Learn Data Skills

Kate Spinner

Financial Analyst

FEMA

Technologies

My Portfolio Highlights

My New Course

Introduction to Python

Analytical maestro, orchestrating the symphony of insights with precision.

My Work

Take a look at my latest work.

course

Introduction to Data Literacy

course

Introduction to Data

course

Introduction to Python

My Certifications

These are the industry credentials that I’ve earned.

Other Certificates

ISC2 Certified Information Systems Security Professional

DataCamp Course Completion

Take a look at all the courses I’ve completed on DataCamp.

My Work Experience

Where I've interned and worked during my career.

FEMA | Feb 2025 - Present

Hazard Mitigation Advisor

Support risk mitigation programs, established in response to vulnerabilities exposed during recent hurricanes in Sarasota and Tampa Bay region. Participate in outreach to inform residents, insurance agents, and community leaders about mitigation resources available to reduce risk of loss from future severe weather events.
Show More

DXC Technology | Nov 2018 - Jun 2024

PRINCIPAL CYBERSECURITY RISK MANAGEMENT

RISK ASSESSMENT • Conducted risk assessments and helped to facilitate and document risk treatment and remediation for internal systems. • Identified and documented noncompliance, vulnerabilities, control effectiveness, inherent risk, risk treatment and residual risk, following qualitative and quantitative (FAIR “light”) methods. • Presented risk assessment results, and risk acceptance and risk treatment agreements, to Architecture Review Board for system authorization. • Maintained trusted relationships across global business units. • Contributed to secure datacenter migration to AWS Cloud. Risk assessed Cloud landing zone and first 12 applications. Developed streamlined process to assess 200 systems prior to migration deadline. • Collaborated with consultant on annual enterprise-wide Cybersecurity Maturity Assessment. Facilitated over 20 interviews across business units. Analyzed results and presented summary to CISO. RISK MANAGEMENT • Led process and workflow improvements for assessing and managing risk, aligned with Service Now IRM. • Communicated Service Now requirements to consultants for risk dashboards and role permissions, and wrote content for email alerts and help text. • Collaborated with enterprise architects and other cross-functional stakeholders to write and maintain Risk Management Lifecycle procedure aligned to NIST RMF. • Contributed to development of in-house security controls and requirements based on NIST CSF, AWS Well-Architected Framework, FedRAMP and Zero- Trust principles. • Established Third-party Risk Management program in partnership with TPRM lead, consultant and stakeholders. Evaluated risk rating platforms (BitSight, Risk Recon, Black Kite) to use in assessments. Ran pilot TPRM assessments. • Improved Security Policy Exception program. Delegated tasks among 5 global security leads. Developed processes and service level agreements to enhance program effectiveness. Presented exception volume, resolution timeframes, and risk to CISO.

CSC - Computer Sciences Corporation | Apr 2012 - Nov 2018

CYBERSECURITY ADVISOR - AMERICA'S REGION

VULNERABILITY RISK REDUCTION • Established and managed Qualys vulnerability scanning service for internal systems globally, replacing Nessus. • Took Qualys training to run scans and asset discovery. Trained RSLs to use Qualys in their regions. • Led weekly meetings with RSLs to improve process, maximize remediation, and reduce business impact from scans. • Ran discovery, ad hoc, and monthly scans based on America’s region target list of approx. 3,000 servers. • Notified system owners and admins of vulnerabilities and explained remediation steps as needed. • Escalated remediation for critical, exploitable vulnerabilities. For example, during WannaCry attacks, I contacted business units and system owners with instructions to remove or upgrade SMBv1 on over 1,000 servers. • Produced and presented monthly reports on vulnerability trends, issues, and successes to Executives. MANAGED SECURITY SERVICES AND POLICY MANAGEMENT • Aggregated data from security service leads on the suite of security services delivered to the internal account. Used Excel and Access to run meaningful and actionable metrics. Developed monthly presentations to present on security posture and service performance to Risk Director and CISO. • Represented Global Cybersecurity on Daily Service Review (DSR) and coordinated problem resolution as needed. • Provided support to track and assist with resolution of security incidents reported to the incident response team. • Documented present and future state scenarios for incident response, in preparation for consultant process analysis. • Collaborated with leadership and technical security subject matter experts to align information security policies, standards, and procedures to ISO27001 / 27002 . Piloted policy management in Archer GRC platform.

Herald-Tribune Media Group | Jul 2006 - Dec 2012

Science and Environment Reporter

• Won 2012 Waldo Proffitt Award for Excellence in Environmental Journalism, Florida’s top environmental reporting award. Recognized for coverage of climate change, satellite program funding shortages, invasive species issues, and public land management problems. https://www.heraldtribune.com/story/ news/2012/07/08/herald-tribune-a-heavy-hitter-at-news-awards/29107369007/ • Researched complex scientific information and translated into accurate content for general audiences. • Established and maintained trust relationships with top national scientists and local officials through smart reporting, accurate writing, and confidentiality when warranted.

My Education

Take a look at my formal education

Master's Degree in Information Systems Management, Information Security / CybersecurityKeller Graduate School of Management of DeVry University | 2016
Salisbury University

About Me

Data science is needed in all fields and industries. It's a valuable skill and in high demand. Plus, it's amazing to see useful or interesting insights revealed by applying order, structure and analysis to data.

Powered by

  • Work
  • Certifications
  • Courses
  • Experience
  • Education
  • About Me
  • Create Your Data Portfolio for Free