Balboa Travel, Inc.Security Analyst & Data Protection Officer
May. 2023San Diego, California, United StatesIn addition to serving as Data Protection Officer, I currently operate in multiple capacities, including Helpdesk Technician, Network Engineer, Systems Administrator, Information Security Analyst, Security Operations Center (SOC) Analyst, Cybersecurity Compliance Analyst, and GRC Analyst—providing end-to-end security and IT solutions for the organization. Oversaw all aspects of data protection, information security controls, and monitoring systems, ensuring adherence to GDPR, SOC 2, and ISO 27001 frameworks. Developed and implemented policies and procedures to safeguard sensitive data, minimize risk, and maintain regulatory compliance. Key accomplishments: -- Ensured compliance with GDPR, SOC 2, and ISO 27001 frameworks, developing and implementing comprehensive data protection and information security policies and procedures. -- Conducted Data Protection Impact Assessments (DPIAs) for high-risk data processing activities, identifying and mitigating potential risks to data privacy. -- Maintained a comprehensive Record of Processing Activities (ROPA), documenting all data processing operations and ensuring transparency and accountability. -- Developed and delivered data privacy training programs for employees, fostering a culture of data protection and ensuring compliance with regulations. -- Managed data breach incidents, including reporting to relevant authorities and affected individuals, and implementing corrective actions to prevent future occurrences. -- Established and modernized information security controls and monitoring systems, performing regular tasks such as daily log review, weekly threat intelligence review, monthly certificate review and revocation, monthly vulnerability remediation planning, quarterly Wi-Fi scanning, quarterly asset inventory, quarterly user inventory, quarterly access review, and semi-annual firewall policy review.