Andrew Stravitz
AeroLeads people directory · profile

Andrew Stravitz Email & Phone Number

vCISO, CISSP, CISM & ITIL | Security Transformation | Regulatory Compliance & GRC | Critical Infrastructure | OT ICS SCADA | President of Park Toastmasters Club at Touchpoint Cyber
Location: Allendale, New Jersey, United States 12 work roles 2 schools
1 work email found @veolia.com 7 phones found area 212 and 201 LinkedIn matched
✓ Verified May 2026 4 data sources Profile completeness 100%

Contact Signals · 1 work email · 7 phones

Work email a****@veolia.com
Direct phone (212) ***-****
LinkedIn Profile matched
3 free lookups remaining · No credit card
Current company
Role
vCISO, CISSP, CISM & ITIL | Security Transformation | Regulatory Compliance & GRC | Critical Infrastructure | OT ICS SCADA | President of Park Toastmasters Club
Location
Allendale, New Jersey, United States

Who is Andrew Stravitz? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Andrew Stravitz is listed as vCISO, CISSP, CISM & ITIL | Security Transformation | Regulatory Compliance & GRC | Critical Infrastructure | OT ICS SCADA | President of Park Toastmasters Club at Touchpoint Cyber, based in Allendale, New Jersey, United States. AeroLeads shows a work email signal at veolia.com, phone signal with area code 212, 201, and a matched LinkedIn profile for Andrew Stravitz.

Andrew Stravitz previously worked as Founder (IT Risk & Cybersecurity Consultant) at Touchpoint Cyber and BISO, Senior Director DB&T at Veolia North America. Andrew Stravitz holds Master Of Science - Ms, Accounting from Pace University - Lubin School Of Business.

Company email context

Email format at Touchpoint Cyber

This section adds company-level context without repeating Andrew Stravitz's masked contact details.

{first}.{last}@veolia.com
86% confidence

AeroLeads found 1 current-domain work email signal for Andrew Stravitz. Compare company email patterns before reaching out.

Profile bio

About Andrew Stravitz

Professional Profile:Seasoned information security professional protecting national critical infrastructure, holding CISSP, CISM and ITIL certifications with over 20 years of management and technical experience as innovative leader. Managed and mentored staff at all levels of the organization on a variety of information security initiatives, building strong teams to protect corporate assets. Provided input to industry leading vendors for numerous product enhancements, and commentary on regulatory legislation. Extensive experience in implementing web application security, rapid incident response programs and operating in a highly regulated environment. Developed impactful and measurable security awareness training.• Security Transformation • IS Strategy & Execution • Executive reporting (metrics) • Program development • Information risk management • Security architecture • Security roadmap • Regulatory compliance • Business continuity planning • Strong cryptology design knowledge• Business Resilience • Security in the cloud • Critical Infrastructure (Financial & OT ICS SCADA) Accomplishments:Developed new information security and computer risk management programs from inception based on the NIST, ISO27001 and PCI DSS standards. Authored numerous security articles, white papers, information security policies and performed security risk assessments. Presented on a variety of security topics, including web application security, data-centric approach, security awareness and information risk management. Speaking engagements as a SME at Evanta, IANS conferences, SC Magazine, CISO Executive Summit, Security 500, Tech Managers Forum and Polytechnic University. Executive Skills:• Executive & Board level reporting (metrics) • Program development • Information risk management • Security architecture • Security roadmap • Regulatory compliance • Business continuity planning • Strong cryptology design knowledge • Expert level knowledge of the PCI Standard • BudgetingContact me at astravitz@yahoo.com

Listed skills include Information Security, Security, Computer Security, Cissp, and 25 others.

Current workplace

Andrew Stravitz's current company

Company context helps verify the profile and gives searchers a useful next step.

Touchpoint Cyber
Touchpoint Cyber
vCISO, CISSP, CISM & ITIL | Security Transformation | Regulatory Compliance & GRC | Critical Infrastructure | OT ICS SCADA | President of Park Toastmasters Club
AeroLeads page
12 roles

Andrew Stravitz work experience

A career timeline built from the work history available for this profile.

Founder (It Risk & Cybersecurity Consultant)

Current

Allendale, New Jersey, US

I'm excited to announce the launch of "Touchpoint Cyber LLC." I've been fortunate to launch an IT Risk and Cybersecurity consulting practice. My first client is located in Connecticut, and is a prestigious "Asset Management Firm / Hedge Fund." I've been helping with their SOC1 preparation, risk assessments and security program development. I'm available to.

Nov 2023 - Present

Biso, Senior Director Db&T

Boston, MA, US

  • Veolia fully acquired SUEZ in Q2 2022 forming the largest water utility worldwide
  • Promoted to Sr. Director to focus supporting on the Municipal Water Business Unit post-merger
  • Responsible for GRC program development, vendor risk management (VRM), RFP new business generation, critical infrastructure framework (OT, ICS, SCADA) and training development
  • Architected Nozomi SCADA security solution to provide OT/IoT near real-time inventory, vulnerability management, alerting and risk prioritization based on Perdue Model mapping to ISA/IEC 62443
  • Lead the effort to produce both SOC1 and SOC2 reports to support regulated utility BU
Jun 2022 - Oct 2023

Regional Ciso Of North America, Director Of It Risk & Security

Paris, Ile De France, FR

  • Part of the Global Cybersecurity Strategy team developing roadmap and executing vision
  • Developed NIST Policy framework and governance risk and compliance program (GRC)
  • Responsible for overseeing all aspects of regulatory framework, and securing critical SCADA infrastructure, rollout of IPS/IDS, MSSP, incident response procedures, and security architecture
  • Implementing IT-GRC program based on NIST and ISO27001 security frameworks
  • Rolled out next generation end-point security (EDR) in both corporate and SCADA networks
  • Building and mentoring a highly effective cybersecurity team, rolled out centralized SOC, firewall audit tools, and set up comprehensive vulnerability management system (Rapid7 Certified)
Jun 2017 - Jun 2022

Information Security Officer, Vp (Ciso Of Americas Office)

Frankfurt Am Main, Hessen, DE

  • Lead the NYS-DFS 500 interpretation, resource planning, project management
  • Completed the responses of the FFIEC Cybersecurity Maturity Assessment Tool
  • Handled audit and regulatory responses
Sep 2016 - Jun 2017

Fvp, Ciso

New York, NY, US

  • Transformed the information security program by assessing, identifying and creating an information security roadmap and multi-year projected budget.
  • Coordinated the annual Disaster Recover and Business Contingency Planning test(s).
  • Mapped the internal control structure against the newly established FFIEC / FSSCC Cybersecurity Assessment Tool (494 mapped controls) to determine the maturity level of the bank.
  • Created and presented the InfoSec Dashboard to the Board of Directors, providing relevant metrics on the state of the InfoSec program. Co-chair of the IT/IS Steering Committee.
  • Resolved numerous preexisting audit, compliance and regulatory issues (GLBA) by formulating response plan, tracking documentation, and executing remediation plans.
  • Improved the resiliency of the network perimeter, implementing APT detection strategy and preventive controls on end-points, designed new NAC strategy with 802.1x Radius integration, VPN redesign, privileged account.
Oct 2014 - May 2016

Principal Of Information Security

New York, NY, US

  • Created, architected, and engineered the security road map, which aligned the information security initiatives to focus on high-risk areas
  • Managed Information Security Special Projects, reporting directly to CISO
  • Realigned the Web Application Firewall (WAF) strategy; RFI, RFP and global implementation
  • Assumed responsibility for policies, standards, procedures, and guidelines
  • Lead effort to combat advanced persistent threats (APT’s)
  • Authored a series of strategy documents including cloud security directive, database security, highly confidential initiatives, legal and regulatory compliance, and MSSP project
Nov 2011 - Jul 2014

Director Of Information Security

New York, US

  • Dedicated and proven leader who championed a highly effective information security program for 8 years at B&N.com; thwarting numerous attempted external threats.
  • Oversee all security related audits and regulatory activity, including Sarbanes Oxley, PCI DSS, etc.
  • Responsible for all aspects of the Information Security Program based on ISO 17799 framework
  • Incorporated secure development lifecycle working with developers and defect management
  • Developed the credit card encryption methodology used universally across all business lines
  • Manage and supervise IT security staff and consultants – including “NOOK” independent review
Nov 2003 - Oct 2011

Ing Bank Security Consultant

Ing

Amsterdam, North Holland, NL

  • Developed Strategy as part of core team in Global Office of the CISO
  • International assignment, lead a variety of security audits based on BS7799
  • Performed Risk Assessments against industry best practices, ISO17799, OCTAVE (CERT)
  • Assessed information systems for vulnerabilities using third-party tools (GFI, NetIQ, etc.)
May 2002 - Oct 2003

Chief Technology Officer

Tel Aviv, IL

  • Developed a new US based internet startup from seed money from parent company, as part of the CEO’s immediate executive team
  • Responsible for all aspects of the project development
  • Authored IT banking policies and procedures for the business plan and approved by the OCC
  • Designed web front-end to the legacy Alltel Systematics
  • Fortified the Banks perimeter building out security stack and high availability infrastructure
  • Managed a 5-million-dollar budget
Oct 2000 - May 2002

Corporate Security

Ing

Amsterdam, North Holland, NL

  • Authored and reviewed Policies and Procedures, including: TCP/IP Policy, Antivirus Policy, Firewall Policy, SWIFT procedures, Laptop Policy, Internet Usage Policy, and Security Awareness Program.
  • Lead project manager of team that secured company laptops world-wide. Implemented the PKI backbone with ODBC replication in New York, London, Hong Kong & Amsterdam offices.
  • Lectured to new and existing employees as part of a security awareness training initiative.
  • Assisted in the Y2K implementation of the SWIFT Alliance Application (UNIX Platform) from ST400 (Dec Vax).
Jul 1999 - Oct 2000

Assistant Vice President

Zurich, Zürich, CH

  • Responded to security related outstanding audit points and implemented solutions.
  • Implemented the first Internet connection at the NY Branch providing secure web and email access.
  • Network Administration for the following products: Windows NT, MS Exchange Server, Guardian Firewall, Little Brother (Proxy Filter), McAfee Antivirus, PGP Encryption, DHCP, WINS and MS Proxy Server.
  • Administrated Open VMS (VAX/VMS V.71) on the VAX; and OS/400 on the AS/400.
  • Administered various financial systems in the bank including: SWIFT(VMS), Wall Street System (DEC/VAX), Maxdata (UNIX), EBS, Windows NT, Novell, Exchange Server, Firewall, Proxy Server, and Midas (AS/400).
  • Generated and reviewed daily logs on various Bank systems (e.g. PS Audit logs on AS/400).
Nov 1997 - Jul 1999

Vice President

Montreal, QC, CA

  • Performed security reviews with end users & created firm security policy, including Windows NT.
  • Supervised a staff of six employees that supported the correspondent clearing business.
  • Implemented system security in a multi-platform environment, including Windows NT, Apple Talk, AS/400, Mainframe & Encryption.
  • Investigated legal issues using forensic computer techniques, restored Novell and NT servers using Arc serve and other specialized software.
  • Developed, designed and tested new and existing mainframe applications for strong security controls.
  • Administered Top Secret Security in a MVS / CICS environment.
Jul 1995 - Nov 1997
2 education records

Andrew Stravitz education

Master Of Science - Ms, Accounting

Pace University - Lubin School Of Business

Bachelor Of Science - Bs, Psychology Minor: Computer Science, Economics

Stony Brook University
FAQ

Frequently asked questions about Andrew Stravitz

Quick answers generated from the profile data available on this page.

What company does Andrew Stravitz work for?

Andrew Stravitz works for Touchpoint Cyber.

What is Andrew Stravitz's role at Touchpoint Cyber?

Andrew Stravitz is listed as vCISO, CISSP, CISM & ITIL | Security Transformation | Regulatory Compliance & GRC | Critical Infrastructure | OT ICS SCADA | President of Park Toastmasters Club at Touchpoint Cyber.

What is Andrew Stravitz's email address?

AeroLeads has found 1 work email signal at @veolia.com for Andrew Stravitz at Touchpoint Cyber.

What is Andrew Stravitz's phone number?

AeroLeads has found 7 phone signal(s) with area code 212, 201 for Andrew Stravitz at Touchpoint Cyber.

Where is Andrew Stravitz based?

Andrew Stravitz is based in Allendale, New Jersey, United States while working with Touchpoint Cyber.

What companies has Andrew Stravitz worked for?

Andrew Stravitz has worked for Touchpoint Cyber, Veolia North America, Suez, Deutsche Bank, and Safra National Bank Of New York.

How can I contact Andrew Stravitz?

You can use AeroLeads to view verified contact signals for Andrew Stravitz at Touchpoint Cyber, including work email, phone, and LinkedIn data when available.

What schools did Andrew Stravitz attend?

Andrew Stravitz holds Master Of Science - Ms, Accounting from Pace University - Lubin School Of Business.

What skills is Andrew Stravitz known for?

Andrew Stravitz is listed with skills including Information Security, Security, Computer Security, Cissp, Application Security, Penetration Testing, Network Security, and Vulnerability Assessment.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.