Jane McGraw
Associate Principal - Cybersecurity
- Role
- Cyber Security Versatile Leader Insightful Strategist Client Focused Sales at Open to New Opportunities (#ONO)
- Location
- Cincinnati, OH, US
- LinkedIn followers
- 500 followers
About Jane McGraw
With over 20 years as a Cybersecurity Professional in Technology Risk Management, Cybersecurity, Regulatory Compliance (GRC), and Third-Party Risk Management (TPRM)• Vendor & Stakeholder Engagement: Work with third-party vendors, IT teams, and executives to align security strategies with business objectives• Develop and implement third-party risk management framework, policies, and procedures.• Conducted due diligence and risk assessments of vendors and partners, evaluating cybersecurity, financial, legal, operational, and compliance risks.• Monitor vendor performance and risk exposure through ongoing assessments, audits, and periodic reviews.• Collaborate with internal teams (Legal, Compliance, IT Security, Procurement) to ensure third-party contracts include appropriate risk mitigation measures.• Technology Risk and Controls: Design, implement, and evaluate IT controls to ensure compliance with regulatory frameworks (e.g, NIST, ISO 27001, SOC 2, GLBA, GDPR).• Monitor and test IT general controls (ITGCs) related to access management, change management, data protection, and system security.• Conduct periodic audits, control reviews, and remediation tracking.• Current on relevant regulations, industry standards, and best practices (e.g, GDPR, ISO 27001, NIST, SOC 2 Type I and II).• Ensured compliance with company policies and regulatory requirements related to third-party risk.• Implemented and maintained cybersecurity frameworks (NIST, ISO 27001, CIS, etc.).• Cyber Risk Management: Develop and implement risk management frameworks, ensuring compliance with industry standards (ISO 27001, NIST, GDPR, HIPAA, CMMC, SOC 2 etc.).• Conduct risk assessments, including control testing, gap analysis, and impact evaluations.• Security Assessment & Audits: Conduct security assessments, penetration tests, and risk analyses to identify vulnerabilities and recommend mitigation strategies.• Compliance & Regulatory Guidance: Ensure organizations adhere to legal, regulatory, and industry cybersecurity standards.• Security Awareness & Training: Educate employees on cybersecurity best practices,• Recommend process enhancements to improve efficiency and effectiveness,• Current knowledge of emerging risks, new technologies, and evolving compliance requirements.• Platform experience with Archer, OneTrust, ProcessUnity, Veeva Vault, AWS, Azure DevOps (ADO), Jira, Service Now
Experience
Cyber Security Versatile Leader Insightful Strategist Client Focused Sales
Open to New Opportunities (#ONO)
Jan 2020 — Present
Education
Saint Petersburg College
BAS Management and Organizational Leadership, Entrepreneurship/Entrepreneurial Studies
2012 — 2016
Skills
- Governance
- Compliance
- Needs Assessment
- Hipaa
- Team Building
- Management Consulting
- Customer Engagement
- Data Protection
- Compliance Management
- Information Security
- Security
- Nist 800-53
- Business Process
- Trusted Advisor
- Iso 27001
- Program Management
- Risk Assessment
- Business Intelligence
- Cissp
- Disaster Recovery
- Risk Mitigation
- Privacy
- Policy
- Risk Management
- Auditing
- Practice Management
- Cobit
- Cloud Computing
- Business Process Design
- Virtualization Security
- Glba
- Strategic Planning
- Enterprise Risk Management
- Security Awareness
- IT Governance
- Process Improvement
- Vendor Management
- IT Strategy
- Financial Services
- Itil
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.