GRC Analyst (Compliance Fellowship) — West Virginia University CRRC
May 2026 – August 2026 | Morgantown, WV
- Designed and authored a suite of structured GRC training courses for the CRRC program, including a 20-lesson RBAC/IAM Governance course, Vendor Risk Management, ISO 27001 Foundations, SOC 2, Vulnerability Management, and a security awareness curriculum covering phishing, MFA, and social engineering.
- Built the Vendor Risk Management course using real third-party assessment artifacts, including vendor tiering, security questionnaires (CAIQ), control mapping (GLBA and PCI DSS), and POA&M remediation tracking to demonstrate the end-to-end third-party risk lifecycle.
- Translated security and compliance requirements into plain-language policies, standards, and training aligned with CISA best practices while coordinating delivery across student teams, faculty mentors, and partner organizations supporting West Virginia critical infrastructure.
Client Engagement — Bridle Paths
Information Security Analyst Intern (Governance and Compliance) | Project Lead
May 2026 – August 2026 | Loudoun County, VA
- Led the governance and compliance workstream for a 54-module HIPAA-regulated CRM engagement, authoring the audit plan and directing field-level access-control validation across 32,100+ field/profile permission combinations and 680 access rules.
- Raised configuration compliance from 51.5% to 97.8% before production deployment and led structured validation and stakeholder review of 315 access-control remediation items, reducing unresolved findings from 322 to 7.
- Designed the SEC-01 field-level security matrix mapping 10 operational profiles to 6 PHI data-sensitivity groups and enforcing least-privilege access aligned to NIST 800-53 AC-6(1).
- Built the master configuration inventory and reviewer change history and authored CRM administration and operational governance documentation covering permissions, change management, deployment, rollback, incident response, and audit evidence.
- Built Python automation using the Zoho CRM REST API and OAuth 2.0 to reconcile live CRM metadata, validate RBAC configurations, and generate executive analysis, configuration inventories, and audit-ready evidence that passed independent technical verification.