, Sourcing, Privacy, and Procurement (ITAM) to ensure alignment of vendor contracts, data protection requirements, and residual risk acceptance.• Mentored junior analysts and new hires, enhancing team performance and GRC maturity across the group.• Assisted in updating FedRAMP control documentation and revising client SSPs to ensure compliance with NIST RMF/CSF.• Managed all other duties related to vendor governance, risk decisions, and compliance operations.
EDUCATION
Central Michigan University
Bachelor of Applied Science (B.A.Sc.)
Baker College
Master of Information Systems - MSIS, Cloud Security Risk Management and Cybersecurity
Macomb Community College
Associate of Arts and Sciences (A.A.S.)
ABOUT ARREKO GIBBS
I’m a cybersecurity professional with over 10+ years of experience working across governance, risk management, and compliance, with a strong focus on third-party management, security governance, and enterprise risk reduction. My work has spanned highly regulated environments, including media, healthcare, and technology, where I’ve helped organizations strengthen their security posture while still enabling the business to move forward.In my current role at LexisNexis Risk Solutions, I lead key initiatives within the Cyber GRC and Third-Party Risk Management programs. I regularly conduct and oversee complex vendor risk assessments, partner with legal, procurement, privacy, and engineering teams, and help leadership make informed risk decisions based on real data, not assumptions. I’m also part of the AI Steering Committee, where I contribute to conversations and initiatives around AI governance, automation, and risk, drawing on both academic and research and hands-on experience with LLM and automation tools.What drives my work is balance, strong security controls that are practical, defensible, and aligned with business objectives. I care deeply about building security programs that are sustainable, not just compliant on paper, and about mentoring others so teams grow stronger over time. I’ve seen firsthand how effective governance, clear standards, and thoughtful risk management can prevent issues long before they become incidents.I bring experience with frameworks such as NIST CSF-RMF, ISO 27001, SOC 2, FedRAMP, and FAIR, but more importantly, I understand how to apply them in real world environments where tradeoffs exist and decisions matter. Whether I’m working on vendor governance, risk assessment, policy development, or automation, my goal is always the same, reduce risk, improve clarity, and help the organization operate securely and confidently.I’m always open to thoughtful conversations around cybersecurity leadership, GRC strategy, third-party risk, and emerging risks in AI and cloud environments.Security should enable the business, not slow it down, and that’s the approach I bring to every role.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.