Cybersecurity GRC Analyst | NIST RMF, FISMA, FedRAMP | Security Control Assessment, Risk Assessment, POA&M Management
Washington DC and Baltimore area | nkiru_sarah@yahoo.com | LinkedIn | CISA, CompTIA Security+ | MS Cybersecurity Management and Policy
Every project below is built on a fictional organisation. The Keystone Grants Management System does not exist and the Federal Workforce Development Agency is a fictional agency invented for this portfolio. Every organisation, person, identifier, finding, date and signature is fabricated for training purposes, with one exception: the author, Nkeiru Sarah Adesida, is a real person. Where her name appears in a scenario role, that role is fictional, and she has never worked for this agency, which does not exist. Nothing here comes from any real employer, client or government system, no real document or data has been reproduced, and none of it is a government record. Each repository and each individual document repeats this on its own first screen.
Cybersecurity Governance, Risk and Compliance analyst with approximately five years of hands on experience in NIST Risk Management Framework implementation, security control assessment, risk assessment and continuous monitoring across federal and regulated environments.
My work sits where security meets evidence. I review implementation statements, examine artifacts, test controls against NIST SP 800-53 requirements, and document what I find in language both engineers and auditors can act on. I build and maintain Plan of Action and Milestones records so that every open weakness has an owner, a target date, and closure evidence that holds up under review.
Open to: Cybersecurity GRC Analyst, Information System Security Officer (ISSO), Security Control Assessor, Security Compliance Analyst and IT Audit roles across the Washington DC, Maryland and Virginia region. On site, hybrid or remote.
Every project below is built on a fictional organisation and a simulated system. The Federal Workforce Development Agency and the Keystone Grants Management System do not exist. Every organisation, person, identifier, finding, date and signature is fabricated for training purposes, with one exception: the author, Nkeiru Sarah Adesida, is a real person. Where her name appears in a scenario role, that role is fictional, and she has never worked for this agency, which does not exist. Nothing in this portfolio comes from any real employer, client or government system, and no real document or data has been reproduced. Each repository and each individual document states this on its own first screen.
Rather than three unrelated projects, these repositories document the same simulated federal system three times, from three professional angles. An employer is not buying knowledge of one framework, they are buying the ability to pick up a framework and apply it, and doing one system three ways is how that gets demonstrated.
| Repository | What it covers | Focus |
|---|---|---|
| keystone-kgms-fedramp-rmf | A complete FedRAMP Moderate authorisation: NIST RMF Steps 0 to 6, from readiness through a FIPS 199 categorisation with a documented impact adjustment, a System Security Plan with control implementation narratives, 16 assessment findings each with a disposition, a 10 item POA&M, the Authorization to Operate memorandum, and a live monthly continuous monitoring report | |
| keystone-kgms-iso27001 | The same system under ISO/IEC 27001:2022: ISMS scope and context, a Statement of Applicability covering all 93 Annex A controls individually, a 12 risk register scored inherent and residual, a risk treatment plan, an internal audit, a management review, and a crosswalk showing where the federal and international frameworks genuinely diverge | |
| keystone-kgms-security-plus | All five CompTIA Security+ SY0-701 domains applied to the same simulated system: general security concepts and cryptography, threats and mitigations traced to the real assessment findings, security architecture, security operations, and program management. The technical breadth underneath the GRC work | |
| keystone-kgms-conmon-vulnmgmt | The work of keeping a system authorised: continuous monitoring strategy, a vulnerability management programme with real CVEs and correct CVSS handling, the POA&M lifecycle in ServiceNow, control monitoring and evidence management in RSA Archer, security control assessment procedures with worked test cases, and the metrics and reporting that go to the Authorizing Official |
- Every summary number is generated from its own detail rows. No summary table in this portfolio disagrees with the rows beneath it, because the summaries are computed rather than typed. A summary that does not reconcile takes a reviewer under a minute to find.
- Every assessment finding has exactly one disposition, and they sum to the total. 16 findings: 5 closed during fieldwork, 1 formally risk accepted, 10 carried into the POA&M. Nothing is unexplained.
- Machine readable artifacts, not only documents. The POA&M, the Statement of Applicability, the risk register, the finding sets and the test cases are published as CSV as well, because that is the format they are actually worked in.
- The failures are written up as fully as the successes, including root cause. A portfolio where nothing went wrong is a portfolio that was not tested.
- Every document discloses that it is simulated, on its own first screen, not only in a repository landing page a reader may never open.
All portfolio work on this profile is built on a fictional organisation and a simulated system. It is coursework and it is not a government record. nkiru_sarah@yahoo.com | LinkedIn