Brian Koref Email and Phone Number
Brian Koref work email
- Valid
- Valid
- Valid
Brian Koref personal email
- Valid
Brian Koref phone numbers
► CISSP, ISSMP, Certified ISO 27001:2022 Lead Implementer► Highly skilled Enterprise Security professional who is knowledgeable of the vulnerabilities of applications and traditional/cloud environments and how hackers are able to exploit.► Business and security technology leader with hands on working knowledge and practical experience applying security technologies within a global business landscape.► Lead operational risk management activities to enhance the value of the company and brand.► Former federal computer crime investigator in Intrusions and Forensics.► Standards based experience (ISO 27001, PCI, NIST 800-53, HIPAA, SSAE 18, SOC 2, GDPR / Privacy).► Hands on technical and leadership experience in Network Security, Incident Response, Advanced Endpoint Protection, M&A due diligence, Security Awareness and Training, Firewalls, Intellectual Property Protection, API Security, Vulnerability Management, Security Architecture, Threat Hunting, Sec OPS, E-Discovery, SDLC, Data Loss Prevention (DLP), Security and Event Management (SIEM), Cloud/SaaS (AWS) Security, AI/ML security / governance.
Self-Employed
View-
Self-EmployedSan Francisco Bay Area
-
Head Of Information SecurityCaastle Jul 2024 - PresentNew York, Us -
Cyber Security ConsultantSelf-Employed Jun 2023 - Present
-
AdvisorValence Mar 2024 - PresentNew York City, New York, Us -
Cyber Security AdvisorLightup Data May 2020 - PresentMountain View, Ca, Us -
Consultant / VcisoHebbia Jan 2024 - Jun 2024New York, Ny, Us -
Chief Information Security OfficerSisense Feb 2022 - Jun 2023New York, New York, Us► Lead and mentored global team of security professionals responsible for functions to include: IT, GRC, Application and Product Security, Security Operations, Supplier Security, Incident Response, Vulnerability Management,, Pen Testing and Sales Enablement► Responsible for defining, driving and maintaining a comprehensive strategy that addressed security, risk and compliance requirements, to include SOC 2, HIPAA, ISO 27001, and FedRamp► Established a mature SDLC security process resulting in measurable decrease in vulnerabilities; authored, obtained consensus, and drove adoption of a contextual exploitability blueprint and narrative► Managed internal and outsourced Security Operations functions used to monitor corporate and production resources► Managed and optimized the security budget, negotiated discounts and other creative cost saving initiatives► Developed, maintained and presented security metrics, scorecards and key performance indicators (KPI) for both interdepartmental and exec leadership► Responsible for sales enablement activities to include customer meetings and escalations, attendance at industry conferences, defining and presenting customer facing security strategy, roadmap and other relevant materials► Served as a trusted consultant to the business on topics of security, risk management and corporate strategy► Implemented a Security Champions program to extend security visibility and responsibility across the enterprise► Participated in corporate strategy meetings that enabled revenue generation and maintained cash flow -
Senior Director, Information Security And Privacy OfficerSage Intacct Software Sep 2014 - Nov 2021Dublin, IeRecruited to establish strategy and manage a world class information security program in preparation for IPO or acquisition. Senior Director, Information Security and Privacy Officer | Head of Security► Established and managed the Information Security Program, budget and security personnel.► Collaborated with operations, engineering, IT, HR, legal and other business units to manage risk.► Identified, established and audited security requirements for migration and use of AWS environments. Deployed technology to audit and identify AWS specific security events.► Developed and managed data governance programs for AI / ML initiatives and other business processes.► Managed PCI-DSS (Full ROC), SSAE 18, SOC 2, GDPR and HIPAA compliance to include identification of controls, generation and collection of evidence and engagement with audit firms.► Partnered with Product Management to drive and enhance security related product features and bug fixes, provided security requirements and oversight to the Agile Software Development Lifecycle (SDLC).► Represented Intacct during sales engagements and responded to inquiries related to security and privacy.► Presented on various security topics at both company, partner and industry events.► Chaired security, risk and governance steering committees to prioritize to drive change to decrease risk.► Authored security policies, processes and standards and obtain appropriate executive support/approval.► Drove global security awareness and training for workers, developers, and partners.► Established and managed a vendor/supplier security program to manage risks to corporate and customer data.► Executed and managed internal and third-party vulnerability management and pen testing engagements.► Established and managed the Incident Response process and conducted exercises to test and measure effectiveness.► Served on the Mergers and Acquisition team providing security due diligence for potential targets. -
Director, Information SecurityInformatica Corporation Oct 2010 - Sep 2014Redwood City, Ca, UsResponsible for the global Information Security program. Defined and authored security standards/policies, provide security oversight, and drive security projects that reduce risk.► Established a Data Handling program to identify, control and minimize loss of corporate and customer sensitive data.► Identified, deployed and managed the following technologies: Data Leak Prevention (DLP), Two-Factor Authentication, Security Incident and Event Management (SIEM), File Encryption, End Point Protection.► Established and managed a 24x7 Security Operations Center responsible for Incident Analysis and Response, Audit/Compliance and Vulnerability Assessments.► Represented security at Change Control, Architecture Review Boards and Customer Engagements.► Review and responded to customer security RFI's and contracts.► Managed both internal and external third party (SOX, PCI, HIPPA) audits and associated remediation.► Responsible for providing security requirements and guidance on NAC, Mobile Device Management, BYOD/BYOPC, Hybrid Cloud, Virtual Machine Management, E-Commerce integrations.► Established, implemented and maintain a global security awareness and training program.► Established, maintained and presented metrics which measure the security function and corporate risk.► Led, conducted security reviews and defined requirements for Mergers and Acquisitions.► Identified protection goals, objectives and metrics consistent with the corporate strategic plan.► Maintained relationships with local, state, federal and international law enforcement agencies.► Responsible for incident response planning as well as the investigation of security breaches. -
Senior Manager / Information Security OfficerKla-Tencor Corporation Jun 2005 - Oct 2010Milpitas, California, UsHired as KLA-Tencor’s first Information Security Officer, charged with maturing and building an information security program, hiring staff and implementing technology, policies and processes to minimize risk.► Created and managed the information security function to include operations, engineering and architecture.► Responsible for product selection, testing and rollout of Disk Encryption, Digital Rights Management, Two-Factor authentication, content monitoring and filtering, SOX automation tools, SSL-VPN, IDS/IPS.► Responsible for addressing Intellectual Property protection initiatives to prevent the theft of sensitive data.► Researched and tracked new and emerging technologies used to respond to business and customer demands.► Developed security architectures that supported goals of end-to-end authentication, authorization, confidentiality, transactional integrity, non- repudiation and availability of key critical business applications.► Served as the Information Security Project Manager for all information security initiatives.► Perform end to end information security assessments on existing, new and purchased applications, systems and networks to include PLM, CRM, Blackberry, IP Telephony, M&A Activity.► Created information security balanced scorecard metrics to effectively measure ROI, risk reduction and provide status. -
Senior Security EngineerVeritas Software Dec 2001 - Jun 2005San Jose, California, UsResponsible for planning, installation, configuration, maintenance and support of various security applications.► Planned and conducted audit, assessments and penetration testing of core enterprise infrastructure and applications.► Conducted research and tracked new and emerging technologies to respond to business and customer demands.► Served as key member of Sarbanes Oxley team: identified IT control objectives, test and recommend solutions.► Built, configured and managed the Veritas enterprise RSA SecureID multi-factor authentication environment.► Utilized EnCase forensics software to support forensics analysis for internal investigations. -
Security ArchitectAaa May 2001 - Nov 2001UsConsulted with various business units to provide security direction, recommend methods and procedures to secure CSAA assets.Technical lead for various security initiatives. Performed security design review and assessments regarding all third party engagements. Served as the approval authority for all security related service requests. Reviewed and ensured compliance with current mandates to include HIPPA, Graham Leach Bliley, AICPA attestations (i.e. Webtrust, Systrust) -
Senior Manager, Information SecurityPortera Systems Sep 2000 - Apr 2001Built, from ground up, the Information Security program to satisfy both IT and external customer requirements. Developed strategic and tactical roadmaps. Implemented and enforced security policies.Supervised team of Security Engineers, analysts and other cross-functional assets -
Special Agent - Computer Crime InvestigatorAir Force Office Of Special Investigations (Afosi) 1993 - 1998Quantico, Va, UsSpecial Agent | Computer Crime InvestigatorInvestigated computer intrusion (hacker), child pornography, espionage, fraud and other felony Computer Crime investigations for the Mid-Atlantic States. Provided court testimony, trained DOJ US Attorney’s on Network Security, and conducted computer forensic media analysis on seized evidence. Selected to assist in the Lewinsky/Clinton matter by providing forensic analysis of evidence.
Brian Koref Skills
Brian Koref Education Details
-
Webster UniversityInformation Systems -
Southern Illinois University, CarbondaleEducation
Frequently Asked Questions about Brian Koref
What company does Brian Koref work for?
Brian Koref works for Self-Employed
What is Brian Koref's role at the current company?
Brian Koref's current role is Chief Information Security Officer | Cyber Security Consultant | Advisor.
What is Brian Koref's email address?
Brian Koref's email address is bk****@****cct.com
What is Brian Koref's direct phone number?
Brian Koref's direct phone number is (617)-305*****
What schools did Brian Koref attend?
Brian Koref attended Webster University, Southern Illinois University, Carbondale.
What skills is Brian Koref known for?
Brian Koref has skills like Information Security, Security, Penetration Testing, Computer Security, Computer Forensics, Network Security, Information Security Management, Vulnerability Assessment, Cissp, Security Policy, Dlp, Enterprise Architecture.
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial