At CATERPILLAR INC, I review security plans and FedRAMP authorization package deliverables, including System Security Plans and Security Assessment Reports. I validate control evidence using NIST SP 800-53A methods and delivered 100% of reports on time for management risk decisions.
I also assess system risks and review Nessus, ACAS, and Nexpose scan reports for findings. I maintain risk registers and assessment evidence to support visibility into outstanding risks and corrective actions.
At BRISTOL LLC., I prepared security authorization and risk assessment documentation and assessed security and privacy controls. I also conducted inherent risk assessments for third-party vendors and tracked remediation plans for identified vulnerabilities.
At UnitedHealth, I completed operational, regulatory, and third-party risk assessments for healthcare clients. I reviewed safeguards against NIST SP 800-53, supported audits, and created remediation plans for security and privacy control deficiencies.

