Desire Oduma

Senior IT Security Compliance Analyst @Spirit Airlines

Houston, TX, US
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Sep 2024 — Present

Senior IT Security Compliance Analyst @Spirit Airlines

View department →

Developed automated evidence collectors for audit artifacts: access reviews, change logs, secrets rotation, SBOMs.• Embedded GRC controls into infrastructure code—policy-as-code, RBAC, encrypted state, and audit trails.• Integrated security automation and compliance enforcement into pipeline/tools using Terraform, EKS, Jenkins, and AWS.• Conducted user access reviews across multiple platforms, ensuring alignment with regulatory controls such as SOX and PCI, and delivered actionable compliance reports.• Coordinated internal and external SOX/PCI audits by acting as a liaison between auditors and IT, streamlining evidence collection and responses to findings.• Developed and maintained security policies and procedures, ensuring compliance with information security standards and regulatory requirements.• Led risk assessments for IT assets and third-party entities, producing detailed remediation plans and metrics to mitigate identified risks. Procedures.• Managed and tracked the timely remediation of audit findings, ensuring effective implementation of controls to address identified vulnerabilities.

EDUCATION

N/A

Purdue University Fort Wayne

Bachelor's degree, Information Technology

N/A

River state university of science and technology

Bachelor's degree, Business Management

ABOUT DESIRE ODUMA

I\'m a security compliance professional with a strong GRC foundation and a growing passion for DevSecOps. With experience in frameworks like NIST, ISO 27001, SOC 2, and SOX, I\'ve led audit readiness, policy design, and risk assessments. Now, I\'m expanding into automation building EKS clusters with Terraform, securing pipelines with GitHub Actions, and scanning for vulnerabilities with tools like Dependency-Check and SonarQube.I believe security should be built in, not bolted on. That’s why I’m diving deeper into IaC, CI/CD, container security, and open-source tooling to bridge governance with engineering. Recent Projects:Provisioned a 3-tier app with Terraform (VPC, EKS, RDS, S3)Built a secure Jenkins CI/CD pipeline with automated scansIntegrated vulnerability scanning in GitHub Actions workflowWhether it\'s implementing ISO 27001 controls or securing a Kubernetes deployment, I bring a blend of policy expertise and hands-on DevSecOps practice.Let’s connect if you’re building secure cloud environments, championing secure-by-design, or looking to bring more GRC talent into engineering.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.