Security Consultant
CurrentI conduct data security assessments through data discovery and classification, data security strategies, as well as activities focused on preventing data loss. In particular:• Development of documentation for the definition of the Information Security and Data Privacy Management System• GDPR Readiness Assessment: customer interviews evaluating the ISO29100 controls to identify security gaps in order to comply with the new data privacy legislation.• ISO / IEC 27001 Assessment: customer interviews evaluating the ISO27002 / 27017/27018 controls to identify security gaps with the aim of obtaining ISO 27001 certification or to sensitize management on the need to implement security solutions.• Business Impact Analysis methodology application: interviews with each of the company divisions to define and quantify the economic, reputational and regulatory impacts on each process in case of unavailability of IT services. Analysis of results and presentation of implementable solutions to management.