Avery Singh Senior GRC Analyst
McLean, VA • grcanalyst@gmail.com • +1 703-555-0188
Profile Summary
- Senior GRC Analyst with 7 years of experience running regulated and federal-contracting environments across federal contracting, SaaS, and financial services, specializing in multi-framework compliance, risk management, and audit readiness.
- Hands-on coverage across compliance frameworks (SOC 2, ISO 27001, FedRAMP), risk frameworks (NIST CSF), GRC platforms (ServiceNow GRC, Vanta), third-party risk (OneTrust), privacy (GDPR), and analytics (SQL, Excel (advanced)) with strong fundamentals in control-narrative writing, evidence-collection rigor, and audit-ready documentation.
- Deep expertise in risk-based prioritization, continuous control monitoring, evidence-as-code automation, and framework-mapping rigor, leveraging methodologies such as NIST RMF and ISO 31000 risk methodologies and quarterly control-effectiveness reviews to drive audit-ready compliance posture and a defensible risk narrative for the board.
- Engaged collaborator working cross-functionally with Engineering, IT, Legal, and Procurement teams in regulated SaaS and federal-contractor environments, contributing to risk committees, vendor reviews, and audit war-rooms with a calm, evidence-first temperament.
- Emerging leader who shares technical excellence and fosters a culture of evidence completeness and control-documentation discipline through peer reviews and runbook authoring, while leading GRC enablement workshops and authoring widely used policy and control-narrative templates.
Technical Skills
- Compliance Frameworks:
- SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, FedRAMP Moderate, NIST 800-53, NIST 800-171, CMMC Level 2
- Risk Frameworks & Methodology:
- NIST CSF, NIST RMF, ISO 31000, FAIR, COSO ERM, CIS Controls v8
- GRC Tooling & Platforms:
- ServiceNow GRC, RSA Archer, Vanta, Drata, Secureframe, Hyperproof, AuditBoard, Workiva
- Audit & Control Operations:
- Control narrative authoring, evidence packaging, walkthroughs, deficiency tracking, control testing, POA&M
- Third-Party Risk:
- OneTrust Vendorpedia, ProcessUnity, BitSight, SIG, CAIQ, SOC 1/SOC 2 review
- Privacy & Data Protection:
- GDPR, CCPA, HIPAA, DPIA authoring, DSAR workflows, data mapping, breach-notification protocols
- Reporting & Analytics:
- KRI/KPI dashboards, board-level reporting, Power BI, Tableau, audit-summary writing
- Languages & Productivity:
- SQL, Python (basic), PowerShell, Excel (advanced), Jira, Confluence
Education
Work Experience
- Own compliance framework operations across federal-contracting environments spanning 10 product lines across DoD and civilian agencies, running FedRAMP Moderate, CMMC Level 2, and NIST 800-53 Rev 5 as 4 concurrent compliance programs.
- Drive enterprise and IT risk management for 150+ tracked risks in the register, applying NIST RMF scoring with annual top-down assessments and threat-informed treatment recommendations across 4 strategies (accept, mitigate, transfer, avoid).
- Maintain the security and IT policy library across 45+ policies, standards, and procedures, running regulatory alignment reviews and annual recertification cycles, with adoption across 12 business units.
- Lead internal and external audit coordination across 8 cycles per year, running auditor walkthroughs, evidence collection, and finding remediation; delivered SOC 2 Type II and FedRAMP ATO renewals with zero significant findings.
- Own control design, testing, and continuous monitoring across 320+ in-scope controls, authoring control narratives against NIST 800-53 with operating-effectiveness testing and compensating-control documentation, lifting control effectiveness from 87% to 99%.
- Led the GRC platform rollout on ServiceNow GRC and Vanta, shipping evidence-collection automation against AWS and Okta, control-status dashboards, and Jira integrations for finding workflows; compressed the audit-prep cycle from 6 weeks to 9 days.
- Produce compliance posture and risk reporting on a quarterly cadence to the Risk Committee and board, delivering KRI and KPI dashboards, plain-language risk narratives, and audit-finding summaries; translated posture into board-ready briefings that shifted leadership investment by $2.4M.
- Ran the third-party and vendor risk program across 220+ vendors through SIG and CAIQ questionnaire reviews, SOC 1 / SOC 2 report analysis, and contract-clause reviews with Legal and Procurement; flagged 30+ critical findings that drove contract renegotiations and tier-downgrade decisions.
- Supported the privacy and data-protection program across 60+ data-subject access requests, running GDPR and CCPA gap assessments, data mapping, and DPIA authoring; partnered with Legal and the DPO to close a regulator finding within 90 days.
- Delivered security awareness and stakeholder enablement through annual all-hands training, targeted phishing and tabletop sessions, and compliance office hours reaching 4,500+ employees across 6 client engagements, partnering with Engineering, IT, HR, and Legal to ship 12 client-specific control documents and onboard 4 junior GRC analysts.