HimalayasHimalayas logo
Tikva AlayoTA
Open to opportunities

Tikva Alayo

@tikvaalayo

Information Security GRC officer using NIST frameworks to reduce cyber risk and strengthen regulatory compliance.

United States
Message

What I'm looking for

I’m looking for a GRC role where I can lead NIST-aligned risk assessments, build measurable KRI/KPI reporting, strengthen third-party risk, and drive audit-ready evidence that reduces cyber risk and improves compliance outcomes.

I’m an Information Security Governance, Risk and Compliance Officer with 4+ years of experience in cyber risk, regulatory compliance, risk assessments, audits, vendor risk management, and security governance in financial and regulated environments. I help organizations turn complex regulatory requirements into practical controls, evidence, and measurable improvements.

I’ve supported regulatory examinations and audit readiness end-to-end, including Federal Reserve FFIEC examination testing. By developing security policies, performing risk assessments, and improving security and compliance posture, I achieved 25% risk reduction and 35% compliance process improvement, with successful audit and regulatory examination results in 3 months.

At Sabadell Bank, I created and maintained information security policies and procedures that increased secure workflow across departments within 3 months. I also collaborated with legal to strengthen third-party vendor security questionnaires and SOC 2 review processes during onboarding, improving supply chain risk management by 20% in 2 months, and conducted cybersecurity risk assessments aligned with NIST CSF 2.0, GLBA, and GDPR.

Previously at Maverc Technologies, I implemented NIST SP 800-171 controls to support CMMC compliance and enabled successful CMMC Level 2 certification within 6 months. I managed compliance platform improvements through NIST RMF gap analysis and exception handling, increasing CUI confidentiality protection by 25%, while also building incident response and monitoring capabilities using SIEM tools and cloud security practices.

Experience

Work history, roles, and key accomplishments

SB
Current

Information Security GRC Officer

Sabadell Bank Miami Branch

Nov 2024 - Present (1 year 5 months)

Created and maintained information security policies and procedures, increasing secure workflow across departments within 3 months. Led FFIEC audit evidence testing with no regulatory findings, built NIST CSF 2.0/GLBA/GDPR-aligned risk assessments, and delivered a remediation roadmap that reduced risk by 25%.

MT

GRC and Security Analyst

Maverc Technologies

Jan 2022 - Oct 2024 (2 years 9 months)

Implemented and maintained NIST SP 800-171 controls for CMMC, enabling successful CMMC Level 2 certification within 6 months and improving alignment of system configurations and documentation. Automated NIST RMF gap analysis and improved CUI confidentiality protection by 25%, while conducting Elastic SIEM monitoring and incident response that reduced false positives by 40% and alerts by 60%.

Education

Degrees, certifications, and relevant coursework

University of the People logoUP

University of the People

Bachelor of Science, Computer Science

2021 - 2024

Grade: GPA: 3.6

Earned a Bachelor of Science in Computer Science (GPA 3.6) from University of the People from 02/2021 to 11/2024.

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan