Sunita Gopalani
Details
Aristi Technologies
Principal Cybersecurity Consultant
2006 : 2008
OnPoint
Sr. Information Security Analyst
About
Ms. Sunita Gopalani is a senior information security professional with over fifteen (15) years of experience providing IT security consulting and cybersecurity compliance services to federal agencies and private sector customers.
Ms. Gopalani has extensive experience in supporting information security governance, risk and compliance activities including developing information security policies, processes and procedures; assessing security risk against industry standards and frameworks; preparing authorization to operate (ATO) documentation; and supporting continuous monitoring efforts.
She has expertise in advising, preparing and assessing federal agencies and commercial clients to comply with mandatory and regulatory security standards including NIST, RMF, FISMA, FedRAMP and CMMC (preparation).
Ms. Gopalani is committed to continuous learning and staying current with federal security regulations; cybersecurity best practices; and industry standards, guidelines and frameworks. She brings a flexible and adaptable attitude along with the discipline to manage multiple responsibilities and adjust to varied customer environments.
Experience working with large and small government agencies and private sector firms: The National Institutes Of Health (NIH), United States Department of Agriculture (USDA) multiple agencies, USDA National Information Technology Center (NITC), General Services Administration (GSA), Farm Credit Administration (FCA), Federal Retirement Thrift Investment Board (FRTIB), Government National Mortgage Association (Ginnie Mae), HHS Health Resources and Services Administration (HRSA), The National Institutes Of Health (NIH) - Office of Research Services (ORS) and Center for Information Technology (CIT), National Weather Service (NWS), United States Mint, US Department of Energy (DOE), Emergent Bio-solutions, MacrGenics, and VenatoRx.
Expertise:
NIST Risk Management Framework (RMF)
Governance, Risk and Compliance (GRC)
Security Policies and Procedures
Federal Risk and Authorization Management Program (FedRAMP)
Assessment and Authorization (A&A)
Security Control Assessments (SCA)
Security Awareness and Training
RSA Archer GRC Platform