Hazel C.
Compliance Analyst | ISO 27001 Internal Auditor
I am a Certified ISO 27001 Information Security Internal Auditor, ISO 27701 Privacy Lead Implementer, Certified in Cybersecurity (CC) provided by ISC2, and a Certified Public Accountant (CPA). I have more than 14 years of diverse experience with a focus on information security, data privacy, risk assessment, IT governance, and audits (internal audits, IT audits, and compliance audits). I have helped companies obtain their ISO 27001 Certification. and I have also performed various IT and compliance audits, such as: - Led and performed Information Security Assessments/ Audits using ISO/ IEC 27001 and 27002 (both 2013 and 2022 version) - Led and performed Privacy Information Management System audits - Perform SOC2 Type 1 and 2 audits - Document and maintain Information Security Management System (ISMS) policy and procedure documents - Conduct Information Security Awareness training - Conducted security assessments and audits based on different security frameworks such as NIST, SOC 2, GDPR and HIPAA, and crafting PCI DSS templates - Lead data privacy audits and advisory/ consulting services. - Performed IT Governance Maturity Assessment using COBIT - Knowledge and performs auditing of IT general and application controls such as Change Management, Identity and User Access Management and Password Logins, Information Security, and Data Privacy - Implemented governance processes and frameworks (including IT Governance and Data Governance)