Romaric M
GRC Analyst | IT Auditing, Compliance | Third-Party Risk | NIST CSF | HITTRUST | PCI-DSS | HIPAA | SOC 2 | ITGC/SOX
- Role
- Information Security Governance, Risk, and Compliance Analyst at eHealth, Inc.
- Location
- Dallas-Fort Worth, TX, US
- LinkedIn followers
- 500 followers
About Romaric M
Cybersecurity & GRC professional with a strong focus on IT Audit, Compliance, and Risk Management. Passionate about building secure, scalable systems aligned with regulatory frameworks such as NIST, HITRUST, PCI-DSS, HIPAA, ISO 27001, and SOC 2. I specialize in assessing and strengthening security postures through effective control implementation, third-party risk assessments, and continuous compliance monitoring. Known for being detail-oriented, forward-thinking, and highly collaborative, I bring deep knowledge of IT General Controls (ITGC), SOX compliance, and security architecture. I enjoy working with cross-functional teams to develop security policies, streamline audit processes, and ensure alignment with industry best practices. I’m currently focused on leveraging GRC tools and frameworks to drive effective governance, risk mitigation, and audit readiness across complex enterprise environments.
Experience
Information Security Governance, Risk, and Compliance Analyst
Mar 2021 — Present · US
Lead day-to-day IT compliance, data governance, and internal/external audit activities. Perform security and compliance assessments on new/existing systems, processes, and technology. Analyze information risks across the organization, influencing effective management for legal and regulatory compliance. Collaborate with business units to identify and implement appropriate controls for information risk management.Coordinate audits including SOC 2, PCI-DSS, HIPAA, and ISO, overseeing security control assessments across enterprise systems and assets. Conduct periodic gap assessments to validate ongoing compliance. Utilize GRC tools to manage assessment results, ensuring efficient tracking, follow-up on remediation, and compilation of risk data.Demonstrate excellent organizational, facilitation, presentation, and project management skills.Support the 3rd Party Security Vendor Risk Management program, conducting risk assessments for third parties and managing responses to security assessments, questionnaires, and audits.Oversee risk metrics, report data, and maintain documentation within RSA Archer, ensuring comprehensive security for confidential information, assets, and intellectual property.Research and develop detailed network security policies to align with HIPAA security regulations, ensuring compliance.Conduct disaster recovery planning, schedule testing, and play a key role in business continuity planning for IT and emergency notification services.Utilize JIRA to assign evidence requests, facilitate communication, guide stakeholders, and review submitted evidence.
Education
University of Buea
Law
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.