Desire Oduma
GRC Analyst | Passionate About DevSecOps | Bridging Compliance & Automation | Terraform • Kubernetes • CI/CD • Security Scanning | CRISC, CCSK, AWS, AZURE Certified
- Role
- Senior IT Security Compliance Analyst at Spirit Airlines
- Location
- Houston, TX, US
- LinkedIn followers
- 500 followers
About Desire Oduma
I\'m a security compliance professional with a strong GRC foundation and a growing passion for DevSecOps. With experience in frameworks like NIST, ISO 27001, SOC 2, and SOX, I\'ve led audit readiness, policy design, and risk assessments. Now, I\'m expanding into automation building EKS clusters with Terraform, securing pipelines with GitHub Actions, and scanning for vulnerabilities with tools like Dependency-Check and SonarQube.I believe security should be built in, not bolted on. That’s why I’m diving deeper into IaC, CI/CD, container security, and open-source tooling to bridge governance with engineering. Recent Projects:Provisioned a 3-tier app with Terraform (VPC, EKS, RDS, S3)Built a secure Jenkins CI/CD pipeline with automated scansIntegrated vulnerability scanning in GitHub Actions workflowWhether it\'s implementing ISO 27001 controls or securing a Kubernetes deployment, I bring a blend of policy expertise and hands-on DevSecOps practice.Let’s connect if you’re building secure cloud environments, championing secure-by-design, or looking to bring more GRC talent into engineering.
Experience
Senior IT Security Compliance Analyst
Sep 2024 — Present
Developed automated evidence collectors for audit artifacts: access reviews, change logs, secrets rotation, SBOMs.• Embedded GRC controls into infrastructure code—policy-as-code, RBAC, encrypted state, and audit trails.• Integrated security automation and compliance enforcement into pipeline/tools using Terraform, EKS, Jenkins, and AWS.• Conducted user access reviews across multiple platforms, ensuring alignment with regulatory controls such as SOX and PCI, and delivered actionable compliance reports.• Coordinated internal and external SOX/PCI audits by acting as a liaison between auditors and IT, streamlining evidence collection and responses to findings.• Developed and maintained security policies and procedures, ensuring compliance with information security standards and regulatory requirements.• Led risk assessments for IT assets and third-party entities, producing detailed remediation plans and metrics to mitigate identified risks. Procedures.• Managed and tracked the timely remediation of audit findings, ensuring effective implementation of controls to address identified vulnerabilities.
Education
Purdue University Fort Wayne
Bachelor's degree, Information Technology
River state university of science and technology
Bachelor's degree, Business Management
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.