JOY JONATHAN NURIA OYIBO

Governance, Risk & Compliance (GRC) Analyst

About

Highly analytical GRC Analyst with robust practical experience in risk assessment, vulnerability management, and regulatory compliance across ISO 27001, NIST CSF, GDPR, and PCI DSS frameworks. Leverages over 15 years of leadership in educational operations to drive process optimization, enhance documentation, and coordinate cross-functional teams, ensuring stringent operational standards and effective governance.

Work Experience

Senior Operations Lead

Educational Institution (Inferred)

Sep 2009 - Aug 2020

Lagos, Lagos State, NG

Directed comprehensive operational strategies for educational institutions, overseeing structured processes, staff coordination, and the maintenance of high educational and administrative standards for over a decade.

  • Led school operations for over 10 years, implementing structured processes that improved efficiency and consistency across all departments.
  • Supported policy enforcement and delivered training programs, enhancing organizational consistency and compliance with internal and external standards.
  • Managed diverse teams, optimizing workflow efficiency and ensuring adherence to established procedures, fostering a collaborative and high-performing environment.
  • Developed comprehensive documentation for operational procedures, significantly improving clarity, accountability, and staff onboarding processes.

Education

English Language

Lagos State University

Sep 2010 - Jun 2014

Lagos, Lagos State, NG

Certificates

Lead Implementer ISO 27001 and ISO 42001

Accredited Body (Inferred)

Dec 2025

Cybersecurity Training

Axia Africa

Dec 2025

Introduction to Cybersecurity

Cisco

Dec 2025

Governance, Risk & Compliance (GRC)

ICDFA (Ongoing)

Dec 2024

ISO 27001

ICDFA (Ongoing)

Dec 2024

Diploma in Risk Management

OHSC UK

Dec 2024

Projects

Governance, Risk & Compliance Portfolio

Jan 2023 - Jun 2024

Comprehensive portfolio of hands-on projects demonstrating expertise in risk management, vulnerability assessment, security monitoring, and compliance across various industry-standard frameworks.

Languages

English

Skills

Risk Management

  • Risk Assessment
  • Risk Register Development
  • Threat Identification
  • Quantitative Risk Analysis (SLE, ALE, ARO)
  • Vendor Risk Management

Compliance & Governance

  • ISO 27001
  • NIST CSF
  • CIS Controls
  • GDPR
  • HIPAA
  • PCI DSS
  • ISO 27701
  • SOX
  • FCPA
  • GLBA
  • Compliance Mapping
  • Policy Development
  • Governance Documentation
  • Audit Preparation & Support
  • Regulatory Compliance

Vulnerability Management

  • Vulnerability Assessment
  • CVE Interpretation
  • Nmap
  • Nikto
  • Nuclei
  • xsltproc
  • OWASP Top 10
  • Burp Suite Pro
  • Technical Controls

Security Operations

  • SIEM & Log Analysis
  • Incident Response Procedures
  • File Integrity Monitoring (FIM)
  • Security Monitoring
  • Incident Analysis
  • Phishing Risk Analysis

Technical Tools & Frameworks

  • Wazuh
  • Nmap
  • Nikto
  • Nuclei
  • xsltproc
  • Burp Suite Pro
  • ISO 31000
  • NIST CSF
  • CIS Controls
  • ISO 27001
  • ISO 27701
  • GDPR
  • HIPAA
  • PCI DSS

Leadership & Operations

  • Documentation
  • Process Coordination
  • Team Leadership
  • Operational Standards
  • Policy Enforcement
  • Training Delivery
  • Workflow Efficiency
  • Strategic Planning
  • Cross-functional Collaboration