Skip to content

Hey there!

OsenOsagie

I'm a GRC Analyst and Risk Specialist who turns complex regulations into clear, actionable strategies.

About Me

Portrait representing Osen Osagie

I am a cybersecurity governance, risk, and compliance practitioner focused on making security programs clearer, more accountable, and easier to operate.

My work connects policy, audit evidence, control frameworks, risk registers, and remediation planning. I like the point where a finding becomes a decision and documentation becomes something a team can actually use.

In these projects, I worked across ISO/IEC 27001, CIS Controls v8.1, NIST CSF 2.0, CIS RAM, HIPAA, PCI DSS, GDPR, incident response, vulnerability review, vendor risk, and business continuity.

Contact Me

Skills &Certifications

I group my skills by the work they support: governance, risk, compliance, documentation, operations readiness, and professional communication.

ISC2

ISC2 Certified in Cybersecurity (CC)

Google Career Certificates

Google Cybersecurity Professional Certificate

Professional Development Path

ISO 27001 Lead Implementer

ISACA

CISA

Governance

I build policies, standards, control expectations, and documentation that make security programs easier to own.

Security policy developmentPolicy reviewGovernance framework alignmentControl assessment

Risk Management

I connect cybersecurity risk to business impact, ownership, likelihood, and practical treatment options.

Risk assessmentRisk register developmentRisk treatment planningBusiness risk analysis

Compliance

I interpret framework expectations and prepare audit-friendly evidence, reports, and gap analysis outputs.

ISO 27001 alignmentNIST CSF mappingCIS ControlsCompliance gap analysis

Documentation

I write clear materials that help technical and non-technical stakeholders act with confidence.

Technical writingExecutive summariesProceduresReports

Security Operations Support

I support readiness through incident planning, vulnerability review, continuity planning, and vendor workflows.

Incident response planningVulnerability reviewBusiness continuity planningSecurity awareness

Professional Skills

I bring structure, communication, collaboration, and judgment to cybersecurity engagements.

Stakeholder communicationAnalytical thinkingPresentationProblem solving

Governance

I build policies, standards, control expectations, and documentation that make security programs easier to own.

Security policy developmentPolicy reviewGovernance framework alignmentControl assessment

Risk Management

I connect cybersecurity risk to business impact, ownership, likelihood, and practical treatment options.

Risk assessmentRisk register developmentRisk treatment planningBusiness risk analysis

Compliance

I interpret framework expectations and prepare audit-friendly evidence, reports, and gap analysis outputs.

ISO 27001 alignmentNIST CSF mappingCIS ControlsCompliance gap analysis

Documentation

I write clear materials that help technical and non-technical stakeholders act with confidence.

Technical writingExecutive summariesProceduresReports

Security Operations Support

I support readiness through incident planning, vulnerability review, continuity planning, and vendor workflows.

Incident response planningVulnerability reviewBusiness continuity planningSecurity awareness

Professional Skills

I bring structure, communication, collaboration, and judgment to cybersecurity engagements.

Stakeholder communicationAnalytical thinkingPresentationProblem solving

Projects

Cybersecurity Governance

Develop, review, and align cybersecurity policies with organizational needs, compliance obligations, and industry standards.

Cybersecurity Governance project cover

Internal Cybersecurity Assessment

Conduct a comprehensive cybersecurity assessment and translate control gaps into business-focused recommendations.

Internal Cybersecurity Assessment project cover

Risk Assessment

Run a structured cybersecurity risk assessment covering assets, threats, vulnerabilities, scoring, and treatment planning.

Risk Assessment project cover

Third-Party Risk Assessment

Evaluate suppliers and third-party vendors for cybersecurity risk, control maturity, and onboarding readiness.

Third-Party Risk Assessment project cover

Incident Response Program

Develop an incident response capability and validate the response workflow through tabletop exercises.

Incident Response Program project cover

Cybersecurity Awareness Training

Improve organizational security awareness through structured training materials, sessions, and learning evaluation.

Cybersecurity Awareness Training project cover

Vulnerability Assessment

Review vulnerability findings and prioritize remediation activity according to severity, exposure, and operational impact.

Vulnerability Assessment project cover

Framework Review & Mapping

Compare major cybersecurity frameworks and recommend adoption strategies that fit governance and control needs.

Framework Review & Mapping project cover

Business Continuity & Disaster Recovery

Develop business continuity and disaster recovery capabilities aligned to critical business operations and recovery targets.

Business Continuity & Disaster Recovery project cover

WhatPeopleNotice

Osen makes security expectations easier to understand

Osen makes security expectations easier to understand. Her work connects controls, evidence, and ownership in a way teams can act on.

Security Program Reviewer

GRC portfolio review

The strongest signal in her case studies is communication

The strongest signal in her case studies is communication. She explains risk without losing the business context behind it.

Cybersecurity Mentor

Professional feedback

Let'sConnect