Jules M.

Sr IT Grc Analyst @Varo Bank

Chicago, IL, US
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Sep 2020 — Present

Sr IT Grc Analyst @Varo Bank

View department →

Developed, reviewed, implemented, and maintained comprehensive GRC frameworks, aligning organizational policies with regulatory standards such as ISO 27001, PCI DSS, NIST CSF Controls, and GDPR•Spearheaded internal and external audits for ISO 27001, PCI DSS, and SOC 2 Type II, coordinating audit schedules, collecting necessary evidence, and driving the remediation of audit findings.•Worked with control owners to track and document findings in the risk register and follow up on remediation milestones with evidence. •Created information security documentation and workflows to assist with incident response, audits, and vendor requirements.•Led risk assessments and vulnerability analysis across critical business functions, finding key security gaps and driving risk mitigation strategies.• Managed and monitored compliance activities using GRC tools like RSA Archer and BitSight, tracking audit findings, and remediation plans.•Managed and assessed third-party vendor risks, by conducting due diligence and security assessments using tools like Archer.•Sent out security templates, SIG Lite, and SIG Core prompting the vendor to respond and provide artifacts for review.•Performed documentation review including but not limited to SOC1-2 Reports, ISO 27001, Pentest, Cyber Liability insurance, Policies and Procedures, BCP/DRP, and Architecture diagrams.•Documented all findings and provided recommendations for each finding identified. Also, follow up for those findings to be remediated.•Drafted final Vendor Security report documenting what artifacts were collected and reviewed.•Collaborated with cross-functional teams to integrate risk management processes into business operations.•Created and delivered training programs on governance, risk, and compliance to enhance company-wide awareness.•Developed and reported clear security and compliance documentation for IT and non-IT stakeholders

EDUCATION

N/A

University of Buea

Bachelor's degree

ABOUT JULES M.

I am a results-driven Governance, Risk, and Compliance (GRC) professional with over 7 years of experience in cybersecurity, IT risk management, third-party risk management (TPRM), vulnerability management, and regulatory compliance. Throughout my career, I have built security programs in diverse environments, including finance, healthcare, and technology. My expertise lies in identifying and mitigating cyber risks while designing and implementing security controls, policies, and procedures that safeguard organizational assets and ensure compliance with industry standards. Over the years, I have worked across key areas of governance, risk management, compliance, and third-party/vendor risk. I have led projects involving NIST 800-53/CSF, ISO 27001, PCI-DSS, SOC 2, HIPAA, FedRAMP, HITRUST, CMMC, and GDPR. I know how to prepare organizations for audits, strengthen control environments, and respond to evolving regulatory demands. I also bring hands-on experience with cloud platforms (AWS, Azure, Google Cloud) and GRC tools such as RSA Archer, Vanta, and ServiceNow GRC, which I use to streamline workflows and improve visibility into risks. In my current role as a Sr. GRC Analyst at Varo Bank, I lead GRC initiatives, manage the RSA Archer GRC platform, conduct enterprise risk assessments, and oversee vulnerability management. I also support internal and external audits, Incident response, overseeing change management, vendor onboarding, and client due diligence to ensure compliance with GLBA, PCI-DSS, ISO 27001, and SOC 2 Type II standards. Previously, I served as an IT Risk and Compliance Analyst at BlueCross BlueShield, where I enhanced third-party risk management, supply chain oversight, and compliance programs. I supported the implementation of NIST 800-53 by creating SSP, collecting evidence, developing POA & Ms, conducting vulnerability assessments, and implementing controls. This strengthened my expertise in regulatory compliance, risk assessments, and vulnerability management. I hold a Bachelor’s degree in Computer Science, as well as CISA and CompTIA Security+ certifications, and I am currently pursuing the CISM certification. I am known for my problem-solving skills, attention to detail, collaboration, and strategic thinking. I am dedicated to driving compliance, enhancing security postures, and fostering a culture of risk awareness.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.