GS
Open to opportunities

Gabriel Samuel

@gabrielsamuel1

Experienced GRC professional with a focus on information security.

United States

What I'm looking for

I am looking for a role that allows me to leverage my GRC expertise while fostering a culture of security awareness and compliance within the organization.

I am an experienced Governance, Risk, and Compliance (GRC) professional with over 10 years in Information Security Governance, Enterprise Risk Management, Compliance, and IT Audit. My proven ability to lead security and compliance programs is aligned with industry frameworks such as NIST 800-53, ISO 27001, and HIPAA. I excel in managing third-party risk, conducting technical assessments, and developing security policies while interfacing with senior stakeholders to drive security maturity and regulatory compliance.

Throughout my career, I have led enterprise-wide GRC initiatives, including policy management and compliance reviews, and have successfully managed third-party risk programs. My experience includes delivering board-level reports on key risk indicators and facilitating Cyber Business Impact Analyses to assess data confidentiality and integrity. I am committed to enhancing organizational security posture through effective training and awareness campaigns, ensuring that all employees are equipped to recognize and respond to security threats.

Experience

Work history, roles, and key accomplishments

UC
Current

GRC Manager (InfoSec)

UT Southwestern Medical Center

Mar 2016 - Present (9 years 2 months)

Led enterprise-wide GRC initiatives, including policy management, risk analysis, and compliance reviews aligned to HIPAA, PCI DSS, NIST, and SOC 2 standards. Managed the third-party risk program, including cloud vendor reviews and TX-RAMP compliance.

UC
Current

GRC Manager (InfoSec)

UT Southwestern Medical Center

Mar 2016 - Present (9 years 2 months)

Led enterprise-wide GRC initiatives, including policy management, risk analysis, and compliance reviews aligned with HIPAA, PCI DSS, NIST, and SOC 2 standards. Managed the third-party risk program, developed the IS risk register, and responded to regulatory audits.

UC
Current

IT Governance, Risk, and Compliance

UT Southwestern Medical Center

Mar 2016 - Present (9 years 2 months)

Oversaw annual IT risk assessments and developed prioritized audit plans. Coordinated audit evidence collection, conducted enterprise-wide PCI DSS compliance reviews, and advised on data privacy.

UC
Current

Assessment / Audit

UT Southwestern Medical Center

Mar 2016 - Present (9 years 2 months)

Designed and executed IT audit programs using NIST and COBIT frameworks. Reviewed data flows and system interconnectivity for data integrity risks, and performed change management and incident review audits.

UC
Current

GRC Manager (InfoSec)

UT Southwestern Medical Center

Mar 2016 - Present (9 years 2 months)

Led enterprise-wide GRC initiatives, including policy management, risk analysis, and compliance reviews aligned with HIPAA, PCI DSS, NIST, and SOC 2 standards. Managed the third-party risk program, including cloud vendor reviews and TX-RAMP compliance, and responded to regulatory audits. Delivered board-level reports on KRIs, KPIs, and enterprise security risks, while also overseeing internal IT a

CS

IT Auditor

Cook Children’s Health Care System

Dec 2013 - Mar 2016 (2 years 3 months)

Audited IT controls for compliance with HIPAA and internal policies, reviewing system development life cycles for new implementations. Conducted vendor access reviews, BAA compliance, and Active Directory audits. Documented audit findings and action plans, presenting them to senior management.

CS

IT Auditor

Cook Children’s Health Care System

Dec 2013 - Mar 2016 (2 years 3 months)

Audited IT controls for HIPAA compliance and internal policies, and reviewed system development life cycles for new implementations. Conducted vendor access reviews, BAA compliance, and Active Directory audits.

UC

IT Governance, Risk, and Compliance (Internal Audit)

UT Southwestern Medical Center

Oversaw annual IT risk assessments and developed prioritized audit plans. Coordinated audit evidence collection and engagement with external auditors, and conducted enterprise-wide PCI DSS compliance reviews.

CS

IT Auditor

Cook Children’s Health Care System

Dec 2013 - Mar 2016 (2 years 3 months)

Audited IT controls for compliance with HIPAA and internal policies, and reviewed system development life cycles for new implementations. Conducted vendor access reviews, BAA compliance, and Active Directory audits.

Education

Degrees, certifications, and relevant coursework

EU

Enugu State University

Bachelor's Degree, General Studies

Obtained a Bachelor's Degree from Enugu State University, Nigeria. This foundational education supported subsequent career development in Information Security Governance, Enterprise Risk Management, Compliance, and IT Audit.

Tech stack

Software and tools used professionally

Interested in hiring Gabriel?

You can contact Gabriel and 90k+ other talented remote workers on Himalayas.

Message Gabriel

People also viewed

View all talent

Find your dream job

Sign up now and join over 85,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Gabriel Samuel - GRC Manager (InfoSec) - UT Southwestern Medical Center | Himalayas