Jane McGraw
Cyber Security Versatile Leader Insightful Strategist Client Focused Sales @Open to New Opportunities (#ONO)
Signup · Get unlimited contacts
WORK HISTORY
Cyber Security Versatile Leader Insightful Strategist Client Focused Sales @Open to New Opportunities (#ONO)
EDUCATION
Saint Petersburg College
BAS Management and Organizational Leadership, Entrepreneurship/Entrepreneurial Studies
SKILLS
ABOUT JANE MCGRAW
With over 20 years as a Cybersecurity Professional in Technology Risk Management, Cybersecurity, Regulatory Compliance (GRC), and Third-Party Risk Management (TPRM)• Vendor & Stakeholder Engagement: Work with third-party vendors, IT teams, and executives to align security strategies with business objectives• Develop and implement third-party risk management framework, policies, and procedures.• Conducted due diligence and risk assessments of vendors and partners, evaluating cybersecurity, financial, legal, operational, and compliance risks.• Monitor vendor performance and risk exposure through ongoing assessments, audits, and periodic reviews.• Collaborate with internal teams (Legal, Compliance, IT Security, Procurement) to ensure third-party contracts include appropriate risk mitigation measures.• Technology Risk and Controls: Design, implement, and evaluate IT controls to ensure compliance with regulatory frameworks (e.g, NIST, ISO 27001, SOC 2, GLBA, GDPR).• Monitor and test IT general controls (ITGCs) related to access management, change management, data protection, and system security.• Conduct periodic audits, control reviews, and remediation tracking.• Current on relevant regulations, industry standards, and best practices (e.g, GDPR, ISO 27001, NIST, SOC 2 Type I and II).• Ensured compliance with company policies and regulatory requirements related to third-party risk.• Implemented and maintained cybersecurity frameworks (NIST, ISO 27001, CIS, etc.).• Cyber Risk Management: Develop and implement risk management frameworks, ensuring compliance with industry standards (ISO 27001, NIST, GDPR, HIPAA, CMMC, SOC 2 etc.).• Conduct risk assessments, including control testing, gap analysis, and impact evaluations.• Security Assessment & Audits: Conduct security assessments, penetration tests, and risk analyses to identify vulnerabilities and recommend mitigation strategies.• Compliance & Regulatory Guidance: Ensure organizations adhere to legal, regulatory, and industry cybersecurity standards.• Security Awareness & Training: Educate employees on cybersecurity best practices,• Recommend process enhancements to improve efficiency and effectiveness,• Current knowledge of emerging risks, new technologies, and evolving compliance requirements.• Platform experience with Archer, OneTrust, ProcessUnity, Veeva Vault, AWS, Azure DevOps (ADO), Jira, Service Now
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.