Priya Deshmukh
GRC & Compliance · CISA
priya.deshmukh@email.com(312) 555-0164Chicago, ILlinkedin.com/in/priyadeshmukh-grc
Summary
GRC professional with 8+ years running audit programs, control frameworks, and policy ownership for regulated healthcare and financial services. Clear communicator between auditors, legal, and engineering on evidence and remediation.
Skills
- SOC 2
- ISO 27001
- NIST CSF
- HITRUST
- risk assessments
- policy drafting
- vendor due diligence
- ServiceNow GRC
- Archer
- audit evidence
- SOX ITGC basics
Experience
Senior GRC AnalystMeridian Health Systems
2020 – Present
- Own SOC 2 Type II and HITRUST audit cycles; coordinate evidence collection across 18 control owners.
- Mapped policies to NIST CSF and ISO 27001; reduced audit findings by 30% over two cycles.
- Facilitated risk assessments for new SaaS vendors and tracked remediation in GRC platform.
IT Compliance SpecialistGreat Lakes Mutual Insurance
2016 – 2020
- Maintained policy library (acceptable use, data classification, incident response) with legal and HR review.
- Supported internal audits and external regulator inquiries with traceable control narratives.
- Implemented access review workflows for privileged accounts and third-party integrations.
Education
BS Management Information SystemsUniversity of Wisconsin–Milwaukee
2016
Coursework: risk management, business law, systems analysis
Certifications
CISAISACA
2021
CRISCISACA
2023