Jose Garcia | GRC & Cybersecurity Risk
J O S E G A R C I A

Governance · Risk · Compliance

Jose Garcia

NIST CSF 2.0 · Candidate Record

Jose Garcia

GRC & Cybersecurity Risk

View the Record Get in Touch

The Short Version

Compliance isn't the binder. It's knowing which vendor should keep you up at night.

Controls are easy to list and hard to prove. I do the unglamorous part — scoring the risk, chasing the evidence, closing the finding — so the decision at the top is made on something real.

Background

Profile

I'm a Master's in Cybersecurity candidate at the University of Dallas, concentrating in Governance, Risk & Compliance, holding a 4.0 GPA and graduating Fall 2026. Before this I earned a B.A. in Business Administration from Austin College, minoring in Accounting and Spanish, a background that turned out to matter more than I expected, since GRC work is as much about process, documentation, and stakeholder communication as it is about technical controls.

Before moving into security, I worked in regulated, client-facing roles, including HIPAA-compliant pharmacy workflows at Walgreens and broker support at Orion Lending, where accuracy and documentation were part of the daily job, the same discipline that carried directly into vendor risk work at Digital Realty. I'm looking for an entry level role where I can support risk assessments, control testing, and third-party risk management, and long term I see myself in a role that blends business and security, working toward CISO by helping a business make the security decisions that keep it running.

  • Undergrad degreeB.A. Business Admin. — Austin College
  • GraduatingFall 2026
  • GPA4.0
  • LanguagesEnglish / Spanish
  • LocationDallas – Carrollton, TX
  • Long-term goalCISO

Applied Experience

Experience

Cybersecurity Intern

Digital Realty · Dallas, TX · 2026

Helped maintain third-party risk records in a GRC/TPRM platform, initiated and tracked vendor remediation requests, resolved 60+ tickets within defined SLAs, and contributed to threat landscape summaries that informed risk prioritization.

Pharmacy & Broker Support

Walgreens · Orion Lending

HIPAA-compliant pharmacy workflows and broker support in regulated, client-facing environments where accuracy, documentation, and process discipline were part of the daily job.

Applied Projects

Projects

TPRA Ledger interface

TPRA Ledger

REF. TPRA–00

A full-stack third-party risk assessment tool: inherent risk is scored across five weighted criteria, then adjusted into a residual score as control ratings come in through a questionnaire mapped to NIST CSF 2.0 and ISO 27001 Annex A. Ratings that flag a real gap automatically generate a tracked finding with an owner, due date, and status.

Built with Node.js/Express and SQLite, with server-side validation, rate limiting, unit tests, and linting.

View Repo
Breach Exposure Estimator interface

Breach Exposure Estimator

REF. BEE–00

A browser-based calculator that estimates the financial exposure of a data breach from a company profile alone: industry, size, and primary region drive a live low/high/midpoint range and a severity rating, updating instantly as the profile changes. No server, no data collection, the entire model runs client-side.

View Repo Live Demo

Coursework & Exercises

REF. IAM–01

IAM Threat Report

Mapped real-world breaches against the NIST Cybersecurity Framework. Co-authored with a classmate for CYBS 7350.

REF. CMMC–02

CMMC 2.0 / NIST 800-171

Self-study assessment of a fictional defense contractor; built out SPRS scoring and a POA&M.

REF. GAP–03

NIST CSF Gap Analysis

Capstone for the Google Cybersecurity Certificate; evaluated a program against the CSF functions.

Framework exposure — ISO 27001, SOC 2, HIPAA, PCI DSS — is coursework and internship-level familiarity, not claimed mastery.

What I Work With

Skills & Tools

  • NIST CSF 2.0
  • ISO 27001
  • SOC 2
  • HIPAA
  • PCI DSS
  • CMMC 2.0
  • NIST 800-171
  • OneTrust
  • ServiceNow
  • Python
  • Linux
  • Bash
  • SQL

Leadership

Leadership

Treasurer → Vice President

ISSA Subchapter, University of Dallas · 2025–Present

Coordinate with the chapter president and officers to plan workshops, guest speaker events, and networking opportunities on cybersecurity trends and professional development. Manage club funds alongside running the events calendar.

Treasurer → Vice President → President

Rho Lambda Theta, Austin College · 2019–2022

Progressed through all three officer roles over four years. Started by managing the chapter's budget and financial records as Treasurer, moved into supporting executive decisions and event planning as Vice President, then led the organization directly as President.

Also

  • Member, Sigma Iota EpsilonUniversity of Dallas · 2025–Present

Community

Where I Show Up

Jose Garcia outside the Digital Fight Club cybersecurity event marquee
Digital Fight Club — Cybersecurity Event
Attendee lineup at the Seattle Data, AI & Security Global Security Tour
Global Security Tour — Seattle
Group at the University of Dallas Gupta College of Business
University of Dallas — Business Leadership Series
North Texas ISSA presenting a $10,000 scholarship check to the University of Dallas
NTX ISSA — $10K Scholarship Donation, University of Dallas
Small group at the ISSA Lunch and Learn at Maggiano's Little Italy
ISSA Lunch & Learn — Maggiano's, Little Italy
At the ISACA North Texas May 2026 chapter meeting
ISACA NTX — May 2026 Meeting
Jose Garcia outside the Digital Fight Club cybersecurity event marquee

Dallas, TX · 2026

Digital Fight Club

Live debate format where Dallas security leaders argue the year’s hardest questions.

Attendee lineup at the Seattle Data, AI & Security Global Security Tour

Seattle, WA · 2026

Global Security Tour

Data, AI and security sessions on how large programs govern third-party risk.

Group at the University of Dallas Gupta College of Business

Irving, TX · 2026

UD Business Leadership Series

Gupta College session connecting graduate students with practicing business leaders.

North Texas ISSA presenting a $10,000 scholarship check to the University of Dallas

Irving, TX · 2025

NTX ISSA Scholarship Donation

North Texas ISSA presenting a $10,000 scholarship to University of Dallas students.

Small group at the ISSA Lunch and Learn at Maggiano’s Little Italy

Dallas, TX · 2026

ISSA Lunch & Learn

Chapter lunch session on practical control testing and audit readiness.

At the ISACA North Texas May 2026 chapter meeting

Dallas, TX · May 2026

ISACA North Texas Chapter Meeting

Monthly chapter meeting on evolving audit, governance, and reporting expectations.

01 / 06

Get In Touch

Let's Talk

Looking for an entry level GRC, risk, or compliance analyst role in the Dallas area. Reach out directly, or grab the resume below.

Or view the resume directly.