Tikva Alayo
@tikvaalayo
Information Security GRC officer using NIST frameworks to reduce cyber risk and strengthen regulatory compliance.
What I'm looking for
I’m an Information Security Governance, Risk and Compliance Officer with 4+ years of experience in cyber risk, regulatory compliance, risk assessments, audits, vendor risk management, and security governance in financial and regulated environments. I help organizations turn complex regulatory requirements into practical controls, evidence, and measurable improvements.
I’ve supported regulatory examinations and audit readiness end-to-end, including Federal Reserve FFIEC examination testing. By developing security policies, performing risk assessments, and improving security and compliance posture, I achieved 25% risk reduction and 35% compliance process improvement, with successful audit and regulatory examination results in 3 months.
At Sabadell Bank, I created and maintained information security policies and procedures that increased secure workflow across departments within 3 months. I also collaborated with legal to strengthen third-party vendor security questionnaires and SOC 2 review processes during onboarding, improving supply chain risk management by 20% in 2 months, and conducted cybersecurity risk assessments aligned with NIST CSF 2.0, GLBA, and GDPR.
Previously at Maverc Technologies, I implemented NIST SP 800-171 controls to support CMMC compliance and enabled successful CMMC Level 2 certification within 6 months. I managed compliance platform improvements through NIST RMF gap analysis and exception handling, increasing CUI confidentiality protection by 25%, while also building incident response and monitoring capabilities using SIEM tools and cloud security practices.
Experience
Work history, roles, and key accomplishments
Information Security GRC Officer
Sabadell Bank Miami Branch
Nov 2024 - Present (1 year 5 months)
Created and maintained information security policies and procedures, increasing secure workflow across departments within 3 months. Led FFIEC audit evidence testing with no regulatory findings, built NIST CSF 2.0/GLBA/GDPR-aligned risk assessments, and delivered a remediation roadmap that reduced risk by 25%.
GRC and Security Analyst
Maverc Technologies
Jan 2022 - Oct 2024 (2 years 9 months)
Implemented and maintained NIST SP 800-171 controls for CMMC, enabling successful CMMC Level 2 certification within 6 months and improving alignment of system configurations and documentation. Automated NIST RMF gap analysis and improved CUI confidentiality protection by 25%, while conducting Elastic SIEM monitoring and incident response that reduced false positives by 40% and alerts by 60%.
Education
Degrees, certifications, and relevant coursework
University of the People
Bachelor of Science, Computer Science
2021 - 2024
Grade: GPA: 3.6
Earned a Bachelor of Science in Computer Science (GPA 3.6) from University of the People from 02/2021 to 11/2024.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Social media
Job categories
Skills
Interested in hiring Tikva?
You can contact Tikva and 90k+ other talented remote workers on Himalayas.
Message TikvaFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
