ISC2
Hey there!
OsenOsagie
I'm a GRC Analyst and Risk Specialist who turns complex regulations into clear, actionable strategies.
About Me

I am a cybersecurity governance, risk, and compliance practitioner focused on making security programs clearer, more accountable, and easier to operate.
My work connects policy, audit evidence, control frameworks, risk registers, and remediation planning. I like the point where a finding becomes a decision and documentation becomes something a team can actually use.
In these projects, I worked across ISO/IEC 27001, CIS Controls v8.1, NIST CSF 2.0, CIS RAM, HIPAA, PCI DSS, GDPR, incident response, vulnerability review, vendor risk, and business continuity.
Contact MeSkills &Certifications
I group my skills by the work they support: governance, risk, compliance, documentation, operations readiness, and professional communication.
Google Career Certificates
Google Cybersecurity Professional Certificate
Professional Development Path
ISO 27001 Lead Implementer
ISACA
CISA
Governance
I build policies, standards, control expectations, and documentation that make security programs easier to own.
Risk Management
I connect cybersecurity risk to business impact, ownership, likelihood, and practical treatment options.
Compliance
I interpret framework expectations and prepare audit-friendly evidence, reports, and gap analysis outputs.
Documentation
I write clear materials that help technical and non-technical stakeholders act with confidence.
Security Operations Support
I support readiness through incident planning, vulnerability review, continuity planning, and vendor workflows.
Professional Skills
I bring structure, communication, collaboration, and judgment to cybersecurity engagements.
Governance
I build policies, standards, control expectations, and documentation that make security programs easier to own.
Risk Management
I connect cybersecurity risk to business impact, ownership, likelihood, and practical treatment options.
Compliance
I interpret framework expectations and prepare audit-friendly evidence, reports, and gap analysis outputs.
Documentation
I write clear materials that help technical and non-technical stakeholders act with confidence.
Security Operations Support
I support readiness through incident planning, vulnerability review, continuity planning, and vendor workflows.
Professional Skills
I bring structure, communication, collaboration, and judgment to cybersecurity engagements.
Projects
Cybersecurity Governance
Develop, review, and align cybersecurity policies with organizational needs, compliance obligations, and industry standards.
Internal Cybersecurity Assessment
Conduct a comprehensive cybersecurity assessment and translate control gaps into business-focused recommendations.
Risk Assessment
Run a structured cybersecurity risk assessment covering assets, threats, vulnerabilities, scoring, and treatment planning.
Third-Party Risk Assessment
Evaluate suppliers and third-party vendors for cybersecurity risk, control maturity, and onboarding readiness.
Incident Response Program
Develop an incident response capability and validate the response workflow through tabletop exercises.
Cybersecurity Awareness Training
Improve organizational security awareness through structured training materials, sessions, and learning evaluation.
Vulnerability Assessment
Review vulnerability findings and prioritize remediation activity according to severity, exposure, and operational impact.
Framework Review & Mapping
Compare major cybersecurity frameworks and recommend adoption strategies that fit governance and control needs.
Business Continuity & Disaster Recovery
Develop business continuity and disaster recovery capabilities aligned to critical business operations and recovery targets.
WhatPeopleNotice
“Osen makes security expectations easier to understand”
Osen makes security expectations easier to understand. Her work connects controls, evidence, and ownership in a way teams can act on.
Security Program Reviewer
GRC portfolio review
“The strongest signal in her case studies is communication”
The strongest signal in her case studies is communication. She explains risk without losing the business context behind it.
Cybersecurity Mentor
Professional feedback