I will conduct nist csf maturity assessment and enterprise risk analysis
Assistant Manager Security Cyber Resilience
About this Gig
I bring 9+ years assessing and managing enterprise risk, including an 18-month enterprise risk framework build for a leading regional bank (regulator-mandated), using scenario-based threat modeling, a scalable risk register, and real-time reporting dashboards. I've also run IT general controls audits that identified 84+ control gaps other reviews had missed.
What you get:
- NIST CSF 2.0 maturity assessment across all six functions (Govern, Identify, Protect, Detect, Respond, Recover)
- Risk register with likelihood/impact scoring and treatment plans
- Enterprise risk appetite and KRI framework (for organizations building or refreshing ERM)
Findings are built around how your organization actually operates, not a generic six-function checklist you could fill out yourself.
My Portfolio
FAQ
Is this only for large enterprises?
No, I scale scope and depth to your organization's size and maturity level.
Can you map findings to other frameworks like ISO 27001?
Yes, I can cross-reference NIST CSF findings against ISO 27001, SOC 2, or other frameworks you're also pursuing.
Do you provide ongoing risk monitoring, or just the one-time assessment?
This gig covers the assessment; ongoing monitoring/advisory can be arranged as a custom offer.

