Zahid Khawaja

Information Security Professional | GRC | FedRAMP | SOC2 | HITRUST | PCI DSS | Risk Assessment | Vulnerability Management | NIST 800 18/30/37/39/53

Role
Grc Analyst at Get Well
Location
Houston, TX, US
LinkedIn followers
500 followers
Finance & AccountingView LinkedIn profile

About Zahid Khawaja

I’m a Senior IT Security Advisor at Get Well with more than a decade of experience helping organizations strengthen their cybersecurity, privacy, and compliance programs. Over the years, I’ve guided teams through the complexities of FedRAMP, GDPR, CCPA, HIPAA, SOX, GLBA, PCI-DSS, and frameworks like NIST 800-53, ISO 27001, COBIT, and HITRUST.My work goes beyond checkboxes—I’ve led efforts in third-party risk assessments, M&A due diligence, vulnerability management, and data protection initiatives that directly reduce risk and build trust.I’m also hands-on with the tools that make this work possible, from GRC platforms (OneTrust, ProcessUnity, Drata) to security and cloud solutions (BeyondTrust, SailPoint, ForcePoint, Boldon James, AWS, Azure, Qualys).At the core, my mission is simple: to help organizations and their partners stay secure, stay compliant, and stay confident in an ever-changing threat landscape.

Experience

  1. Grc Analyst

    Get Well

    Aug 2022 — Present · Bethesda, MD, US

    Managed FedRAMP certification efforts from initial assessment through achieving Authority to Operate (ATO), coordinating cross-functional teams, collaborating with the 3PAO and sponsoring agency, preparing and reviewing the System Security Plan (SSP) and appendices, managing POA & Ms, and leading the Rev4 to Rev5 transition.• Led annual third-party risk assessments, including web, mobile, infrastructure penetration testing, and red teaming exercises, overseeing risk identification, prioritization, remediation validation, and reporting to executive leadership.• Managed SOC 2 Type II attestation and HITRUST r2 (interim and full) audits by preparing and validating control evidence, coordinating with auditors and internal stakeholders, and driving remediation and corrective action initiatives.• Managed internal user account reviews, AWS security group assessments, network architecture reviews, boundary diagram updates, SSP and appendices reviews, configuration baseline assessments, vulnerability scan analysis, and audit log reviews, ensuring compliance with regulatory and organizational standards.• Developed and enforced security policies, risk management strategies, and audit processes that enhanced organizational resilience, improved compliance posture, and ensured continuous audit readiness.

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Zahid Khawaja — Grc Analyst at Get Well in Houston, TX, US | Unifers