Jane McGraw

Cyber Security Versatile Leader Insightful Strategist Client Focused Sales @Open to New Opportunities (#ONO)

Cincinnati, OH, US
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Jan 2020 — Present

Cyber Security Versatile Leader Insightful Strategist Client Focused Sales @Open to New Opportunities (#ONO)

View department →

EDUCATION

2012 — 2016

Saint Petersburg College

BAS Management and Organizational Leadership, Entrepreneurship/Entrepreneurial Studies

SKILLS

GovernanceComplianceNeeds AssessmentHipaaTeam BuildingManagement ConsultingCustomer EngagementData ProtectionCompliance ManagementInformation SecuritySecurityNist 800-53Business ProcessTrusted AdvisorIso 27001Program ManagementRisk AssessmentBusiness IntelligenceCisspDisaster RecoveryRisk MitigationPrivacyPolicyRisk ManagementAuditingPractice ManagementCobitCloud ComputingBusiness Process DesignVirtualization SecurityGlbaStrategic PlanningEnterprise Risk ManagementSecurity AwarenessIT GovernanceProcess ImprovementVendor ManagementIT StrategyFinancial ServicesItil

ABOUT JANE MCGRAW

With over 20 years as a Cybersecurity Professional in Technology Risk Management, Cybersecurity, Regulatory Compliance (GRC), and Third-Party Risk Management (TPRM)• Vendor & Stakeholder Engagement: Work with third-party vendors, IT teams, and executives to align security strategies with business objectives• Develop and implement third-party risk management framework, policies, and procedures.• Conducted due diligence and risk assessments of vendors and partners, evaluating cybersecurity, financial, legal, operational, and compliance risks.• Monitor vendor performance and risk exposure through ongoing assessments, audits, and periodic reviews.• Collaborate with internal teams (Legal, Compliance, IT Security, Procurement) to ensure third-party contracts include appropriate risk mitigation measures.• Technology Risk and Controls: Design, implement, and evaluate IT controls to ensure compliance with regulatory frameworks (e.g, NIST, ISO 27001, SOC 2, GLBA, GDPR).• Monitor and test IT general controls (ITGCs) related to access management, change management, data protection, and system security.• Conduct periodic audits, control reviews, and remediation tracking.• Current on relevant regulations, industry standards, and best practices (e.g, GDPR, ISO 27001, NIST, SOC 2 Type I and II).• Ensured compliance with company policies and regulatory requirements related to third-party risk.• Implemented and maintained cybersecurity frameworks (NIST, ISO 27001, CIS, etc.).• Cyber Risk Management: Develop and implement risk management frameworks, ensuring compliance with industry standards (ISO 27001, NIST, GDPR, HIPAA, CMMC, SOC 2 etc.).• Conduct risk assessments, including control testing, gap analysis, and impact evaluations.• Security Assessment & Audits: Conduct security assessments, penetration tests, and risk analyses to identify vulnerabilities and recommend mitigation strategies.• Compliance & Regulatory Guidance: Ensure organizations adhere to legal, regulatory, and industry cybersecurity standards.• Security Awareness & Training: Educate employees on cybersecurity best practices,• Recommend process enhancements to improve efficiency and effectiveness,• Current knowledge of emerging risks, new technologies, and evolving compliance requirements.• Platform experience with Archer, OneTrust, ProcessUnity, Veeva Vault, AWS, Azure DevOps (ADO), Jira, Service Now

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.