Security+ certified cybersecurity professional transitioning into Governance, Risk & Compliance (GRC), IT Risk, and Third-Party Cyber Risk Management. My background combines IT support, technical troubleshooting, business operations, and stakeholder communication with a growing cybersecurity foundation.
Currently completing an A.S. in Cybersecurity / Digital Forensics & Incident Response at Coastline Community College with a 4.0 GPA. I am developing hands-on GRC skills in vendor risk assessment, NIST CSF 2.0, security controls, SOC 2, ISO/IEC 27001, risk identification, and risk-based recommendations.
| Certification | Issuer | Status |
|---|---|---|
| CompTIA Security+ | CompTIA | β Certified |
| CompTIA A+ | CompTIA | β Certified |
| CompTIA Network+ | CompTIA | β Certified |
| ISC2 Certified in Cybersecurity (CC) | ISC2 | β Certified |
| Microsoft SC-900 | Microsoft | β Certified |
| Microsoft Azure Fundamentals (AZ-900) | Microsoft | β Certified |
| Google IT Support Professional | β Certified | |
| CompTIA Linux+ | CompTIA | π In Progress |
Associate of Science in Cybersecurity / Digital Forensics & Incident Response
GPA: 4.0 | Expected Spring 2027
Coastline Community College | Orange County, CA
Phi Theta Kappa Honor Society β Beta Psi Alpha Chapter
Bachelor of Arts in Business Administration β Cum Laude
Temple University, Fox School of Business | Philadelphia, PA
- Third-Party Cyber Risk Management (TPRM) and vendor security assessment
- NIST Cybersecurity Framework (CSF) 2.0
- Cybersecurity risk identification, scoring, and remediation
- SOC 2 and security control evidence review
- ISO/IEC 27001 fundamentals
- Building my first hands-on Third-Party Cyber Risk Assessment portfolio project
- Linux and cybersecurity coursework at Coastline Community College
I am currently building practical GRC projects that demonstrate cybersecurity risk assessment, control evaluation, third-party risk analysis, and risk-based communication.
Mock vendor cybersecurity assessment covering:
- Vendor security questionnaire review
- SOC 2 evidence review
- Identity and access controls
- Risk identification and scoring
- Security findings
- Remediation recommendations
- Executive risk communication
Status: In progress. Project artifacts will be published upon completion.
Cybersecurity GRC | IT Risk | Third-Party Risk Management
Target opportunities:
- Cybersecurity GRC Analyst
- GRC Analyst
- IT Risk Analyst
- Technology Risk Analyst
- Third-Party Risk Analyst
- Vendor Risk Analyst
- Security Compliance Analyst
- Security Assurance Analyst
- IT Controls Analyst
Long-term focus: combining cybersecurity technical knowledge, business experience, and stakeholder communication to identify, assess, communicate, and manage technology risk.
My technical projects support my GRC development by strengthening my understanding of the systems, security controls, identity environments, and technical risks that GRC professionals assess.
| Repository | Focus |
|---|---|
| azure-iam-labs | Microsoft Azure and identity/security lab work |
| sc-300-identity-labs | Identity and access management study/lab work |
| cybersecurity-labs | Cybersecurity lab exercises |
| python-scripts | Python coursework and scripting practice |
| linux-labs | Linux administration exercises |
| incident-response-labs | Incident response and cybersecurity exercises |
| security-plus-notes | Security+ study materials |
| kenneth-scott-portfolio | Professional cybersecurity portfolio |