Kien Madong

IT Auditor/Third Party Risk Analyst at PwC

Role
IT Auditor Third Party Risk Analyst at PwC
Location
Columbia, MD, US
LinkedIn followers
500 followers
Information TechnologyView LinkedIn profile

About Kien Madong

Third party vendor risk and GRC analyst with over 5 years of experience in risk management framework, security life cycle, vulnerability scanning, NESSUS, audit compliance, and POAM management, while committed to protecting the confidentiality, integrity, and availability of the information system. In-depth knowledge of Sarbanes-Oxley Act (SOX), SAS 70/SSAE 18 Attestation Engagements, PCI DSS, COBIT, COSO, FedRAMP Baseline Security Controls, Privacy and Security rule (HIPAA), Data Center, Disaster Recovering Plan, NIST 800 series, HITRUST CSF, ISO 27001. Experience in TPRM process optimization, vendor security reviews, and risk mitigation. Good knowledge of governance risk and controls implementation related to various industry standards/compliance. Excellent abilities and experience in evaluating and implementing internal controls procedures to ensure efficiency and risk mitigation.

Experience

  1. IT Auditor Third Party Risk Analyst

    PwC

    Jan 2019 — Present · New York, NY, US

    Assess vendors SIG responses and supporting documentation to validate vendor appropriate implementation of information security controls-Facilitate and document kick-off and risk review meetings between vendor owners, subject matter experts, and stakeholders to present potential vendors and discuss or issues-Analyze vendor evidences such as SOC, vulnerability scans and penetration test reports to identify gaps or exceptions-Monitor, and tracked TPRM life-cycle activities… Show more -Assess vendors SIG responses and supporting documentation to validate vendor appropriate implementation of information security controls-Facilitate and document kick-off and risk review meetings between vendor owners, subject matter experts, and stakeholders to present potential vendors and discuss or issues-Analyze vendor evidences such as SOC, vulnerability scans and penetration test reports to identify gaps or exceptions-Monitor, and tracked TPRM life-cycle activities (identify, due diligence, risk assessment contract negotiation, ongoing monitoring)-Create and analyze data, leveraging Excel, SQL and Power BI to identify the areas that conflict with regulations and spot the trends that negatively impact the customer journey-Perform periodic vendor risk assessment to make sure vendor controls are properly implemented to ensure confidentiality, integrity, availability, and privacy throughout the contract-Assist with the implementation and operation of Governance Risk and Compliance (GRC) tooling to further improve and automate our risk management processes-Analyze vendors processes to determine deficiencies within their controls that could violate applicable law, regulation, framework or internal policies and procedures-Assist in the development, review, implementation and maintenance of policies, procedures, standards and guidelines in accordance with applicable regulations including ISO 27001, NIST, HIPAA and PCI DSS-Help support various parts of the company to adopt a common risk management process, this may include joining other Security GRC projects (e.g, Third Party Risk Management, M&A Due Diligence, Risk & Compliance Assessments) or other projects adjacent to our Security GRC program objectives-Provides guidance in the execution of Risk Control Self-Assessments (RCSA\'s), translates control deficiencies into action plans and provides recommendations to enhance governance practices in alignment with risk and compliance frameworks.

Education

  • University of Maryland Global Campus

    Master's degree

    2015 — 2018

  • University of Maryland Global Campus

    Bachelor's degree

    2012 — 2015

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Kien Madong — IT Auditor Third Party Risk Analyst at PwC in Columbia, MD, US | Unifers