NIST CSF 2.0 · CANDIDATE PROFILE

Jose Garcia

GRC & Cybersecurity Risk · Third-Party Risk

Master's candidate building toward the CISO chair — one control, one vendor assessment, one audit trail at a time.

Bilingüe · Inglés / Español

Open to: GRC Analyst roles · Dallas–Fort Worth

ID — IDENTIFY

Profile

I'm a Master's in Cybersecurity candidate at the University of Dallas, concentrating in Governance, Risk & Compliance and graduating December 2026. Before this I earned a B.A. in Business Administration from Austin College, minoring in Accounting and Spanish — a background that turned out to matter more than I expected, since GRC work is as much about process, documentation, and stakeholder communication as it is about technical controls. My focus now is third-party risk and vendor management — the unglamorous, essential work of knowing who touches your data and how exposed that makes you. I'm bilingual in English and Spanish, and working toward CISO over the long run, starting with the fundamentals.

  • BasedDallas, TX
  • ProgramM.S. Cybersecurity, GRC — Univ. of Dallas
  • GraduatingDecember 2026
  • Prior degreeB.A. Business Admin. — Austin College
  • LanguagesEnglish / Spanish
  • In progressCompTIA Security+ (SY0-701)

PR — PROTECT

Experience

Cybersecurity Intern

Digital Realty · Dallas, TX · 2025

Resolved 60+ security tickets end to end — triaging requests, documenting actions and evidence, and keeping the queue inside SLA. Ran external attack surface and OSINT reconnaissance to flag publicly exposed assets and misconfigurations, then routed findings into the vulnerability management process with severity and impact attached. Contributed to threat landscape summaries by tracking active threat groups and indicators to inform risk prioritization. Created and maintained third-party risk records in the GRC/TPRM platform, initiating and tracking remediation requests with vendors and internal owners.

  • Ticketing & SLA management
  • OSINT & attack surface recon
  • Vulnerability management
  • Threat landscape research
  • TPRM platform
0 Tickets resolved
0 GRC projects
0 Leadership roles
0 Languages

PRIOR ROLES

  • Assistant Director of OperationsPettigrew Luxury Furnishings · 2024
  • Account ExecutiveOrion Lending · 2022–2023
  • Information Technology AssistantAustin College · 2018–2021

DE — DETECT

Projects & Coursework

REF · IAM-01

IAM Threat Report

Mapped real-world breaches — Tesla, Snowflake, Change Healthcare, and the MOVEit incident — against the NIST Cybersecurity Framework to trace where identity and access controls broke down.

REF · CMMC-02

CMMC 2.0 / NIST 800-171 Exercise

Self-study assessment of a fictional defense contractor, Trident Defense Systems — built out SPRS scoring and a POA&M to close the identified gaps.

REF · GAP-03

NIST CSF Gap Analysis

Capstone for the Google Cybersecurity Certificate — evaluated a program against the CSF functions and prioritized the gaps worth closing first.

Framework exposure — ISO 27001, SOC 2, HIPAA, PCI DSS — is coursework and internship-level familiarity, not claimed mastery.

SKILLS & TOOLS

What I work with

GRC

Risk assessments, control reviews, audit prep, evidence collection, TPRM

Frameworks

NIST CSF, NIST 800-171, NIST 800-30/53, ISO 27001, SOC 2, PCI DSS, HIPAA

Security fundamentals

Vulnerability lifecycle, access reviews, OSINT, incident documentation

Technical

Python, SQL, Bash, Linux basics; exposure to network analysis and forensic imaging

Platforms

SIEM, endpoint security, network scanning tools, directory services, GRC/ticketing platforms

RS — RESPOND

Leadership

Treasurer → Vice President

ISSA Subchapter, University of Dallas · 2025–Present

Moved from managing chapter finances to helping run the organization — the same instinct that drives the GRC work: someone has to own the process and make sure it holds up when it's checked. Also an active member of Sigma Iota Epsilon at UD, and previously held Treasurer, Vice President, and President roles in my undergraduate fraternity at Austin College.

RC — RECOVER

Let's talk

Looking for entry-level GRC analyst roles in the Dallas area. If you're hiring, or just want to compare notes on vendor risk, reach out.