Brian Koref

Brian Koref Email and Phone Number

Chief Information Security Officer | Cyber Security Consultant | Advisor @ Self-employed
San Francisco Bay Area
Brian Koref's Location
Mountain View, California, United States, United States
Brian Koref's Contact Details

Brian Koref personal email

Brian Koref phone numbers

About Brian Koref

► CISSP, ISSMP, Certified ISO 27001:2022 Lead Implementer► Highly skilled Enterprise Security professional who is knowledgeable of the vulnerabilities of applications and traditional/cloud environments and how hackers are able to exploit.► Business and security technology leader with hands on working knowledge and practical experience applying security technologies within a global business landscape.► Lead operational risk management activities to enhance the value of the company and brand.► Former federal computer crime investigator in Intrusions and Forensics.► Standards based experience (ISO 27001, PCI, NIST 800-53, HIPAA, SSAE 18, SOC 2, GDPR / Privacy).► Hands on technical and leadership experience in Network Security, Incident Response, Advanced Endpoint Protection, M&A due diligence, Security Awareness and Training, Firewalls, Intellectual Property Protection, API Security, Vulnerability Management, Security Architecture, Threat Hunting, Sec OPS, E-Discovery, SDLC, Data Loss Prevention (DLP), Security and Event Management (SIEM), Cloud/SaaS (AWS) Security, AI/ML security / governance.

Brian Koref's Current Company Details
Self-employed

Self-Employed

View
Chief Information Security Officer | Cyber Security Consultant | Advisor
San Francisco Bay Area
Brian Koref Work Experience Details
  • Self-Employed
    Self-Employed
    San Francisco Bay Area
  • Caastle
    Head Of Information Security
    Caastle Jul 2024 - Present
    New York, Us
  • Self-Employed
    Cyber Security Consultant
    Self-Employed Jun 2023 - Present
  • Valence
    Advisor
    Valence Mar 2024 - Present
    New York City, New York, Us
  • Lightup Data
    Cyber Security Advisor
    Lightup Data May 2020 - Present
    Mountain View, Ca, Us
  • Hebbia
    Consultant / Vciso
    Hebbia Jan 2024 - Jun 2024
    New York, Ny, Us
  • Sisense
    Chief Information Security Officer
    Sisense Feb 2022 - Jun 2023
    New York, New York, Us
    ► Lead and mentored global team of security professionals responsible for functions to include: IT, GRC, Application and Product Security, Security Operations, Supplier Security, Incident Response, Vulnerability Management,, Pen Testing and Sales Enablement► Responsible for defining, driving and maintaining a comprehensive strategy that addressed security, risk and compliance requirements, to include SOC 2, HIPAA, ISO 27001, and FedRamp► Established a mature SDLC security process resulting in measurable decrease in vulnerabilities; authored, obtained consensus, and drove adoption of a contextual exploitability blueprint and narrative► Managed internal and outsourced Security Operations functions used to monitor corporate and production resources► Managed and optimized the security budget, negotiated discounts and other creative cost saving initiatives► Developed, maintained and presented security metrics, scorecards and key performance indicators (KPI) for both interdepartmental and exec leadership► Responsible for sales enablement activities to include customer meetings and escalations, attendance at industry conferences, defining and presenting customer facing security strategy, roadmap and other relevant materials► Served as a trusted consultant to the business on topics of security, risk management and corporate strategy► Implemented a Security Champions program to extend security visibility and responsibility across the enterprise► Participated in corporate strategy meetings that enabled revenue generation and maintained cash flow
  • Sage Intacct Software
    Senior Director, Information Security And Privacy Officer
    Sage Intacct Software Sep 2014 - Nov 2021
    Dublin, Ie
    Recruited to establish strategy and manage a world class information security program in preparation for IPO or acquisition. Senior Director, Information Security and Privacy Officer | Head of Security► Established and managed the Information Security Program, budget and security personnel.► Collaborated with operations, engineering, IT, HR, legal and other business units to manage risk.► Identified, established and audited security requirements for migration and use of AWS environments. Deployed technology to audit and identify AWS specific security events.► Developed and managed data governance programs for AI / ML initiatives and other business processes.► Managed PCI-DSS (Full ROC), SSAE 18, SOC 2, GDPR and HIPAA compliance to include identification of controls, generation and collection of evidence and engagement with audit firms.► Partnered with Product Management to drive and enhance security related product features and bug fixes, provided security requirements and oversight to the Agile Software Development Lifecycle (SDLC).► Represented Intacct during sales engagements and responded to inquiries related to security and privacy.► Presented on various security topics at both company, partner and industry events.► Chaired security, risk and governance steering committees to prioritize to drive change to decrease risk.► Authored security policies, processes and standards and obtain appropriate executive support/approval.► Drove global security awareness and training for workers, developers, and partners.► Established and managed a vendor/supplier security program to manage risks to corporate and customer data.► Executed and managed internal and third-party vulnerability management and pen testing engagements.► Established and managed the Incident Response process and conducted exercises to test and measure effectiveness.► Served on the Mergers and Acquisition team providing security due diligence for potential targets.
  • Informatica Corporation
    Director, Information Security
    Informatica Corporation Oct 2010 - Sep 2014
    Redwood City, Ca, Us
    Responsible for the global Information Security program. Defined and authored security standards/policies, provide security oversight, and drive security projects that reduce risk.► Established a Data Handling program to identify, control and minimize loss of corporate and customer sensitive data.► Identified, deployed and managed the following technologies: Data Leak Prevention (DLP), Two-Factor Authentication, Security Incident and Event Management (SIEM), File Encryption, End Point Protection.► Established and managed a 24x7 Security Operations Center responsible for Incident Analysis and Response, Audit/Compliance and Vulnerability Assessments.► Represented security at Change Control, Architecture Review Boards and Customer Engagements.► Review and responded to customer security RFI's and contracts.► Managed both internal and external third party (SOX, PCI, HIPPA) audits and associated remediation.► Responsible for providing security requirements and guidance on NAC, Mobile Device Management, BYOD/BYOPC, Hybrid Cloud, Virtual Machine Management, E-Commerce integrations.► Established, implemented and maintain a global security awareness and training program.► Established, maintained and presented metrics which measure the security function and corporate risk.► Led, conducted security reviews and defined requirements for Mergers and Acquisitions.► Identified protection goals, objectives and metrics consistent with the corporate strategic plan.► Maintained relationships with local, state, federal and international law enforcement agencies.► Responsible for incident response planning as well as the investigation of security breaches.
  • Kla-Tencor Corporation
    Senior Manager / Information Security Officer
    Kla-Tencor Corporation Jun 2005 - Oct 2010
    Milpitas, California, Us
    Hired as KLA-Tencor’s first Information Security Officer, charged with maturing and building an information security program, hiring staff and implementing technology, policies and processes to minimize risk.► Created and managed the information security function to include operations, engineering and architecture.► Responsible for product selection, testing and rollout of Disk Encryption, Digital Rights Management, Two-Factor authentication, content monitoring and filtering, SOX automation tools, SSL-VPN, IDS/IPS.► Responsible for addressing Intellectual Property protection initiatives to prevent the theft of sensitive data.► Researched and tracked new and emerging technologies used to respond to business and customer demands.► Developed security architectures that supported goals of end-to-end authentication, authorization, confidentiality, transactional integrity, non- repudiation and availability of key critical business applications.► Served as the Information Security Project Manager for all information security initiatives.► Perform end to end information security assessments on existing, new and purchased applications, systems and networks to include PLM, CRM, Blackberry, IP Telephony, M&A Activity.► Created information security balanced scorecard metrics to effectively measure ROI, risk reduction and provide status.
  • Veritas Software
    Senior Security Engineer
    Veritas Software Dec 2001 - Jun 2005
    San Jose, California, Us
    Responsible for planning, installation, configuration, maintenance and support of various security applications.► Planned and conducted audit, assessments and penetration testing of core enterprise infrastructure and applications.► Conducted research and tracked new and emerging technologies to respond to business and customer demands.► Served as key member of Sarbanes Oxley team: identified IT control objectives, test and recommend solutions.► Built, configured and managed the Veritas enterprise RSA SecureID multi-factor authentication environment.► Utilized EnCase forensics software to support forensics analysis for internal investigations.
  • Aaa
    Security Architect
    Aaa May 2001 - Nov 2001
    Us
    Consulted with various business units to provide security direction, recommend methods and procedures to secure CSAA assets.Technical lead for various security initiatives. Performed security design review and assessments regarding all third party engagements. Served as the approval authority for all security related service requests. Reviewed and ensured compliance with current mandates to include HIPPA, Graham Leach Bliley, AICPA attestations (i.e. Webtrust, Systrust)
  • Portera Systems
    Senior Manager, Information Security
    Portera Systems Sep 2000 - Apr 2001
    Built, from ground up, the Information Security program to satisfy both IT and external customer requirements. Developed strategic and tactical roadmaps. Implemented and enforced security policies.Supervised team of Security Engineers, analysts and other cross-functional assets
  • Air Force Office Of Special Investigations (Afosi)
    Special Agent - Computer Crime Investigator
    Air Force Office Of Special Investigations (Afosi) 1993 - 1998
    Quantico, Va, Us
    Special Agent | Computer Crime InvestigatorInvestigated computer intrusion (hacker), child pornography, espionage, fraud and other felony Computer Crime investigations for the Mid-Atlantic States. Provided court testimony, trained DOJ US Attorney’s on Network Security, and conducted computer forensic media analysis on seized evidence. Selected to assist in the Lewinsky/Clinton matter by providing forensic analysis of evidence.

Brian Koref Skills

Information Security Security Penetration Testing Computer Security Computer Forensics Network Security Information Security Management Vulnerability Assessment Cissp Security Policy Dlp Enterprise Architecture Risk Management Vulnerability Management Pci Dss Security Audits Intrusion Detection Application Security Security Architecture Design Vpn Encryption Cloud Security Security Metrics Siem Payment Card Industry Data Security Standard Hipaa Incident Response Two Factor Authentication Data Leak Prevention Security Architecture Presentation To Executive Staff Ssae 18 Iso 27001 Soc 2 Gdpr Software As A Service Cloud Computing Security Awareness Disaster Recovery Program Management Strategy Integration Information Technology Management Business Continuity Sales Communication Iso Standards General Data Protection Regulation U.s. Health Insurance Portability And Accountability Act

Brian Koref Education Details

  • Webster University
    Webster University
    Information Systems
  • Southern Illinois University, Carbondale
    Southern Illinois University, Carbondale
    Education

Frequently Asked Questions about Brian Koref

What company does Brian Koref work for?

Brian Koref works for Self-Employed

What is Brian Koref's role at the current company?

Brian Koref's current role is Chief Information Security Officer | Cyber Security Consultant | Advisor.

What is Brian Koref's email address?

Brian Koref's email address is bk****@****cct.com

What is Brian Koref's direct phone number?

Brian Koref's direct phone number is (617)-305*****

What schools did Brian Koref attend?

Brian Koref attended Webster University, Southern Illinois University, Carbondale.

What skills is Brian Koref known for?

Brian Koref has skills like Information Security, Security, Penetration Testing, Computer Security, Computer Forensics, Network Security, Information Security Management, Vulnerability Assessment, Cissp, Security Policy, Dlp, Enterprise Architecture.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.