Shawn Harris
Skills
• Governance: Policy Development, Control Design & Testing, Audit Management, SIG & A2V
Reviews
• Risk Management: Enterprise Risk Assessment, Third-Party Risk (TPRM), FAIR Methodology, Risk
Reporting
• Compliance: NIST, ISO 27001, PCI DSS, NERC, CIS Top 20, Federal Regulations
• Tools: ServiceNow GRC, RSA Archer, Jira, Confluence, Risk Lens, Security Scorecard, Qualys,
Tenable, ProofPoint, SharePoint.
About
Senior GRC Analyst with over a decade of experience specializing in Governance, Risk, and Compliance
programs. Expert in implementing and auditing controls for frameworks including NIST, ISO 27001, PCI
DSS, and NERC. Proven success in third-party risk management (TPRM), enterprise risk reduction,
security awareness, and ensuring compliance with federal regulations. Leverages technical proficiency
and stakeholder collaboration to build resilient security postures.