Skip to main content
HB
Open to opportunities

Herbert Byekwaso

@herbertbyekwaso

Senior Information Security Analyst specializing in GRC, risk reduction, and cybersecurity compliance for enterprise environments.

United States
Message

What I'm looking for

I’m looking for a fast-paced, highly regulated environment where I can strengthen security posture through GRC, risk assessment, control design, and security operations—driving measurable reductions in vulnerabilities while improving audit readiness and continuous improvement.

I’m an accomplished Senior Information Security Analyst with 8+ years of experience protecting enterprise systems, data, and digital assets through cybersecurity, risk management, and compliance programs.

I implement and maintain security frameworks and standards including NIST Cybersecurity Framework (CSF), NIST 800-53, ISO 27001, CIS Controls, COBIT, SOC 2, PCI DSS, GDPR, and HIPAA—translating requirements into practical controls that improve security posture. I’ve identified and mitigated security risks, reducing critical vulnerabilities by up to 40% through monitoring and control enhancements.

In leadership roles, I’ve driven security operations and incident readiness, built and streamlined GRC workflows in ServiceNow, and engineered RBAC and identity controls that strengthen data protection. I focus on continuous improvement—designing secure processes aligned with frameworks and SDLC best practices so audits stay on track and security stays measurable.

Experience

Work history, roles, and key accomplishments

CL

Senior GRC & IT Controls Engineer

Covaris LLC

Nov 2021 - Jun 2026 (4 years 7 months)

Performed IT General Controls (ITGC) testing for interconnected financial systems and remediated vulnerabilities to strengthen compliance posture. Configured RBAC in SAP and Workday, integrated CRM/ERP via RESTful APIs, and streamlined incident management and SOX 404 evidence collection using ServiceNow and centralized GRC reporting.

OT

Lead GRC Software Engineer

Orange Telecom

Apr 2015 - Oct 2021 (6 years 6 months)

Led delivery of a multi-module GRC platform and engineered workflow automation for risk assessments, control testing, compliance reporting, and audit evidence management. Integrated DevSecOps security testing into GRC development and built RBAC/authentication security controls and regulatory reporting capabilities aligned with enterprise compliance needs.

NR

IT Compliance Auditor

New Relic

Feb 2012 - Mar 2015 (3 years 1 month)

Conducted assessments against ISO 27001, NIST Cybersecurity Framework (CSF), and internal control requirements, achieving high compliance during annual reviews. Evaluated cybersecurity controls and vulnerability management, supported remediation of audit findings, and produced audit reports for leadership risk-based prioritization.

Education

Degrees, certifications, and relevant coursework

Western Governors University logoWU

Western Governors University

Master of Science, Cybersecurity and Information Assurance

Completed a Master of Science in Cybersecurity and Information Assurance at Western Governors University.

Western Governors University logoWU

Western Governors University

Award of Excellence, Cybersecurity Management

Received an Award of Excellence in Cybersecurity Management from Western Governors University.

Brunel University London logoBL

Brunel University London

Bachelor of Science, Computer Science

Completed a Bachelor of Science in Computer Science at Brunel University London.

Tech stack

Software and tools used professionally

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan