2024
Cybersecurity Internship
Eretmis Academy
Completed structured GRC-focused projects covering governance, internal assessment, risk management, awareness, and incident preparedness.
Hello, I am
Cybersecurity GRC professional.
I help teams turn security requirements into clear controls, usable evidence, and confident decisions.


“Cybersecurity should make trust easier to prove, not harder to understand.”
I value clarity, accountability, and practical governance. My work helps teams understand risk, own controls, document evidence, and make better security decisions.
I start by understanding the business context, the risk, and the evidence that already exists.
I use each case study to show the context, method, deliverables, and outcomes behind my GRC work.
Governance
A structured policy development engagement aligning security expectations with business objectives and recognized frameworks.
Internal Audit
An internal assessment that reviewed security controls, documented gaps, and produced a prioritized remediation roadmap.
Risk Management
A risk assessment project documenting assets, threats, likelihood, impact, and treatment options for management review.
I am building my cybersecurity path through focused GRC practice, structured documentation, and work that connects security expectations to business ownership.
2024
Eretmis Academy
2024
Eretmis Academy
Completed structured GRC-focused projects covering governance, internal assessment, risk management, awareness, and incident preparedness.
2024
ISC2 and Google
Built foundational cybersecurity knowledge across principles, operations, frameworks, incident response, and governance.
Ongoing
Professional Development
Expanding expertise in ISO 27001, IT audit, vendor risk, business continuity, and AI security governance.
I bring structured thinking, clear communication, and practical security documentation to governance and risk work.
Building policies, standards, control expectations, and documentation that support accountable security programs.
Connecting cybersecurity risk to business impact, ownership, likelihood, and practical treatment options.
Interpreting framework expectations and preparing audit-friendly evidence and gap analysis outputs.
Producing clear, structured materials that help technical and non-technical stakeholders act confidently.
I aim to make security expectations clear enough for people to understand, own, and improve.
“Osen makes security expectations easier to understand. Her work connects controls, evidence, and ownership in a way teams can act on.”
Security Program Reviewer
GRC portfolio review
Tell me what you are trying to improve, assess, or document.