Nestor F
Vendor Risk Analyst @Vanta
Signup · Get unlimited contacts
WORK HISTORY
Vendor Risk Analyst @Vanta
US
Lead third-party risk assessments aligned with SOC 2, ISO 27001/27002, PCI DSS, and GDPR frameworks, collaborating with procurement, business, and legal teams to ensure contracts meet security and privacy requirements, resulting in a 95% audit compliance rate.Manage third-party assessments of 20+ cloud service providers, validating SOC 2 Type II reports and encryption practices, ensuring 100% contract compliance and improving cloud vendor risk oversight.Leverage AI and machine learning capabilities within the GRC platform to analyze historical vendor risk data, predict vendor risk scores, and proactively prioritize high-risk vendors, increasing risk identification accuracy by 20% and improving overall assessment efficiency.Integrate NIST AI RMF, ISO 42001, and EU AI Act into third-party risk workflows to enhance AI/ML vendor compliance.Implement continuous monitoring frameworks using risk registers, dashboards, and metrics to proactively detect vendor vulnerabilities, reducing critical exposure by 25%.Develop and maintain dynamic risk reports and interactive dashboards, reducing incident response times by 15% and providing executive leadership with clear visibility into risk status and mitigation progress.Conduct periodic vendor assessments to ensure security, confidentiality, integrity, availability, and privacy controls are consistently upheld, leading to a 30% improvement in vendor mitigation outcomes.Deliver quarterly training sessions for over 100 cross-functional staff members, boosting organizational awareness of third-party risk management best practices by 40%.Align security risk management efforts with organizational business goals, reducing operational risk exposure by 20% and driving risk treatment plans that resulted in a 25% reduction in compliance gaps.Partner directly with vendors to develop effective mitigation strategies, strengthening contractual and regulatory adherence by 30%.
EDUCATION
University of Maryland Global Campus
Master's degree (In Progress), cyersecurity and technology
University of Maryland Global Campus
Bachelor's degree, cyersecurity and technology
ABOUT NESTOR F
As a results-driven Third-Party Risk Analyst with 8 years of experience, I specialize in assessing, managing, and mitigating risks associated with vendors, cloud service providers, and critical third parties. My expertise spans conducting comprehensive risk assessments, vendor due diligence, vulnerability management, and leveraging AI-driven risk profiling models to enhance early detection and risk prioritization.I have extensive experience ensuring compliance with regulatory frameworks and industry standards, including HITRUST, SOC 1/2/3, ISO 27001/27002, SOX, PCI DSS, HIPAA, CCPA, NIST AI RMF, ISO 42001, and GDPR. Leveraging advanced GRC platforms such as Drata, Vanta, OneTrust, RSA Archer, ServiceNow, and JIRA, I deliver measurable improvements in operational security, compliance tracking, and vendor risk reporting.With a passion for integrating AI and machine learning into third-party risk management, I proactively analyze historical vendor data to forecast potential risks and drive strategic risk mitigation efforts. I am committed to strengthening organizational resilience by fostering collaboration across cross-functional teams, presenting risk insights to leadership, and continuously refining vendor risk management programs.Let’s connect to discuss how I can help your organization advance its risk management, compliance, and cloud security initiatives through innovative, data-driven solutions.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.