
Derek Gray-Cissp
As an experienced Compliance and Risk Management professional, I am skilled in identifying potential threats to processes and... | Salt Lake City, Salt Lake City, United States
*50 free lookup(s) per month.
No credit card required.
Derek Gray-Cissp’s Emails dg****@lu****.co
Derek Gray-Cissp’s Phone Numbers No phone number available.
Social Media
Derek Gray-Cissp’s Location Salt Lake City, Salt Lake City, United States
Derek Gray-Cissp’s Expertise As an experienced Compliance and Risk Management professional, I am skilled in identifying potential threats to processes and assets, testing controls, and developing practical solutions to mitigate risks. With a thorough understanding of common security frameworks and principles, such as NIST 800-53, ISO 27001, SOC 2, as well as risk analysis methodologies including OCTAVE, FAIR, and NIST 800-30, I have a passion for staying current with industry best practices and security trends. My expertise in managing tasks to meet deadlines, excellent verbal and written skills, and attention to detail enable me to work effectively across different teams and provide detailed updates to stakeholders. In my current role, I have successfully implemented and enhanced compliance programs and routines, resulting in efficient processes and reduced effort in adapting and maturing standards. My ability to identify areas for improvements in security controls while leading the design and implementation of related improvements has earned recognition from colleagues and management. I am proficient in identifying threats to existing processes and assets, performing risk assessments, and developing solutions to mitigate associated risks. With a solid understanding of security frameworks such as NIST 800-53, ISO 27001, SOC 2, and risk analysis methodologies like OCTAVE and NIST 800-30, I work effectively across several internal teams to identify potential threats to critical business assets while identifying opportunities for efficiencies and improvements in security controls. My experience with third-party risk management enables me to evaluate potential third-party vendors' risk profiles and control implementation, manage a questionnaire-based process to log and record assessments and create remediation plans for identified risks. With experience in SOX/ITGC, various audits, and policy documentation, I have made a significant impact across the organizations I have worked for. I am a Certified Sarbanes-Oxley Expert and have led highly visible projects and completed them on time. In addition, I take stewardship of security policies, standards, and processes to ensure they remain in alignment with company objectives, changes to the environment, and regulatory requirements.
Derek Gray-Cissp’s Current Industry Lucid Software
Derek
Gray-Cissp’s Prior Industry
Sylvan Connection
|
Centurylink
|
Conduit Sf Com
|
Rocky Mountain Rpg Guild
|
Lumen Technologies
|
Lucid
|
Lucid Software
Not the Derek Gray-Cissp you were looking for?
Find accurate emails & phone numbers for over 700M professionals.
Work Experience

Lucid Software
Senior Security Analyst II
Tue Aug 01 2023 00:00:00 GMT+0000 (Coordinated Universal Time) — Present
Lucid
Senior Security Analyst
Tue Mar 01 2022 00:00:00 GMT+0000 (Coordinated Universal Time) — Tue Aug 01 2023 00:00:00 GMT+0000 (Coordinated Universal Time)
Lucid
Security Analyst
Sat May 01 2021 00:00:00 GMT+0000 (Coordinated Universal Time) — Tue Mar 01 2022 00:00:00 GMT+0000 (Coordinated Universal Time)
Lumen Technologies
Service Assurance Technician
Fri Feb 01 2019 00:00:00 GMT+0000 (Coordinated Universal Time) — Sat May 01 2021 00:00:00 GMT+0000 (Coordinated Universal Time)
Rocky Mountain Rpg Guild
Lead Coordinator
Sun Jan 01 2017 00:00:00 GMT+0000 (Coordinated Universal Time) — Present
Centurylink
Facilities Specialist
Tue Dec 01 2015 00:00:00 GMT+0000 (Coordinated Universal Time) — Fri Feb 01 2019 00:00:00 GMT+0000 (Coordinated Universal Time)
Centurylink
Stand-in Manager
Thu Aug 01 2013 00:00:00 GMT+0000 (Coordinated Universal Time) — Fri Nov 01 2013 00:00:00 GMT+0000 (Coordinated Universal Time)
Conduit Sf Com
IT services Department Head
Sun Jul 01 2012 00:00:00 GMT+0000 (Coordinated Universal Time) — Mon Jun 01 2015 00:00:00 GMT+0000 (Coordinated Universal Time)
Conduit Sf Com
Web Master
Tue May 01 2012 00:00:00 GMT+0000 (Coordinated Universal Time) — Mon Jun 01 2015 00:00:00 GMT+0000 (Coordinated Universal Time)
Centurylink
Broadband Screening Consultant specializing in escalation managment
Sun Aug 01 2010 00:00:00 GMT+0000 (Coordinated Universal Time) — Thu Aug 01 2013 00:00:00 GMT+0000 (Coordinated Universal Time)
Centurylink
Broadband Screening consultant
Sun Feb 01 2004 00:00:00 GMT+0000 (Coordinated Universal Time) — Tue Dec 01 2015 00:00:00 GMT+0000 (Coordinated Universal Time)
Sylvan Connection
Owner/Operator
Wed Jan 01 2003 00:00:00 GMT+0000 (Coordinated Universal Time) — Tue Mar 01 2005 00:00:00 GMT+0000 (Coordinated Universal Time)