Kien Madong
IT Auditor/Third Party Risk Analyst at PwC
- Role
- IT Auditor Third Party Risk Analyst at PwC
- Location
- Columbia, MD, US
- LinkedIn followers
- 500 followers
About Kien Madong
Third party vendor risk and GRC analyst with over 5 years of experience in risk management framework, security life cycle, vulnerability scanning, NESSUS, audit compliance, and POAM management, while committed to protecting the confidentiality, integrity, and availability of the information system. In-depth knowledge of Sarbanes-Oxley Act (SOX), SAS 70/SSAE 18 Attestation Engagements, PCI DSS, COBIT, COSO, FedRAMP Baseline Security Controls, Privacy and Security rule (HIPAA), Data Center, Disaster Recovering Plan, NIST 800 series, HITRUST CSF, ISO 27001. Experience in TPRM process optimization, vendor security reviews, and risk mitigation. Good knowledge of governance risk and controls implementation related to various industry standards/compliance. Excellent abilities and experience in evaluating and implementing internal controls procedures to ensure efficiency and risk mitigation.
Experience
IT Auditor Third Party Risk Analyst
Jan 2019 — Present · New York, NY, US
Assess vendors SIG responses and supporting documentation to validate vendor appropriate implementation of information security controls-Facilitate and document kick-off and risk review meetings between vendor owners, subject matter experts, and stakeholders to present potential vendors and discuss or issues-Analyze vendor evidences such as SOC, vulnerability scans and penetration test reports to identify gaps or exceptions-Monitor, and tracked TPRM life-cycle activities… Show more -Assess vendors SIG responses and supporting documentation to validate vendor appropriate implementation of information security controls-Facilitate and document kick-off and risk review meetings between vendor owners, subject matter experts, and stakeholders to present potential vendors and discuss or issues-Analyze vendor evidences such as SOC, vulnerability scans and penetration test reports to identify gaps or exceptions-Monitor, and tracked TPRM life-cycle activities (identify, due diligence, risk assessment contract negotiation, ongoing monitoring)-Create and analyze data, leveraging Excel, SQL and Power BI to identify the areas that conflict with regulations and spot the trends that negatively impact the customer journey-Perform periodic vendor risk assessment to make sure vendor controls are properly implemented to ensure confidentiality, integrity, availability, and privacy throughout the contract-Assist with the implementation and operation of Governance Risk and Compliance (GRC) tooling to further improve and automate our risk management processes-Analyze vendors processes to determine deficiencies within their controls that could violate applicable law, regulation, framework or internal policies and procedures-Assist in the development, review, implementation and maintenance of policies, procedures, standards and guidelines in accordance with applicable regulations including ISO 27001, NIST, HIPAA and PCI DSS-Help support various parts of the company to adopt a common risk management process, this may include joining other Security GRC projects (e.g, Third Party Risk Management, M&A Due Diligence, Risk & Compliance Assessments) or other projects adjacent to our Security GRC program objectives-Provides guidance in the execution of Risk Control Self-Assessments (RCSA\'s), translates control deficiencies into action plans and provides recommendations to enhance governance practices in alignment with risk and compliance frameworks.
Education
University of Maryland Global Campus
Master's degree
2015 — 2018
University of Maryland Global Campus
Bachelor's degree
2012 — 2015
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.