Rodrick Stephen
Skills
Cybersecurity, Data Privacy, Privacy Compliance, Personally Identifiable Information (PII), Governance Risk and Compliance (GRC), Risk Management, Information Systems Auditing, IT Audit, Privacy Assessments, Security Assessments, Compliance Assessments, Internal Controls, ITGC, ITAC, Third-Party Risk Management, Vendor Risk Management, Regulatory Compliance, Security Controls, Control Testing, Corrective Action, Remediation Management, Incident Response, Security Awareness, Privacy Awareness, NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-171, ISO 27001, ISO 27002, GDPR, CCPA, HIPAA, GLBA, SOC 2, PCI DSS, SOX, COBIT, FAIR, ServiceNow, OneTrust, SIEM, IAM, Identity and Access Management, Zero Trust, Vulnerability Management, Security Policy, Risk Assessment, Audit Documentation, Stakeholder Management
About
Cybersecurity, privacy, governance, risk, and compliance (GRC) professional with approximately 10 years of experience in information systems auditing, privacy/security assessments, regulatory compliance, risk management, internal controls, incident response, and third-party risk. Experienced in evaluating information systems and business processes to identify security and privacy risks affecting personally identifiable information (PII), sensitive information, and regulated data. Skilled in NIST, ISO 27001/27002, NIST SP 800-53/800-171, GDPR, CCPA, HIPAA, GLBA, SOC 2, PCI DSS, SOX, COBIT, and FAIR. Experienced with ServiceNow and OneTrust GRC workflows, corrective-action management, control assessments, stakeholder communication, and security/privacy awareness. Master of Cybersecurity Technology with CISA, CISM, CRISC, CEH, and CySA+ certifications. 100% service-connected permanently and totally disabled veteran eligible for applicable federal veteran hiring authorities.