Maxine Jones profile picture

Hello, I'm

Maxine Jones

GRC Analyst | IT Risk & Compliance | Cybersecurity

I build practical governance, risk, compliance, and security programs that translate frameworks into audit-ready controls, measurable remediation plans, and executive decisions.

🏆 NCL — #1 Midwest Regional (out of 26) 🥉 Google Black CS Summit Hackathon — 3rd Place ✓ CompTIA Security+ Certified
LinkedIn profile GitHub profile

Get To Know More

About Me

Experience icon

Experience

GRC, Cybersecurity
& IT Systems Experience

Education icon

Education

Chicago State University — B.S. Computer Science (3.3 GPA)
President — Computer Science Club
President — WiCyS Chapter
Founder — Girls Who Code College Loop
Member — National Council of Negro Women

West Virginia University
M.S. Business Cybersecurity Management (August 2026, 4.0 GPA)

Governance, Risk, and Compliance analyst focused on enterprise risk, third-party risk, security compliance, control testing, and audit readiness. I translate NIST, ISO 27001, SOC 2, PCI DSS, GLBA, HIPAA, and CSA CAIQ requirements into practical workflows, evidence packages, remediation plans, and executive-ready reporting. My portfolio combines professional experience with hands-on case studies in vendor risk management, identity security, vulnerability management, incident response, and security awareness.

Explore My

Experience

Professional Experience

GRC Analyst (Compliance Fellowship) — West Virginia University CRRC

May 2026 – August 2026 | Morgantown, WV

  • Designed and authored a suite of structured GRC training courses for the CRRC program, including a 20-lesson RBAC/IAM Governance course, Vendor Risk Management, ISO 27001 Foundations, SOC 2, Vulnerability Management, and a security awareness curriculum covering phishing, MFA, and social engineering.
  • Built the Vendor Risk Management course using real third-party assessment artifacts, including vendor tiering, security questionnaires (CAIQ), control mapping (GLBA and PCI DSS), and POA&M remediation tracking to demonstrate the end-to-end third-party risk lifecycle.
  • Translated security and compliance requirements into plain-language policies, standards, and training aligned with CISA best practices while coordinating delivery across student teams, faculty mentors, and partner organizations supporting West Virginia critical infrastructure.

Client Engagement — Bridle Paths

Information Security Analyst Intern (Governance and Compliance) | Project Lead

May 2026 – August 2026 | Loudoun County, VA

  • Led the governance and compliance workstream for a 54-module HIPAA-regulated CRM engagement, authoring the audit plan and directing field-level access-control validation across 32,100+ field/profile permission combinations and 680 access rules.
  • Raised configuration compliance from 51.5% to 97.8% before production deployment and led structured validation and stakeholder review of 315 access-control remediation items, reducing unresolved findings from 322 to 7.
  • Designed the SEC-01 field-level security matrix mapping 10 operational profiles to 6 PHI data-sensitivity groups and enforcing least-privilege access aligned to NIST 800-53 AC-6(1).
  • Built the master configuration inventory and reviewer change history and authored CRM administration and operational governance documentation covering permissions, change management, deployment, rollback, incident response, and audit evidence.
  • Built Python automation using the Zoho CRM REST API and OAuth 2.0 to reconcile live CRM metadata, validate RBAC configurations, and generate executive analysis, configuration inventories, and audit-ready evidence that passed independent technical verification.

Risk Analyst Intern (Vulnerability Management) — United Airlines

May 2024 – August 2024

  • Triaged 10,000+ Qualys vulnerability findings against NIST SP 800-53, scoring each by likelihood and business impact to risk-rank remediation across high-criticality assets.
  • Translated scan data into risk-based remediation plans mapped to asset owners and maintained POA&M-style tracking within the ISO 27001 framework to support a quarterly audit cycle.
  • Developed compliance documentation and dashboards aligned to NIST 800-53 control families to communicate compliance posture to leadership.

IT Security Analyst — Chicago State University

January 2025 – May 2025 | Chicago, IL

  • Deployed and hardened Windows Server systems to secure configuration baselines for a 100+ participant cybersecurity event, documenting residual risks and control decisions.
  • Translated technical risks into plain-language guidance for non-technical stakeholders across four partner institutions, supporting risk-informed decisions.

Technical Skills

GRC & Compliance

NIST 800-53, ISO 27001, SOC 2, PCI DSS, GLBA, HIPAA, Risk Assessment, Control Testing, Evidence Collection, Policy Development, POA&M

Third-Party Risk Management

Vendor Intake, Tiering, Inherent & Residual Risk, CAIQ Review, SOC 2 Review, Contract Controls, Continuous Monitoring

Identity & Access Management

Microsoft Entra ID, RBAC, MFA, Conditional Access, Least Privilege, Zero Trust

Vulnerability Management

Qualys, Risk Prioritization, Patch Analysis, Remediation Tracking

SIEM & Detection

Splunk, Wazuh, Log Analysis

Incident Response

Threat Investigation, Endpoint Analysis, MITRE ATT&CK

Programming

Python, Bash, SQL

Browse My

Projects

Featured GRC & Cybersecurity Case Studies

Selected work demonstrating how I assess risk, map controls, document findings, support remediation, and communicate security decisions to technical and executive audiences.

Featured Case Study

MindfulAI Labs — AI GRC & Audit Evidence Portfolio

ISO 27001 | CIS Controls | Control Testing | Risk Management | Audit Evidence

Built a simulated enterprise GRC environment for an AI organization, developing risk and control documentation, control assessments, audit evidence, access reviews, change-management testing, vulnerability-management assessments, and remediation documentation.

Scope: AI governance, vulnerability management, access governance, change management, backup and recovery, and training-data validation.

Assessment Approach: Defined control criteria, evaluated simulated control effectiveness, documented findings and observations, identified evidence requirements, assessed residual risk, and developed remediation recommendations.

Featured Artifacts: Vulnerability Management Control Assessment, User Access Review Worksheet, Change Management Control Test Worksheet, AI Training Data Validation Checklist, and Backup & Recovery Test Record.

Portfolio Disclosure: MindfulAI Labs is a simulated GRC practice environment created for educational and portfolio purposes. Results do not represent testing performed against an actual production organization.

Featured Case Study

SecurityGroup101 Enterprise GRC & Vendor Risk Program

NIST SP 800-30 | NIST SP 800-161 | ISO 27001 | CSA CAIQ | PCI DSS | GLBA

Designed a simulated fintech GRC operating model that connects quantitative risk assessment, regulatory compliance, business continuity, governance, ISO 27001 control applicability, and an end-to-end third-party risk management lifecycle.

11

Vendors Inventoried

85

CAIQ Questions

93

ISO Controls Assessed

8

Open Findings Tracked

Business Problem: Fragmented risk processes, inconsistent control ownership, regulatory exposure, and no formal third-party risk program.

Methodology: Quantitative SLE/ARO/ALE analysis, multi-framework control mapping, vendor tiering, inherent and residual risk analysis, and POA&M-based remediation.

Vendor Risk Workflow: Intake → Tiering → Inherent Risk → CAIQ / SOC 2 Review → Residual Risk → POA&M → Monitoring → Executive Decision.

Key Decision: Assessed Stripe as HIGH inherent risk with STRONG control effectiveness, resulting in MEDIUM-LOW residual risk and an Approved with Conditions recommendation.

Deliverables: Risk register, DR/BCP plans, governance model, control catalog, ISO 27001 Statement of Applicability, vendor inventory, CAIQ, scoring rubric, residual risk report, POA&M, Trust Center, and executive summary.

Azure AD Incident Response & Zero Trust Lab

Microsoft Entra ID | Conditional Access | Identity Security

Built a cloud identity security lab to simulate suspicious sign-in and account compromise scenarios using Microsoft Entra ID. Designed and tested Zero Trust controls to strengthen identity protection and reduce unauthorized access risk.

Key Metrics: 5 Conditional Access policies implemented | MFA enforcement tested | legacy authentication blocked | location- and device-based access restrictions validated | 350+ alerts investigated

Tools: Microsoft Entra ID, Conditional Access, MFA, Salesforce SSO, Intune concepts

Focus: Identity security, Zero Trust policy enforcement, suspicious sign-in investigation

Deliverables: Incident response report, policy testing results, remediation recommendations

Layered Network Security Monitoring & Fusion Detection Framework

Suricata IDS | Cowrie Honeypot | Splunk SIEM

Built a layered detection and deception architecture that combined Suricata network alerts, Cowrie honeypot telemetry, and Splunk correlation dashboards to investigate exploit attempts, brute-force logins, malware retrieval, and persistence activity across the attack lifecycle.

Key Metrics: 307,708 total observed attack events | 30,649 high-severity exploit attempts | 18 confirmed multi-stage kill chains | 109 persistence attempts | 60 unique malware payloads

Tools: Splunk, Suricata, Cowrie, MITRE ATT&CK

Focus: Detection engineering, alert correlation, incident response, attack progression analysis

Deliverables: Correlation dashboards, executive-level security metrics, incident response playbooks

Endpoint Incident Response & Lateral Movement Analysis

Windows Forensics | Procmon | Endpoint Investigation

Performed an endpoint incident response investigation using Procmon to analyze process, file, and registry activity associated with a suspected compromise. Traced multi-stage infection behavior and lateral movement indicators to support containment and remediation planning.

Key Evidence: Multi-stage infection behavior identified | suspicious process execution analyzed | abnormal file creation patterns reviewed | registry activity investigated for persistence indicators

Tools: Procmon, Windows endpoint telemetry, forensic analysis workflow

Focus: Endpoint triage, malware behavior analysis, lateral movement investigation

Deliverables: Incident response report, findings summary, prioritized remediation actions

TPOT-CIC Fusion Intrusion Detection System

Machine Learning IDS | T-Pot Honeypot | CIC-IDS Dataset

Developed a hybrid intrusion detection system that fused honeypot telemetry from T-Pot with machine learning pipelines trained on CIC-IDS data. Used automated model generation to improve malicious traffic classification and support SOC-oriented threat analysis.

Key Evidence: Combined live honeypot telemetry with benchmark intrusion dataset | automated optimized ML pipelines for attack classification | designed to improve visibility into malicious traffic patterns

Tools: Python, TPOT AutoML, T-Pot, CIC-IDS, Splunk

Focus: ML-based intrusion detection, network threat classification, security analytics

Deliverables: Detection pipeline, project report, security visualization support

Academic Projects

Network Traffic Risk Assessment Using Simulated Attacks

West Virginia University — CYBR 530

Built a Python-based network monitoring system to simulate SYN flood and ICMP sweep attacks, log packet activity into SQLite, and apply NIST-based risk scoring to detected network threats.

Key Metrics: Logged 3,000+ packets into SQLite during attack simulation

Tools: Python, SQLite, packet analysis, NIST-based risk scoring

Focus: Network monitoring, threat simulation, risk assessment

Quantitative Risk Assessment

West Virginia University — CYBR 525

Conducted a quantitative risk analysis using SLE, ARO, and ALE calculations to assess business impact and support risk-based decision-making aligned with NIST SP 800-30.

Tools: Risk quantification methodology, NIST SP 800-30

Focus: Quantitative risk analysis, business impact evaluation

Deliverables: Risk calculations, analysis document, recommendations

IT Audit Planning Project

West Virginia University — CYBR 510

Developed an IT audit planning document focused on vulnerability management and control review, incorporating NIST CSF 2.0 and NIST SP 800-171 concepts to support structured audit preparation.

Tools: NIST CSF 2.0, NIST SP 800-171

Focus: Audit planning, control assessment, vulnerability management review

Deliverables: Audit plan, scope definition, control mapping

Security Reports & Deliverables

Professional-grade incident reports and security documentation produced as part of hands-on investigations.

Security Incident Report — Azure AD Credential Compromise

Incident ID: INC-2026-0322-001 | Severity: HIGH | Status: Contained

Formal incident report documenting a vishing-based credential compromise of a Microsoft 365 account. Covers full attack narrative, Entra ID sign-in log analysis, MITRE ATT&CK mapping, Zero Trust remediation actions, IOCs, and executive business impact assessment.

Scope: Cloud identity compromise, unauthorized group creation, privilege escalation attempt

Frameworks: MITRE ATT&CK (T1566.004, T1078, T1098, T1069), Zero Trust, NIST CSF

Deliverable: Executive-level incident report with full log evidence, IOCs, and remediation steps

MDR Executive Report — Endpoint Malware & Lateral Movement

Client: Lumen Soda, Inc. | Prepared for: CEO | Role: Junior MDR Analyst

Executive-level MDR report delivered to a CEO summarizing a multi-stage malware infection, lateral movement to a remote host, and ransomware-style file creation. Translates forensic Procmon findings into clear business impact, root cause, and actionable remediation steps.

Scope: Dropper execution, second-stage payload, lateral movement to ADMIN-21139, remote file impact

Tools: Sysinternals Procmon, Windows endpoint forensics

Deliverable: Non-technical executive summary with prioritized remediation recommendations

My Credentials

Resume & Certifications

Resume

Certification

CompTIA Security+ (SY0-701)

Get in Touch

Contact Me

I am open to GRC, third-party risk, security compliance, IT audit, and cybersecurity analyst opportunities in Chicago or remote.