Cybersecurity Specialist
Security program · Privacy and AI governance · IAM · End-user support- Lead a company-wide security program build-out: ran a NIST CSF 2.0 gap assessment across all six functions, prioritized findings in authentication, client-side data handling, and input validation into an engineering remediation queue, and built the policy and controls roadmap.
- Own COPPA/FERPA and AI governance for a K-12 platform, translating regulatory change into engineering acceptance criteria for PII blocking, age gating, and parental consent, and defining data-handling requirements for third-party AI vendors.
- Conduct recurring security control and tool reviews across the company’s cloud and SaaS platforms, delivering hardening recommendations (encryption, IAM least privilege, MFA, access reviews, logging), reviewing identity and access configuration in Microsoft 365, Google Workspace, Slack, and Notion, and analyzing inbound vendor and school-district security questionnaires.
- Serve as first-line technical and security support for employees and student participants over remote support calls, resolving Windows, software, browser, and peripheral issues, handling password resets, MFA enrollment, and account access troubleshooting, and supporting participants on client-provisioned K-12 laptops through device resets, recovery, and onboarding setup.
- Architected segmented, identity-verified access for the student research community, deliver weekly security-awareness briefings and new-hire orientations, coordinate user-acceptance testing across device, OS, and browser configurations, and automate recurring reporting workflows using Zapier, Power Automate, and AI-assisted analysis.
Cybersecurity and Technology Intern
Cloud security reviews · Data governance · Documentation- Conducted security reviews of AWS RDS, GCP, Azure, and SaaS platforms, assessing encryption at rest and in transit, IAM configuration, and compliance posture; compiled results into a reusable internal review library.
- Built team-specific security onboarding handbooks and a multi-domain employee training handbook spanning cloud security, secure development, threat detection, and resilience.
- Proposed data governance procedures aligned with CIS, NIST, COPPA, and FERPA under Zero Trust principles.