Skip to main content
Donna HeiseDH
Open to opportunities

Donna Heise

@donnaheise

I build GRC and third-party risk programs that improve audit readiness.

United States
Message

I've built third-party risk management programs from zero at Upgrade, assessed more than 70 critical vendors within 90 days, and contributed to a SOC 2 Type II certification with no TPRM-related findings.

Across Kaiser Permanente, Hexion, Arvest Bank, Western Union, and Leidos, I've led control testing, framework mapping, audit readiness, remediation tracking, and executive reporting. I implemented OneTrust GRC and Risk Management at Hexion and created first-time HITRUST and NIST control testing processes at Kaiser Permanente.

I work closely with business, technology, audit, legal, privacy, procurement, and vendor teams to turn complex compliance requirements into clear controls, actionable gaps, and organized programs.

Experience

Work history, roles, and key accomplishments

TB

Senior Information Security Analyst

TEKsystems / Arvest Bank

Mar 2025 - Dec 2025 (9 months)

Mapped internal controls across eight frameworks, including NIST CSF v2, PCI DSS 4.0, FFIEC, GLBA, CCM v4, CRI Profile v2, GDPR, and CCPA, establishing full policy-to-standard-to-control traceability. Monitored quarterly banking and fintech regulatory changes and updated control mapping, ran gap analyses, and tracked remediation in Archer.

Education

Degrees, certifications, and relevant coursework

Colorado State University Global logoCG

Colorado State University Global

Bachelor of Science, Healthcare Administration

Bachelor of Science in Healthcare Administration from Colorado State University Global.

Tech stack

Software and tools used professionally

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan