Nsikak Ukpe

Nsikak Ukpe

Snr’ Governance, Risk & Compliance Analyst (TPRM) @ IBM

About

Senior IT Risk & GRC Analyst specializing in enterprise risk management, cybersecurity governance, and regulatory compliance across complex technology environments. Experienced in aligning security controls with industry frameworks such as NIST and COBIT, while leading control assessments, risk remediation initiatives, and audit readiness efforts across cloud and on-premise infrastructures (PaaS, SaaS, IaaS). Recognized for strengthening risk visibility, guiding stakeholders on security best practices, and safeguarding sensitive PII through disciplined governance and regulatory adherence.

Country

United States

City

Houston

Industry

Information Technology & Services

Skill

IT Audit, Audit documentation, SOX Compliance, ITGC, Control Testing, Risk & Controls Assessment, HITRUST, NIST 800-53, HIPAA Security and PHI protection, SAI360, Third-Party Vendor Management, Agile framework, Nist cybersecurity Framework, Iso/IEC 27001, RSA Archer, Vulnerability Management, Vulnerability Assessment, Threat & Vulnerability Management, Servicenow GRC, Communication and collaboration

Experience

IBM

Snr’ Governance, Risk & Compliance Analyst (TPRM)

IBM

LinkedIn
2023-8 - 2026-2 · 2 yrs 7 mos

Houston, Texas, United States

- Led comprehensive third-party cybersecurity risk assessments during vendor onboarding and annual reviews, evaluating security policies, procedures, and incident history for 100+ vendors across regulated environments. - Implemented contractual cybersecurity requirements and continuous monitoring controls for third-party vendors, driving remediation of audit findings and reducing high-risk vendor gaps by approximately 30–40% year over year. - Conducted PCI-relevant vendor risk assessments by reviewing SOC 2 reports, SDLC documentation, and encryption standards; partnered with IT and business teams to achieve on-time PCI-DSS and SOX compliance targets. - Automated vendor vulnerability management and continuous monitoring workflows using ProcessUnity, improving risk visibility and remediation tracking while reducing manual assessment effort by 40%+. - Leveraged RSA Archer, ServiceNow GRC, and ProcessUnity analytics to centralize vendor risk scoring, issue tracking, and executive reporting across third-party risk portfolios. - Performed development, maintenance, and continual improvement of the vulnerability management platform and processes; utilized infrastructure and cloud vulnerability scanning tools such as OpenVAS and Nessus; prioritized new vulnerabilities based on operating environment, risk severity, and data classification policies. - Conducted Business Impact Analyses (BIA) to identify critical functions and dependencies, developed and tested Business Continuity Plans (BCPs) aligned with IT Disaster Recovery (DR) strategies, and strengthened risk governance by defining 2LOD responsibilities, developing risk monitoring frameworks, and enhancing policy oversight, risk appetite alignment, and regulatory compliance checks across risk and compliance functions.

Roblox

Cybersecurity Governance/Risk Analyst

Roblox

LinkedIn
2020-11 - 2023-7 · 2 yrs 9 mos

Houston, Texas, United States

- Evaluated governance and regulatory procedures for Vendor IT SOX audits and assessed client risk management frameworks to identify third-party vendor vulnerabilities and validate mitigation effectiveness. - Conducted comprehensive IT risk assessments, following industry standards such as NIST (National Institute of Standards and Technology) and ISO 27001 to identify and assess potential risks across technology systems, processes, and projects. - Conducted RAL Assessments as one of the By Design processes for enterprise, product and service offers. Identify findings and create new action item in RAL. Where gaps cannot be remediation launch new RAL2 with previous RAL catchup and create action item assigned to Engagement Manager to complete with a due date. - Developed and enforced security policies and procedures related to access control management, ensuring compliance with industry standards and regulatory requirements. - Launched new findings reports and assigned to Eng manager and TPS to review security controls. - Led enterprise-level PCI-DSS self-assessments and audits, focusing on secure vendor integrations and application controls. - Developed and maintained PCI-compliant policies around access control, data encryption, and secure SDLC processes. - Reviewed penetration tests and vulnerability scans to ensure secure handling of payment data. - Validated AI/ML vendor tools for PCI risk, reviewing data flows and TLS 1.2+ encryption. - Coordinated internal and external PCI and SOX audits, managing evidence collection and auditor responses. - Worked with the business leaders to reduce the number of open third-party assessment gaps. - Reviewed vendor penetration test report to identify security findings, remediation plans by reviewing copy of the latest vulnerability assessments and penetration report performed by a qualified external party. - Conducted internal and external security audits based on standard cybersecurity frameworks from ISO 27002

UnitedHealth Group

Cyber security Risk Analyst

UnitedHealth Group

LinkedIn
2018-5 - 2020-10 · 2 yrs 6 mos

Houston, Texas, United States

- Collaborated with the leaders to reduce the number of open third-party assessment gaps. - Performed fair risk assessment for business vendor, identify risk, gather information, assess risk to identify severity, prioritize risk base on the severity, develop mitigation strategy, also provide an avenue in which we can have continuous monitoring on risk. - Performed fair risk assessment utilizing Risklens, understanding business KPI (Key progress indicators) and KRI Key risk Indicator to be able to quantify cyber risk assessment. Also used PowerBI for reporting - Performed Fair risk assessment using different fair risk tools, such as Risk assessment Matrix, scenarios analysis, cost-benefit analysis, mitigation analysis, quantitative analysis, SWOT. - Performed Fair risk using while considering different risk factor such as, probability of risk, vulnerability, mitigation external factor, cost benefit, and providing my reports in PowerBI with stakeholders or business unit. - Updated the controls changes from NIST-800 53 rev 3 to NIST-800 53 rev 4 and control assessment changes from NIST-800 53A to NIST 53A rev4. - Developed and implemented security policies and standards, aligning with COBIT frameworks and GRC programs. - Provided recommendations to minimize vendor risk and follow-up to ensure remediation plans are timely, effective, and appropriately implemented. - Conducted cyber security risk assessments on Third Parties and document gaps in security in the provided GRC tool SAI 360, Archer and ServiceNow - Conducted comprehensive audits and assessments, proactively identifying vulnerabilities, and implementing corrective measures to fortify access Campaigns protocols. - Participated in the status meeting and & discussed issues related to SailPoint Identity IQ with the group. - Determined the overall effectiveness of the controls, based on criteria from NIST 800-53 security controls.

HealthPlus Medical & Diagnostic Clinic, Inc.

Cyber security Risk Analyst

HealthPlus Medical & Diagnostic Clinic, Inc.

LinkedIn
2018-4 - 2020-10 · 2 yrs 7 mos

Houston, Texas, United States

- Collaborated with senior leadership to reduce open third-party assessment gaps by performing FAIR-based cyber risk assessments on vendors, identifying risks, prioritizing them by severity, and recommending mitigation strategies and continuous monitoring approaches. - Performed quantitative cyber risk assessments using FAIR methodology and tools (RiskLens, risk assessment matrix, scenario analysis, cost-benefit and mitigation analysis, SWOT, quantitative analysis), leveraging business KPI and KRI to quantify cyber risk and present results via Power BI reporting. - Conducted third-party and technology cyber security risk assessments using SAI360, Archer, and ServiceNow, documenting security control gaps, determining overall control effectiveness against NIST 800-53/800-53A criteria, and providing recommendations to minimize vendor risk and track remediation to closure. - Updated and aligned control frameworks and security documentation from NIST 800-53 rev 3 to rev 4 and from NIST 800-53A to 53A rev 4, and developed/implemented security policies and standards in alignment with COBIT, GRC programs, PCI DSS, ISO 27001, and internal corporate governance requirements. - Designed and implemented access control and identity security measures, including AWS IAM policies, IAM roles based on least privilege, MFA, SSO (Okta, OneLogin, Azure AD), and SailPoint IdentityIQ access campaigns; analyzed and granted access rights for audits, risk and compliance assessments using Archer and SAI360. - Supported cloud security and compliance by conducting AWS, Google Cloud, and Azure security risk assessments, using AWS CloudTrail for security audit compliance and API monitoring, applying AWS KMS for encryption and key management, and providing remediation recommendations for identified gaps.

Amazon

IT Audit Intern

Amazon

LinkedIn
2017-10 - 2018-3 · 6 mos

Austin, Texas, United States

- Supported IT audit engagements by reviewing access controls, system configurations, and compliance with internal governance standards. - Assisted in evaluating IT general controls (ITGCs) across user access management, change management, and incident response processes. - Conducted documentation reviews and walkthroughs to identify control gaps and improvement opportunities. - Collaborated with audit and cybersecurity teams to assess risk exposure and support remediation tracking. - Helped prepare audit evidence, testing reports, and control summaries for stakeholder review. - Gained hands-on exposure to regulatory and cybersecurity frameworks such as SOX, NIST, and ISO 27001. - Participated in vendor and third-party risk discussions by supporting questionnaire reviews and control validation. - Contributed to improving audit readiness by ensuring accurate recordkeeping and compliance documentation.

Education

New Bulgarian University

New Bulgarian University

LinkedIn

International business communication

2018-1 - Present · 8 yrs 9 mos

Nsikak Ukpe's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.