← LABSESTEBAN ROSALES
GRC-005 / PROFESSIONAL EXPERIENCE

Cyber Risk & Security Assurance

Risk Assessment / Control Reviews / Follow-up

PROFESSIONAL EXPERIENCE

I designed and carried out risk assessments, control reviews and remediation follow-up to turn technical exposure into clear priorities for the organization.

Risk AssessmentIT AuditControl ReviewsRisk TreatmentSecurity AwarenessReporting
Architecture diagram for Cyber Risk & Security Assurance
CYBER RISK ASSURANCE LIFECYCLE

I developed a practical risk workflow that connects technical review with business decisions. I identified relevant scenarios, assessed likelihood and impact, documented control gaps and maintained follow-up on agreed treatment actions.

I also planned controlled security-awareness exercises and translated their results into training priorities. The aim was not simply to produce reports, but to give each risk an owner, a treatment decision and a visible path to closure.