E

Engelbert Sama, MSc -.

Operations Associate

United States5 yrs experience

Key Highlights

  • Over 10 years of experience in Information Security.
  • Expertise in Third-Party Risk Management and compliance.
  • Strong military background enhancing strategic project execution.
Stackforce AI infers this person is a Cybersecurity professional specializing in Third-Party Risk Management within the Financial Services sector.

Contact

Skills

Core Skills

Third Party Risk Management (tprm)It Vendor Risk Assessment

Other Skills

ProcessUnityAttention to DetailISO 27001SOC 2Third-Party Vendor ManagementCommunicationQuestionnairesContract RequirementsReview of Outside Counsel GuidelinesLogistics ManagementData EntryCyber-securityVulnerability ScanningRisk AssessmentRisk Analysis

About

As an Information Security Analyst with over 10 years of diverse experience in Governance, Risk, and Compliance (GRC), I specialize in Third-Party Risk Management. Throughout my career, I have successfully implemented and helped companies build robust risk management programs that safeguard critical assets and ensure compliance with industry standards and regulations. My expertise lies in conducting thorough vendor risk assessments, developing risk mitigation strategies, and fostering a culture of security awareness across organizations. In addition to my professional accomplishments, I am a proud US Citizen who has served in the US Army, bringing a disciplined and strategic approach to every project I undertake. My service has instilled in me a strong sense of duty, integrity, and teamwork, which I apply to my work in the field of information security. I hold a Secret Clearance, underscoring my commitment to maintaining the highest levels of confidentiality and trust. My background includes collaborating with cross-functional teams to identify and manage risks, conducting continuous assessments of current vendors, and responding to detailed security questionnaires. With a proven track record of enhancing security postures and reducing vulnerabilities, I am dedicated to helping organizations navigate the complex landscape of third-party risk and achieve their security and compliance goals.

Experience

5 yrs
Total Experience
1 yr 8 mos
Average Tenure
--
Current Experience

C4 technical services consultant

Third-Party Risk Analyst

Nov 2024Nov 2025 · 1 yr

Silicon valley bank

Third-Party Risk Specialist

Nov 2023Nov 2024 · 1 yr · Remote

  • As a Third-Party Risk Specialist at Silicon Valley Bank through Vaco, I conducted thorough risk assessments, identifying and mitigating security and compliance risks with high-risk vendors. I collaborated across teams to ensure contracts met security requirements and developed actionable mitigation strategies. I also reported regularly to leadership, enhancing the overall third-party risk management framework.
Third Party Risk Management (TPRM)ProcessUnity

Ripple

Third-Party Security Analyst

Jul 2022Sep 2023 · 1 yr 2 mos · California, United States · Remote

  • As a Third-Party Security Analyst Consultant at Ripple through Eastridge, I conducted thorough security assessments of vendors, identifying and mitigating potential vulnerabilities. I facilitated incident response and remediation efforts, ensuring timely risk mitigation. Additionally, I collaborated with internal teams to integrate security controls into vendor contracts, enhancing Ripple’s overall third-party security posture.
Third Party Risk Management (TPRM)IT Vendor Risk Assessment

Confluent

IT Security Analyst

May 2020May 2022 · 2 yrs · United States · Remote

  • At Confluent, I led third-party onboarding security reviews, ensuring vendors met minimum security standards. Collaborated with the application security team to secure third-party integrations for data confidentiality, integrity, and availability. Managed annual reassessments, archived security artifacts in OneTrust and Ironclad, and responded to security inquiries. Worked with federal entities on NIST-800-171 and CMMC assessments.
ISO 27001SOC 2Third-Party Vendor ManagementThird Party Risk Management (TPRM)

Deloitte

TPRM Security Analyst

Nov 2019Apr 2020 · 5 mos · Remote

  • As a TPRM Security Analyst Consultant for Artech working for Deloitte, I developed and implemented third-party risk management frameworks, conducting security assessments to identify vulnerabilities and recommend mitigation strategies. I collaborated with legal, procurement, and IT teams to integrate security requirements into vendor contracts and provided detailed reports to leadership to support data protection and compliance.
IT Vendor Risk Assessment

Polsinelli

IT Compliance & Security Analyst

Jun 2017Sep 2019 · 2 yrs 3 mos · Kansas City, Missouri Area · On-site

  • As an IT Compliance & Security Analyst at Polsinelli, I coordinated vendor risk assessments, ensuring compliance with security controls using tools like OneTrust and ProcessUnity. I ensured adherence to ISO 27001, HIPAA, GDPR, and CCPA regulations, facilitated audits, and responded to vendor questionnaires. I also led security risk assessments and disaster recovery drills and supported business continuity planning and remote work transitions.
IT Vendor Risk Assessment

Kansas national guard

Logistics Specialist - US Army

Feb 2017Feb 2023 · 6 yrs · Knoxville, Iowa, United States

Attention to Detail

Sprint

Third-Party Risk Program Manager

Feb 2017Jun 2017 · 4 mos · Kansas City, Kansas · On-site

  • As a Third-Party Risk Program Manager at Sprint/T-Mobile, I developed a comprehensive risk assessment framework for vendor evaluations based on NYDFS-500-11. I categorized vendors, analyzed key risk documentation like SOC 2 and BCP/DR reports, and tracked vendor deficiencies. Additionally, I created questionnaires for third parties and wrote Vendor Risk Assessment Reports, helping mitigate potential risks and ensuring compliance.
CommunicationISO 27001QuestionnairesAttention to DetailSOC 2Contract Requirements+2

Venerable

TPRM Analyst

Jan 2016Jan 2017 · 1 yr · Des Moines, Iowa Area · On-site

  • At Venerable Annuity, I conducted comprehensive vendor risk assessments focusing on information security and privacy, reviewing SOC 2 Type II reports, BCP/DR, and data security compliance. I collaborated with internal teams to develop and execute risk mitigation plans and assessed vendor maturity levels. I also mapped control standards to the VRA questionnaire, ensuring vendors met compliance and security requirements.
CommunicationISO 27001QuestionnairesAttention to DetailSOC 2IT Vendor Risk Assessment

Washington technology solutions (watech)

Security Vulnerability Analyst

Dec 2013Oct 2015 · 1 yr 10 mos · Washington D.C. Metro Area

  • As a Security Vulnerability Analyst supporting the US Department of Commerce, I led incident response
  • assessments, using NIST SP 800-61, and performed on-site vulnerability testing with Nessus. I managed
  • PCI-DSS assessments identified vulnerabilities, and collaborated with system owners on remediation
  • efforts, ensuring compliance. Additionally, I created Security Assessment Reports (SAR) and tracked
  • findings through POAMs for resolution.
Communication

Linac health services, inc.

Information Security Analyst

Dec 2012Oct 2013 · 10 mos · Washington D.C. Metro Area · On-site

  • At Linac Health Services, I helped develop and maintain information security policies aligned with NIST 800-53 and HIPAA regulations. I conducted third-party HIPAA risk assessments and identified security gaps, contributing to stronger vendor management. Additionally, I supported security incident response, created essential documentation, and led training initiatives to boost security awareness across the organization.
Communication

Education

Southern New Hampshire University

Master's degree — MS Cyber Security - IT Management

Oct 2023May 2025

University of Buea

Bachelor of Science - BS — Computer Science

Jan 2008Jan 2011

Stackforce found 100+ more professionals with Third Party Risk Management (tprm) & It Vendor Risk Assessment

Explore similar profiles based on matching skills and experience