Christian Goudjou
Third Party Risk Analyst at Best Buy
- Role
- Risk and Compliances Analyst at FERRAGAMO
- Location
- Silver Spring, MD, US
- LinkedIn followers
- 500 followers
About Christian Goudjou
A dedicated and driven IT security professional with several years of experience in Information Assurance and Governance Risk and Compliance. Experience with industry-based information security and control frameworks such as NIST Risk Management Framework, Security Management & Operations, Vulnerability Scanning, Certification and Accreditation (A&A), NIST 800-53rev4 and NIST SP 800-37 rev 1, NIST 800-18, NIST800-34, NIST 800-60Vol1 & 2, NIST 800-30, NIST 800-137, FIPS 199/200, FISMA, NIST Family of Security Control, POA & M, Incident and Contingency Planning, ISO 27001 & 2,(SOC1 & 2), PCI-DSS, HIPAA, HITRUST, GDPR, SOX, FedRAMP. Experienced with GRC tools and Vulnerability assessment tools. As well as SIEM technologies, IDS/IPS and analyzing log data, network traffic and/or alerts generated by these tools. Knowledgeable in security control assessment, System Development Life Cycle (SDLC), Vulnerability Management using FISMA, and applicable NIST standards. Detailed-oriented, with strong problem solving and organizational skills. Excellent communication skills with the ability to build and lead high-performance teams to drive positive results. Knowledgeable of trends and threats in network and internet security.
Experience
Risk and Compliances Analyst
Feb 2019 — Present · NJ, US
Perform continuous monitoring by updating the A&A documents and run vulnerability scans using tools such as Nessus and Tenable security center to identify vulnerabilities applicable to the system• Evaluate the likelihood that vulnerabilities could be exploited and assess the impact associated with this threat and vulnerabilities• Experience creating Standard Operational Policies (SOP)• Experience researching, and reviewing vulnerabilities reports, working with developers, system admins and engineers to remediates vulnerabilities on scan report and create POA & M.• Experience categorizing a system with the appropriate stakeholders into either high, moderate or low using FIPS 199 and SP 800-60 Vol 1 & 2 as a guide• Conduct self-control assessment to determine the adequacy of management, operational, privacy and technical security controls implemented• Assist System Owners and ISSO in preparing certification and Accreditation packages for IT System, making sure that management, operational and technical security controls adhere to a federal and well-established security requirement authorized by NIST 800- 53R4 to obtain and maintain• Conduct risk management using NIST SP 800-39 and risk assessment using NIST SP 800-30 to identify system threats, vulnerabilities, and impact level• Experience with auditing by acting as a Liaison Analysis by responding to and assisting with audits, assessments.• Prepare recommendation strategies that are made available to system owners, system admins or system engineers to remediate identified vulnerabilities• Analyze and update system security plan (SSP), Risk Assessment (RA), Privacy Impact Assessment (PIA), System Security Test & Evaluation (ST & E), E- Authentication, Contingency Plan (CP) and Plan of Actions & Milestone (POA & M)• Perform Documentation Review• Assisted in SOC 2,ISO Audits by gathering of evidences and answering to security questions• Responding to Request of Proposals
Education
Bowie State University
Business management
Bowie State University
Bachelor of business management
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.