whoami
GRC & IT Risk Associate — Cybersecurity, Governance, Risk & Compliance
cat about.md
Cybersecurity Governance, Risk, and Compliance (GRC) professional with 2+ years of consulting experience delivering IT risk assessments, ISO 27001 audits, SOC engagements, third-party risk reviews, and business resilience initiatives across financial services, healthcare, technology, BPO, insurance, and marketing sectors.
Conducted 25+ audit assessments and contributed to 50+ client engagements, supporting organizations in achieving audit readiness, maintaining certification compliance, and strengthening control environments.
Experienced in risk assessments, control testing, risk register management, governance reporting, policy development, and stakeholder engagement — with a proven ability to translate technical findings into actionable business recommendations for senior leadership.
ls -la experience/
- Conducted risk assessments across physical security, operational risks, and business resilience — identifying vulnerabilities and delivering actionable mitigation recommendations across multiple sectors.
- Supported design and optimization of risk management frameworks, including SOPs, risk dashboards, and monitoring processes aligned with organizational objectives.
- Assisted in developing and reviewing Business Continuity Plans (BCP) and Crisis Management Plans (CMP), contributing to crisis simulations, tabletop exercises, and post-incident improvement initiatives.
- Managed multiple client engagements remotely, delivering risk assessment reports and advisory documentation while maintaining strong stakeholder communication.
- Collaborated with senior consultants and clients on security advisory and pre-sales activities, contributing to proposals and tailored risk management solutions.
- Analyzed emerging threats and geopolitical factors to support decision-making and strengthen client resilience strategies.
- Supported 30+ client engagements delivering IT risk, compliance, and third-party risk assessments across financial services, healthcare, and IT sectors.
- Led ISO 27001 and NIST audits across 25 assessments, including control design review, operating effectiveness, and remediation tracking.
- Tested and tracked 114 Annex A controls across access management, change management, operational security, and governance domains.
- Collected, validated, and mapped audit evidence to control requirements, including technical security controls and supporting documentation.
- Drafted and updated ISMS policies, standards, and procedures to strengthen audit readiness and control alignment.
- Maintained shared and department-level risk registers, identified emerging risks, and tracked open items through closure.
- Supported third-party risk management and vendor audits for a major Indian bank's insurance division, covering 35 vendors across India.
- Prepared governance, audit, and compliance reports each month for stakeholder review and decision-making.
- Collaborated with internal teams and client stakeholders to close non-conformities and reduce open risks before external audits.
- Supported 15+ SOC engagements — SOC 1, SOC 2 Type 1 & Type 2 — including control testing, evidence review, and audit reporting.
- Performed controls testing, evidence collection and review, and audit report preparation across security, privacy, confidentiality, and data processing/integrity control areas.
- Used Vanta to manage audit evidence, track control readiness, and support audit execution.
- Communicated findings, open risks, and remediation requirements to stakeholders using both technical and non-technical language.
- Supported remediation tracking and drafted detailed and final audit reports after gap closure.
cat skills.json
ls projects/
Designed a blockchain-based framework to enhance authentication, integrity, and trust in V2X communication — implementing secure controls such as replay attack detection and cryptographic key management using Python.
Built a machine learning based prediction model for forecasting cryptocurrency prices by gathering and analyzing live datasets from Yahoo Finance, using Prophet, LSTM, ARIMA, and XGBoost.
ijirt.org/Article?manuscript=159274 →cat education.log
cat certifications.log
- ISO/IEC 27001:2022 Lead Auditor
Sep 2025 - ISC2 Certified in Cybersecurity
Mar 2025 - CompTIA Security+
Pursuing - PwC Switzerland Cybersecurity Job Simulation
Jan 2025 - EY Audit Job Simulation
Jan 2025 - Mastercard Cybersecurity Virtual Experience Program
Jan 2025 - Vanta Audit Partner
Nov 2023
contact --send
- dallasvaz0@gmail.com
- phone
- +971 55 168 5995
- location
- Dubai, UAE
- linkedin.com/in/dallas-vaz