Elizabeth A.
Cybersecurity GRC Engineer | ISO 27001, SOC 2, SOX Expert | Driving Enterprise Risk Strategy, Third-Party Security, & Audit Excellence
- Role
- Risk and Compliance Analyst at Morgan Stanley
- Location
- Dallas-Fort Worth, TX, US
- LinkedIn followers
- 500 followers
About Elizabeth A.
Accomplished GRC Analyst with 5+ years of experience implementing and optimizing…
Experience
Risk and Compliance Analyst
Aug 2023 — Present
Supported enterprise-wide risk and compliance initiatives by aligning internal policies with industry standards, including NIST CSF and ISO/IEC 27001.• Conducted over 50 control assessments annually using Archer GRC, enhancing audit readiness and reducing repeat findings year over year.• Built and maintained a centralized Risk Register and implemented a FAIR-based scoring methodology to prioritize enterprise-level risks.• Participated in the development of data governance policies aligned with GDPR and CCPA, improving regulatory posture and reducing compliance gaps.• Coordinated quarterly SOX ITGC testing activities including documentation review, walkthroughs, evidence collection, and remediation follow-ups with control owners.• Collaborated with Procurement and Vendor Risk teams to embed cybersecurity requirements into onboarding workflows, resulting in a 30% reduction in vendor onboarding time.• Designed compliance dashboards and real-time risk metrics within ServiceNow GRC, improving risk visibility for key stakeholders and leadership.• Contributed to annual Business Impact Analysis (BIA) across 45+ business applications to define RTOs and RPOs and inform recovery strategies.• Facilitated ISO 27001 audit readiness by preparing documentation, tracking evidence, and resolving findings, leading to successful certification without major issues.• Coordinated phishing simulation programs with awareness vendors, helping to increase user detection rates by 60% and reduce click-through rates.• Participated in third-party risk reviews and vendor assessments using AICPA Trust Criteria and SIG Lite, supporting contract reviews and renewal decisions.• Worked cross-functionally with Legal and Privacy teams to draft and review Data Processing Agreements (DPAs) and security contract terms.• Monitored regulatory changes from the SEC and FTC, summarizing key impacts and sharing with leadership to align risk strategy with new guidance.
Education
University of Ilorin (Unilorin)
Bachelor's degree, Computer Science
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.