Summary
Overview
Work History
Education
Skills
Websites
Certification
Timeline
Generic

Cory Brant

Charlottesville

Summary

IT Compliance Manager with over 8 years of experience in governance, risk, and compliance. Developed a NIST 800-53 program that reduced audit costs by over 40%, streamlining compliance efforts. Successfully managed an IT Compliance team, achieving the highest individual contributor performance rating in 2024. Extensive background in a wide range of frameworks and regulations including SOX, SOC 2, ISAE 3000, ISO 27001, NIST 800-53, HIPAA, FERPA, and PCI-DSS.

Overview

8
8
years of professional experience
1
1
Certification

Work History

Information Technology Compliance Manager

Verra Mobility
01.2025 - Current
  • Developed and implemented a comprehensive NIST 800-53 based program incorporating 537 common controls applicable to PCI-DSS, ISO 27001, SOC 2, and SOX.
  • Achieved a greater than 40% reduction in audit and assessment costs through consolidation of tools, firms, and service providers.
  • Reduced findings across audits by 23% compared to the prior year.
  • Managed the IT Compliance team with a focus on employee wellbeing and growth.
  • 2024 performance evaluated at the highest possible outcome for an employee rating at Verra Mobility.

Governance, Risk, and Compliance Analyst

Verra Mobility
12.2022 - 02.2025
  • Administrated the global ISO 27001 program.
  • Lead executor for a range of sales and operational tasks including RFP support, customer risk assessments, contract review, cloud vendor risk assessments, and exception request management.
  • Promoted in February 2024 to Sr. Analyst role.

Lead Security Management Specialist

SOCIETY FOR WORLDWIDE INTERBANK FINANCIAL TELECOMMUNICATION, INC
Culpeper
10.2021 - 12.2022
  • Led ISAE 3000 control baseline management and audit readiness.
  • Conducted risk management activities and continuous monitoring for all controls.
  • Delivered education and training to control owners and control objective owners.

Sr GRC Analyst

Valvoline Inc.
07.2021 - 10.2021
  • Led GRC activities primarily in the domain of third party risk assessments including contract reviews.

Senior IT Compliance Analyst

University of Virginia
Charlottesville
03.2017 - 07.2021
  • Delivered and maintained a comprehensive Governance, Risk, and Compliance program that included, but was not limited to third party risk management, research support, and policy writing.
  • Joined in March 2017 as a contractor with Insight Global to support a policy overhaul initiative. Full time employee status achieved in November 2017 after developing a risk management tool that saved 30K in costs to the department.
  • Promoted to a senior analyst in February 2019 as an acknowledgment for various achievements.

Education

Longwood University - Political Science and Government

Longwood University
12.2016

Skills

  • Cybersecurity Audit and Compliance
  • Risk Assessment
  • Policies, Standards, and Procedures
  • GRC Program Establishment
  • Vendor Assessment

Certification

  • GIAC Security Essentials Certification (GSEC), GIAC Certifications, https://www.giac.org/certification/security-essentials-gsec, 05/01/18
  • GIAC Law of Data Security & Investigations (GLEG), GIAC Certifications, 01/01/21
  • Certified Information Systems Auditor (CISA), ISACA, https://www.credly.com/badges/465e2b7a-2ad2-4560-abd0-f1c92ba3ee19/linked_in_profile, 09/01/22
  • (ISC)2 Security CISSP (ISC2-CISSP), ISC2, https://www.credly.com/badges/09feaadc-2e37-497f-a48d-b2b8bad189f2/linked_in?t=sn7qr6, 11/01/24

Timeline

Information Technology Compliance Manager

Verra Mobility
01.2025 - Current

Governance, Risk, and Compliance Analyst

Verra Mobility
12.2022 - 02.2025

Lead Security Management Specialist

SOCIETY FOR WORLDWIDE INTERBANK FINANCIAL TELECOMMUNICATION, INC
10.2021 - 12.2022

Sr GRC Analyst

Valvoline Inc.
07.2021 - 10.2021

Senior IT Compliance Analyst

University of Virginia
03.2017 - 07.2021

Longwood University - Political Science and Government

Longwood University
Cory Brant