Skills

  • GRC
  • IT Audit
  • Information security
  • CYBERSECURITY ANALYST
  • IT Risks Management
  • think tank
  • not for propit management
  • SOC Analyst
  • vendor risk management
  • Third party Audits
  • Privacy / GDPR
  • COSO
  • COBIT
  • compliance and risk management
  • HIPAA
  • PCI DSS
  • iso
  • NIST

Experience

Charles Hagan

Work experience
  • Information Security & Compliance Analyst  at   Ernst & Young
  • Developed and implemented security frameworks aligned with ISO 27001, NIST, and COBIT standards to enhance data protection and regulatory compliance across all systems and processes, leading to a significant reduction in potential security vulnerabilities.
  • Conducted comprehensive risk assessments by identifying, evaluating, and mitigating potential security risks through structured methodologies such as risk matrices and control frameworks, improving the organization's risk management by 40%.
  • Established and optimized internal controls for SOX compliance, conducting regular audits to ensure adherence, which contributed to a 25% improvement in compliance scores and reduced the likelihood of audit findings.
  • Spearheaded the design and delivery of cybersecurity awareness training for new hires and ongoing sessions for existing employees, increasing company-wide security awareness and reducing security incident reports by 20%.
  • Collaborated with cross-functional teams, including IT, legal, and compliance, to revise and enhance security policies and procedures, aligning with new regulatory requirements such as PCI DSS, HIPAA, and GDPR, resulting in a comprehensive, up-to-date security policy suite.
  • Led vulnerability assessments and penetration testing exercises, identifying potential threats and working with IT teams to implement remediation strategies, which improved system resilience and reduced threat exposure.
  • Actively participated in incident response and management, including investigating security breaches, coordinating with IT to contain incidents, and conducting post-incident reviews to refine protocols and prevent recurrence.
  • Monitored regulatory changes and emerging cybersecurity threats to proactively update controls and security measures, ensuring the organization remains compliant and well-protected against new risks.
  • Developed and presented monthly compliance and risk management reports to senior management, outlining key findings, improvement areas, and actionable insights to guide security-related decision-making.
  • Established vendor risk management protocols to assess and monitor third-party compliance, security controls, and data handling practices, strengthening the organization’s security posture in supply chain interactions.
  • Contributed to the organization’s project management by leading security-focused projects, coordinating timelines, resources, and objectives to implement new security tools and technologies effectively

Related persons

Martin Ocloo forex trading and crypto trading