Maxine Jones profile picture

Hello, I'm

Maxine Jones

GRC Analyst | Third-Party Risk | Security Compliance

I build practical governance, risk, compliance, and security programs that translate frameworks into audit-ready controls, measurable remediation plans, and executive decisions.

🏆 NCL — #1 Midwest Regional (out of 26) 🥉 Google Black CS Summit Hackathon — 3rd Place ✓ CompTIA Security+ Certified
LinkedIn profile GitHub profile

Get To Know More

About Me

Experience icon

Experience

2 Years
GRC, Cybersecurity & IT Systems

Education icon

Education

Chicago State University — B.S. Computer Science (3.3 GPA)
President — Computer Science Club
President — WiCyS Chapter
Founder — Girls Who Code College Loop
Member — National Council of Negro Women

West Virginia University
M.S. Business Cybersecurity Management (In Progress, 4.0 GPA)

Governance, Risk, and Compliance analyst focused on enterprise risk, third-party risk, security compliance, control testing, and audit readiness. I translate NIST, ISO 27001, SOC 2, PCI DSS, GLBA, HIPAA, and CSA CAIQ requirements into practical workflows, evidence packages, remediation plans, and executive-ready reporting. My portfolio combines professional experience with hands-on case studies in vendor risk management, identity security, vulnerability management, incident response, and security awareness.

Explore My

Experience

Professional Experience

Cyber Resilience Fellow — West Virginia University CRRC

August 2024 – Present

  • Develops and delivers cybersecurity compliance training for small businesses, nonprofits, and local governments across West Virginia critical infrastructure, including SOC 2 Compliance Awareness and Account Takeover courses aligned to NIST CSF, SOC 2 Trust Services Criteria, and CISA guidance.
  • Builds security awareness programs covering phishing, MFA, password security, privacy operations, and social engineering for non-technical audiences of 50+ member organizations.
  • Translates regulatory and security requirements into plain-language policies, guidance, and training materials, contributing to documentation for security standards aligned to CISA best practices.

CRM Systems Analyst Intern & Project Lead — Bridle Paths

January 2025 – Present | Leesburg, VA (Remote)

  • Leads a six-person team implementing a 54-module Zoho CRM platform for a HIPAA-regulated therapeutic riding nonprofit, serving as primary project manager and compliance lead.
  • Conducted an end-to-end compliance audit of the platform, authoring the engagement's first audit plan, assessing 1,100+ fields against the HIPAA compliance specification, and identifying 10 control gaps before go-live.
  • Documented findings with risk ratings and remediation recommendations, coordinating corrective actions to closure and producing governance documentation and automated dashboards as audit evidence.

Risk Analyst Intern (Vulnerability Management) — United Airlines

May 2024 – August 2024

  • Triaged 10,000+ Qualys vulnerability findings against NIST SP 800-53, scoring each by likelihood and business impact to risk-rank remediation across high-criticality assets.
  • Translated scan data into risk-based remediation plans mapped to asset owners and maintained POA&M-style tracking within the ISO 27001 framework to support a quarterly audit cycle.
  • Developed compliance documentation and dashboards aligned to NIST 800-53 control families to communicate compliance posture to leadership.

Cybersecurity Hackathon Organizer — Chicago State University

January 2025 – April 2025

  • Organized cybersecurity hackathon for 50+ high school students.
  • Coordinated logistics, faculty collaboration, and event materials.

Technical Skills

GRC & Compliance

NIST 800-53, ISO 27001, SOC 2, PCI DSS, GLBA, HIPAA, Risk Assessment, Control Testing, Evidence Collection, Policy Development, POA&M

Third-Party Risk Management

Vendor Intake, Tiering, Inherent & Residual Risk, CAIQ Review, SOC 2 Review, Contract Controls, Continuous Monitoring

Identity & Access Management

Microsoft Entra ID, RBAC, MFA, Conditional Access, Least Privilege, Zero Trust

Vulnerability Management

Qualys, Risk Prioritization, Patch Analysis, Remediation Tracking

SIEM & Detection

Splunk, Wazuh, Log Analysis

Incident Response

Threat Investigation, Endpoint Analysis, MITRE ATT&CK

Programming

Python, Bash, SQL

Browse My

Projects

Featured GRC & Cybersecurity Case Studies

Selected work demonstrating how I assess risk, map controls, document findings, support remediation, and communicate security decisions to technical and executive audiences.

Featured Case Study

SecurityGroup101 Enterprise GRC & Vendor Risk Program

NIST SP 800-30 | NIST SP 800-161 | ISO 27001 | CSA CAIQ | PCI DSS | GLBA

Designed a simulated fintech GRC operating model that connects quantitative risk assessment, regulatory compliance, business continuity, governance, ISO 27001 control applicability, and an end-to-end third-party risk management lifecycle.

11

Vendors Inventoried

85

CAIQ Questions

93

ISO Controls Assessed

8

Open Findings Tracked

Business Problem: Fragmented risk processes, inconsistent control ownership, regulatory exposure, and no formal third-party risk program.

Methodology: Quantitative SLE/ARO/ALE analysis, multi-framework control mapping, vendor tiering, inherent and residual risk analysis, and POA&M-based remediation.

Vendor Risk Workflow: Intake → Tiering → Inherent Risk → CAIQ / SOC 2 Review → Residual Risk → POA&M → Monitoring → Executive Decision.

Key Decision: Assessed Stripe as HIGH inherent risk with STRONG control effectiveness, resulting in MEDIUM-LOW residual risk and an Approved with Conditions recommendation.

Deliverables: Risk register, DR/BCP plans, governance model, control catalog, ISO 27001 Statement of Applicability, vendor inventory, CAIQ, scoring rubric, residual risk report, POA&M, Trust Center, and executive summary.

Azure AD Incident Response & Zero Trust Lab

Microsoft Entra ID | Conditional Access | Identity Security

Built a cloud identity security lab to simulate suspicious sign-in and account compromise scenarios using Microsoft Entra ID. Designed and tested Zero Trust controls to strengthen identity protection and reduce unauthorized access risk.

Key Metrics: 5 Conditional Access policies implemented | MFA enforcement tested | legacy authentication blocked | location- and device-based access restrictions validated | 350+ alerts investigated

Tools: Microsoft Entra ID, Conditional Access, MFA, Salesforce SSO, Intune concepts

Focus: Identity security, Zero Trust policy enforcement, suspicious sign-in investigation

Deliverables: Incident response report, policy testing results, remediation recommendations

Layered Network Security Monitoring & Fusion Detection Framework

Suricata IDS | Cowrie Honeypot | Splunk SIEM

Built a layered detection and deception architecture that combined Suricata network alerts, Cowrie honeypot telemetry, and Splunk correlation dashboards to investigate exploit attempts, brute-force logins, malware retrieval, and persistence activity across the attack lifecycle.

Key Metrics: 307,708 total observed attack events | 30,649 high-severity exploit attempts | 18 confirmed multi-stage kill chains | 109 persistence attempts | 60 unique malware payloads

Tools: Splunk, Suricata, Cowrie, MITRE ATT&CK

Focus: Detection engineering, alert correlation, incident response, attack progression analysis

Deliverables: Correlation dashboards, executive-level security metrics, incident response playbooks

Endpoint Incident Response & Lateral Movement Analysis

Windows Forensics | Procmon | Endpoint Investigation

Performed an endpoint incident response investigation using Procmon to analyze process, file, and registry activity associated with a suspected compromise. Traced multi-stage infection behavior and lateral movement indicators to support containment and remediation planning.

Key Evidence: Multi-stage infection behavior identified | suspicious process execution analyzed | abnormal file creation patterns reviewed | registry activity investigated for persistence indicators

Tools: Procmon, Windows endpoint telemetry, forensic analysis workflow

Focus: Endpoint triage, malware behavior analysis, lateral movement investigation

Deliverables: Incident response report, findings summary, prioritized remediation actions

TPOT-CIC Fusion Intrusion Detection System

Machine Learning IDS | T-Pot Honeypot | CIC-IDS Dataset

Developed a hybrid intrusion detection system that fused honeypot telemetry from T-Pot with machine learning pipelines trained on CIC-IDS data. Used automated model generation to improve malicious traffic classification and support SOC-oriented threat analysis.

Key Evidence: Combined live honeypot telemetry with benchmark intrusion dataset | automated optimized ML pipelines for attack classification | designed to improve visibility into malicious traffic patterns

Tools: Python, TPOT AutoML, T-Pot, CIC-IDS, Splunk

Focus: ML-based intrusion detection, network threat classification, security analytics

Deliverables: Detection pipeline, project report, security visualization support

Academic Projects

Network Traffic Risk Assessment Using Simulated Attacks

West Virginia University — CYBR 530

Built a Python-based network monitoring system to simulate SYN flood and ICMP sweep attacks, log packet activity into SQLite, and apply NIST-based risk scoring to detected network threats.

Key Metrics: Logged 3,000+ packets into SQLite during attack simulation

Tools: Python, SQLite, packet analysis, NIST-based risk scoring

Focus: Network monitoring, threat simulation, risk assessment

Quantitative Risk Assessment

West Virginia University — CYBR 525

Conducted a quantitative risk analysis using SLE, ARO, and ALE calculations to assess business impact and support risk-based decision-making aligned with NIST SP 800-30.

Tools: Risk quantification methodology, NIST SP 800-30

Focus: Quantitative risk analysis, business impact evaluation

Deliverables: Risk calculations, analysis document, recommendations

IT Audit Planning Project

West Virginia University — CYBR 510

Developed an IT audit planning document focused on vulnerability management and control review, incorporating NIST CSF 2.0 and NIST SP 800-171 concepts to support structured audit preparation.

Tools: NIST CSF 2.0, NIST SP 800-171

Focus: Audit planning, control assessment, vulnerability management review

Deliverables: Audit plan, scope definition, control mapping

Security Reports & Deliverables

Professional-grade incident reports and security documentation produced as part of hands-on investigations.

Security Incident Report — Azure AD Credential Compromise

Incident ID: INC-2026-0322-001 | Severity: HIGH | Status: Contained

Formal incident report documenting a vishing-based credential compromise of a Microsoft 365 account. Covers full attack narrative, Entra ID sign-in log analysis, MITRE ATT&CK mapping, Zero Trust remediation actions, IOCs, and executive business impact assessment.

Scope: Cloud identity compromise, unauthorized group creation, privilege escalation attempt

Frameworks: MITRE ATT&CK (T1566.004, T1078, T1098, T1069), Zero Trust, NIST CSF

Deliverable: Executive-level incident report with full log evidence, IOCs, and remediation steps

MDR Executive Report — Endpoint Malware & Lateral Movement

Client: Lumen Soda, Inc. | Prepared for: CEO | Role: Junior MDR Analyst

Executive-level MDR report delivered to a CEO summarizing a multi-stage malware infection, lateral movement to a remote host, and ransomware-style file creation. Translates forensic Procmon findings into clear business impact, root cause, and actionable remediation steps.

Scope: Dropper execution, second-stage payload, lateral movement to ADMIN-21139, remote file impact

Tools: Sysinternals Procmon, Windows endpoint forensics

Deliverable: Non-technical executive summary with prioritized remediation recommendations

My Credentials

Resume & Certifications

Resume

Certification

CompTIA Security+ (SY0-701)

Get in Touch

Contact Me

I am open to GRC, third-party risk, security compliance, IT audit, and cybersecurity analyst opportunities in Chicago or remote.