Agnes Kuteyi
@agneskuteyi
Seasoned GRC professional with expertise in cybersecurity governance.
What I'm looking for
I am a seasoned Governance, Risk, and Compliance (GRC) professional with extensive experience in regulatory compliance, contractual risk analysis, and cybersecurity governance, particularly within healthcare environments. My career has been marked by a commitment to enhancing organizational resilience through effective risk management strategies and compliance frameworks. I have successfully delivered over 150 RFPs, audits, and due diligence responses, ensuring alignment with critical standards such as NIST 800-53, HITRUST CSF, ISO 27001, PCI DSS, and HIPAA.
In my current role as a Senior IT Risk Analyst at the Center for Social Change, I lead comprehensive cybersecurity risk assessments and facilitate executive-level reporting. My ability to translate complex risk data into actionable insights has influenced strategic decision-making and resource allocation. I am passionate about fostering a culture of risk awareness through cross-departmental workshops and training sessions, which have significantly improved risk identification and remediation across IT and business units.
Throughout my career, I have implemented automated tracking and reporting systems that enhance visibility for senior leadership, reducing manual risk assessment time by 40%. My dedication to continuous improvement and regulatory adherence has been instrumental in supporting numerous audits and compliance reviews, ultimately contributing to the overall security posture of the organizations I have served.
Experience
Work history, roles, and key accomplishments
Senior IT Risk Analyst
Center for Social Change
Jul 2023 - Present (2 years)
Led comprehensive cybersecurity risk assessments leveraging NIST 800-53 and ISO 27001 frameworks to strengthen compliance and reduce organizational vulnerabilities. Facilitated executive-level reporting by translating complex risk data into actionable insights, influencing strategic decision-making and resource allocation.
Security Controls Assessor
Center for Social Change
Mar 2021 - Present (4 years 4 months)
Implemented security control assessments aligned with NIST and ISO frameworks, identifying gaps and recommending remediation to enhance operational resilience. Managed responses to over 150 security questionnaires and RFPs, ensuring alignment with PCI DSS and healthcare compliance standards.
Third-Party Risk Analyst
Microsoft
Feb 2018 - Present (7 years 5 months)
Spearheaded third-party risk management initiatives, integrating ServiceNow GRC tools to automate vendor risk assessments and reporting workflows. Partnered with legal and business units to negotiate contract terms, ensuring alignment with cybersecurity risk policies and regulatory mandates.
Education
Degrees, certifications, and relevant coursework
Hood College
Master of Science, Cyber Security
Completed a Master of Science in Cyber Security, focusing on advanced topics in cybersecurity and risk management. Gained expertise in securing complex systems and data.
University of Maryland, Baltimore County
Bachelor of Science, Business Technology Administration
Obtained a Bachelor of Science in Business Technology Administration. Developed a strong foundation in business principles combined with technological applications.
Baltimore City Community College
Associate Degree, Computer Information Systems
Earned an Associate Degree in Computer Information Systems. Acquired fundamental knowledge and skills in computer systems and information technology.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Agnes?
You can contact Agnes and 90k+ other talented remote workers on Himalayas.
Message AgnesFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
