Global Cybersecurity Manager
Nashville, Tennessee, Us
Led the development, implementation, and oversight of a comprehensive enterprise cybersecurity and IT risk management controls program, ensuring the confidentiality, integrity, and availability of business systems and data. Served as a subject matter expert for all IT security components, data privacy, and threats, assuring the security of systems and data.Drafted and published IT security policies and procedures, and standards to establish a robust framework for cybersecurity governance. Such policies include Multi-factor Authentication (MFA), Secure Data Disposal, Data Retention, Password Management, Security Awareness Training, Secure Workstation Configuration Standard, and others. Managed external security audits and assessments to identify security gaps and vulnerabilities based on NIST CSF and similar frameworks and followed up with cross-functional teams to develop remediation plans. Achieved an 82% compliance rate within first 6 months of employment.Provided oversight into the daily security operations including, security logging and monitoring, endpoint security tools, vulnerability scanning and patch management tools, coordinating with cross-functional teams, such as infrastructure, networking, to develop and document runbooks to ensure business continuity planning. Maintained a high-security posture across all business systems. Improved cybersecurity and business resiliency by defining and creating baselines for hardening user systems and improving IT process related to security and business continuity.Analyzed and managed security incidents, investigating and responding promptly to mitigate potential threats. Provided executive management with monthly cybersecurity status reports, regularly reporting metrics and KPIs on the corporate IT security program.Managed and conducted the KnowBe4 Cybersecurity Awareness Training, including simulated phishing email campaigns for all users. Managed the cybersecurity budget and all cybersecurity spending.