
Eva Obeng Anson
Information Security Analyst

Connect with Eva Obeng Anson to Send Message
Connect
Connect with Eva Obeng Anson to Send Message
ConnectTimeline
About me
Information Technology Auditor
Education

Katherine Gibb College
2000 - 2002Associate's degree Liberal Arts and Sciences/Liberal Studies
Experience

Kairos Vision Consult
Mar 2013 - Jun 2020Information Security Analyst• Documented audit findings and developed thorough and creative recommendations for business and process owners to mitigate identified risks.• Conducted IT audit fieldwork and walk through of controls; performed detailed testing, analysis of controls, validations, and creation of clear, accurate documentation of workflows in IT process and report of test results and exceptions. • Provided analysis and conducted virtual risk assessment to continuously determine the security posture at the vendor site.• Worked with IT compliance management to ensure appropriately designed controls are implemented for all in-scope entities and divisions and perform testing to validate their operating effectiveness throughout the fiscal year.• Documented progress towards HIPAA Privacy and Security Rules implementation and monitor the status of the organization´s HIPAA compliance.• Monitor information system activities for suspicious events such as logins, administrative rights usage, abandoned sessions or their vulnerabilities.• Performed internal and external IT risk assessments using applicable Risk Matrix templates, Risk Assessment Matrix, Risk Control Self –Assessment and Risk Management life cycle and provided recommendations on mitigation options.• Worked with IT compliance management to ensure appropriately designed controls are implemented for all in-scope entities and divisions and perform testing to validate their operating effectiveness throughout the fiscal year.• Tracked compliance processes such as remediation plans, exception/variance handling, audit requests, and recurring audit reviews to ensure timely completion.• Generated reports, presentations, documents, and other collateral to present assessment updates to senior leadership.• Worked with key stakeholders, leadership, business units, and other internal and external constituents to evaluate and manage information security assessments. Show less

PwC
Jul 2020 - nowEffectively communicate with multiple clients to perform Risk register remediation; handle internal communications within the Office of Information Security and external communications with several different divisions daily. Maintain excellent working relationships with both internal and external clients .• Conduct IT audit fieldwork and walk through of controls; perform detailed testing, analysis of controls, validations, and creation of clear, accurate documentation of workflows in IT process and report of test results and exceptions.• Ensures that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments.• Maintain up-to-date detailed knowledge of the IT security industry including awareness of new or revised security solutions, improved security processes, and the development of new attacks and threat vectors. • Monitor information system activities for suspicious events such as logins, administrative rights usage, abandoned sessions or other vulnerabilities.• Participate in activities across the company, including the Third-Party Risk Management (TPRM) lifecycle and Enterprise Risk Management (ERM).• Lead and support the preparation of client reporting deliverables, e.g., gap and risk assessments, SOC reporting, GDPR assessments, ISO 27001 certifications, etc.• Partner cross-functional, inter-departmental and with the internal and external auditors• Prepare audit plan and report detailed results of audits; provide written recommendations to clients.• Partake in reviewing regulatory reports, SOC reports, certificates of insurance, and other reports associated with vendors included in the vendor program and escalate issues to the appropriate individuals.• Validate system requirements, security policies and procedures, contingency plans, incident response plans, personnel security, access control mechanisms and identification and authentication mechanisms. Show less
Information Technology Auditor
Jun 2020 - nowInformation Technology Security Analyst
Jul 2020 - now
Licenses & Certifications

Certified Information Systems Auditor (CISA)
ISACA
CompTIA Security+
CompTIA Security Plus
Recommendations

Juan francisco salvador garcía prieto
Gerente comercial banca segurosMexico City Metropolitan Area
Gabriel marques
Software Engineer | .NET | NodeJs | SQL | NoSQLContagem, Minas Gerais, Brasil
Yukta pathak
Designer : : Engineer MA/ MSc Innovation Design Engineering Royal College of Art/ Imperial College...United Kingdom
Akinade akinadeniyi
Senior Product Designer | Designlab & ADPList MentorLagos State, Nigeria.webp)
Isabella siler (turner)
Product Specialist at DowGreater Saginaw-Midland-Bay City Area
Piotr lis, phd
Engineer | ResearcherWarsaw, Mazowieckie, Poland
Lakshmi suraj gadiraju
Student at KG Reddy College of Engineering and TechnologyHyderabad, Telangana, India
Miguel salcedo
Service Delivery Manager at SansayDominican Republic
周天宇
沈阳天宇智能设备 - CEOShenyang, Liaoning, China
Lance barnhart
ECommerce Content Manager at MGM ResortsHenderson, Nevada, United States
Lauren frisbie, mph
Epidemiologist II at the Washington State Department of HealthSeattle, Washington, United States
Lauren mccallister
Senior Client Consultant at Jackson & Coker | Anesthesia DivisionAtlanta, Georgia, United States
Himanshu khurana
DGM- Business Operations at HomeScape by Amplus | Ex- ZunRoof, Wishup.coDelhi, India
Colt knight
Associate Extension Professor - State Livestock Specialist at University of MaineOrono, Maine, United States
Ece beyazıt
UNDP Türkiye şirketinde Project AssociateAnkara, Türkiye
Marius navickas
Head of R&D at DextallVilnius, Vilniaus, Lithuania
Mathieu rathbeger
Analyste en Ingénierie FinancièreGreater Lyon Area
Fernanda corrêa da costa
Coordenadora de Projetos na Neon | Especialização em Inovação e Empreendedorismo | Certificado Green...Campo Bom, Rio Grande do Sul, Brazil
Rimmon semere
Aspiring Software Engineer | Computer Science | @ Purdue UniveristyInterstate Business Solutions, LLC
樊世茂
Senior Customer Service Engineer - Hermes-Epitek Corporation Pte LtdDaxing District, Beijing, China
...