Fatukesi Olumide

Cybersecurity GRC Analyst
Lagos, NG.

About

Highly detail-oriented GRC Analyst with practical experience in establishing robust risk management, compliance, and information security frameworks, particularly for startups. Proficient in ISO27001, NIST, GDPR, and NDPR principles, adept at conducting internal control assessments and driving organizational resilience. Proven ability in identifying security threats, developing comprehensive policies, and communicating complex technical concepts effectively to enhance cybersecurity posture.

Work

MasterCard (via Forage Virtual Experience Program)
|

Cybersecurity Analyst (Virtual Experience)

Summary

Participated in a comprehensive job simulation as an analyst on MasterCard's Security Awareness Team, gaining practical experience in cybersecurity operations.

Highlights

Conducted in-depth analysis as a Cybersecurity Analyst within MasterCard's Security Awareness Team during a virtual job simulation.

Identified and reported critical security threats, including sophisticated phishing attempts, contributing to enhanced organizational security.

Analyzed business areas to identify security training gaps, subsequently developing and implementing targeted training courses and procedures to strengthen overall security posture.

Datacom (via Forage Virtual Experience Program)
|

Cybersecurity Risk Analyst (Virtual Experience)

Summary

Engaged in a job simulation focused on cybersecurity risk assessments and mitigation strategies, improving client cybersecurity posture.

Highlights

Performed comprehensive risk assessments by investigating a simulated cyberattack, enhancing understanding of threat identification.

Developed expertise in assessing diverse threat landscapes, prioritizing risks, and implementing critical security measures such as Multi-Factor Authentication (MFA) and penetration testing.

Prepared and presented comprehensive documentation and strategic recommendations, significantly improving client cybersecurity posture and demonstrating effective technical communication.

Languages

English

Fluent

Certificates

ISO/IEC 27001:2022 Lead Auditor

Issued By

Mastermind

Cybersecurity Professional Certificate

Issued By

Self-study/Various Resources

ISO/IEC 27001:2022 Information Security Management Systems

Issued By

SBP

Cybersecurity Foundation in GRC

Issued By

LinkedIn Learning

ISO/IEC 27001:2022 Information Security Associate

Issued By

Skill Front

Leveraging AI for GRC

Issued By

LinkedIn Learning

HIPAA Compliance Program

Issued By

Unknown

PCI DSS 4.0 Compliance

Issued By

Unknown

Skills

Risk Management

Risk Assessment, Risk Identification, Risk Mitigation Planning, Threat Landscape Analysis.

Compliance Frameworks

ISO/IEC 27001:2022, NIST, GDPR, NDPR, Regulatory Compliance.

IT Governance & Policy

Policy Drafting, Documentation, IT Governance, Data Protection, Privacy Policy.

Audit & Control Testing

Internal Audit, Compliance Checklists, Control Testing, Security Posture Assessment.

Analytical & Reporting

Analytical Skills, Research, Report Writing, Technical Documentation.

Security Awareness Training

Security Education, Awareness Programs, Phishing Awareness.

Vendor Risk Management

Third-Party Risk Assessment, Vendor Due Diligence.

Microsoft Office Suite

Excel, PowerPoint.

Active Directory

Configuration, Administration.

Cross-functional Collaboration

Communication, Teamwork, Stakeholder Engagement.

Projects

ISO 27001:2022 Audit Checklist Development

Summary

Developed and implemented a structured audit checklist aligned with ISO/IEC 27001:2022 controls to assess the security posture of a simulated environment. Conducted mock internal audits to evaluate the effectiveness of existing controls across various domains.

Data Protection and Privacy Policy Implementation

Summary

Developed and implemented a data protection and privacy policy aligned with ISO/IEC 27001:2022 and NDPR principles, focusing on access control, data minimization, and retention policies. Demonstrated hands-on capability in security monitoring, policy enforcement, and privacy compliance.