Wendy Athanas

AVP, IT Risk and Compliance, Crisc, Cism, Cisa, Cdpse @Sammons Financial Group Companies

Clayton, NC, US
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Jun 2017 — Present

AVP, IT Risk and Compliance, Crisc, Cism, Cisa, Cdpse @Sammons Financial Group Companies

View department →

San Antonio, TX, US

Responsible for the overall IT Risk and Compliance program, including-Developing, implementing, and maintaining IT risk management methodologies -Conducting regular Company information security risk assessments -Working collaboratively with Enterprise Risk Management, Internal Audit, Legal and Compliance to appropriately manage information risk in alignment with established risk, legal and compliance risk tolerances and methodologies -Developing and implementing IT risk and security policies -Monitoring information risks, mitigation and remediation efforts -Understanding and monitoring the regulatory environment, and ensuring compliance with applicable regulations -Working with IT and entire staff to ensure their compliance with IT and risk security policies -Overseeing the Identity and Access Management program -Developing and implementing a security awareness program -Developing and implementing an IT controls framework -Working with IT to assist them selecting appropriate control activities; measuring and monitoring those control activities -Coordinating IT activities in response to Internal Audit requirements -Providing oversight of audit, regulatory and risk management activities across IT functional areas -Coordinating the IT component of both internal and external audits, federal and statement examinations related to information security -Ensuring compliance with Model Audit Rule controls -Providing IT risk consulting -Directing IT Risk and Compliance team activities -Continuously monitoring the risk function, identifying, developing and implementing process improvements

EDUCATION

2006 — 2010

Metropolitan State University of Denver

Technical Communication

2011 — 2011

ISACA

CISM, Certified Information Security Manager

2021 — 2021

ISACA

CRISC, Certified in Risk and Information Systems Control

2020 — 2020

ISACA

CDPSE, Certified Data Privacy Solutions Engineer

2008 — 2008

ISACA

CISA, Certified Information Security Auditor

ABOUT WENDY ATHANAS

AVP, IT Risk Manager with expertise in leading IT professionals to assess and manage security and risk within complex IT environments. Skilled in IT/Business alignment, IT security policy development and implementation, Business Impact Analysis, Risk Assessments, Vendor Risk Assessments, Gap Analysis, Regulatory Compliance and Project Management. Key core qualifications include: Information Risk Management, Vendor Risk Management, Risk Assessments (ISO 27002, NIST Cybersecurity Framework, High-Level Risk Assessments, Detailed Assessments), Disaster Recovery/Business Continuity Planning, Project Management, Process Improvement, Security Policy Development, Regulatory Compliance, IT Management, IT Controls, Gap Analysis and Remediation, Managing Large Budgets ($21M), Strategic Planning, Security Awareness, Security/Risk Maturity Models

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.