Brian Serra

Brian Serra Email and Phone Number

Cybersecurity & Compliance Leader. Enhancing information security maturity across the IT enterprise and operational technology / industrial controls environments. Mentoring the next generation of cyber leaders. @ Target
Brian Serra's Location
Minneapolis, Minnesota, United States, United States
Brian Serra's Contact Details

Brian Serra work email

Brian Serra personal email

n/a
About Brian Serra

Dynamic compliance leader with diverse industry expertise from delivering executive-level consulting to thousands of clients. Builder of compliance programs and streamlining existing consulting processes to reduce operating overhead. Team leader with a strong technical background who is able to digest the most complex concepts to deliver executive-level action plans in a clear fashion. A rock-solid, hands-on leader that is calm under pressure, thinking clearly to be able to deliver on business objectives. Ethical and well respected by the clients and colleagues I have worked with throughout my career.Has performed thousands of assessments against the published security standards. Evaluated current security controls to provide the detailed next-steps for compliance. Product management of payment tokenization/encryption solutions in order to enable clients to reduce their risk and be in-line with compliance requirements. Data discovery of systems that transmit or store confidential information. Then developed feasible solutions that would protect data in accordance security standards and regulations.Written enterprise information security policies addressing needs that have arisen from formal risk management evaluations. Also assisted in multiple business continuation and disaster recovery planning projects. Incident response by performing security consulting and testing against defaced web systems to identify the hacker’s point of entry. Has performed as a long-term “acting” Information Security Manager for a large direct-sales manufacturer to address the following areas: • Security project management, Security awareness and Incident response• Driving an internal project to bring the company into compliance with security and compliance standards• Delivery of technical security assessments• Security architecture design, Physical security and System security hardeningSpecialties: PCI (QSA, ASV, PA-DSS)ISOHIPAAExperian EI3PA

Brian Serra's Current Company Details
Target

Target

View
Cybersecurity & Compliance Leader. Enhancing information security maturity across the IT enterprise and operational technology / industrial controls environments. Mentoring the next generation of cyber leaders.
Brian Serra Work Experience Details
  • Target
    Business Information Security Office (Biso) Lead
    Target Oct 2021 - Present
    Minneapolis, Mn, Us
    Lead BISO for Target's supply chain distribution center facilities and operations. Heavy focus on Operational Technology (OT) security and risk identification within our Global Supply Chain and Logistics organization.Leading security assessments covering IT and OT operational technology/ICS industrial controls at Target's supply chain facilities and processes. Developed and delivered the first security maturity assessment using a customized control framework, successfully identifying critical areas of security risk, resulting in targeted security recommendations and roadmap that drove the business to become a partner in overall security and risk ownership.Providing management consulting in cyber security, risk and governance direction to the stores and supply chain portfolio business lines, developing roadmaps to maintain or decrease security risk. Evaluated third-party vendors supporting OT/IT to co-develop security requirements for agreements and contracts for support to decrease risk and assign security ownership.
  • Target
    Payment Security Lead
    Target Sep 2018 - Oct 2021
    Minneapolis, Mn, Us
    Selected by the international PCI Security Standards Council to deliver a presentation on cloud Hardware Security Modules (HSM) at the largest Payment Security Community Meeting conference.Spearheaded a significant initiative that had a direct impact on Target’s financial and security assurance. The project marked the first-ever cross-functional validation of a Point-to-Point Encryption (P2PE) Merchant Managed Solution (MMS) at Target. The objective of the project was to eliminate the potential financial risk associated with the organization's investment in Point of Sale (POS) solutions, should the acquiring bank no longer allow unvalidated in-house solutions. We obtained validation of the P2PE MMS and we were able to significantly reduce the organization's risk exposure.Delivered multiple PCI assessment activities for Target retail and RedCard servicing, playing a crucial role in ensuring that the assessments were executed smoothly, completed on time, and within budget constraints and more importantly deemed within compliance with PCI. Conducted risk assessments to evaluate the current state of security within the enterprise. Utilizing expertise in risk management, I was able to offer valuable recommendations aimed at minimizing risk to the organization. Maintained focus on risk reduction, carefully monitoring the impact of the solutions and making necessary adjustments to ensure ongoing success.Leader of other special projects, undertaking the responsibility of devising strategies to mitigate the risk of guests' payment information exposure from the point of capture in the stores. This involved collaborating with various teams across the organization to understand the current state of payment security and identify potential vulnerabilities. Based on the findings, I led the design and implementation of targeted solutions that would reduce the risk of payment card data exposure and ensure compliance with relevant security standards.
  • Optiv Inc
    Vice President - Compliance Advisory Services
    Optiv Inc Jul 2015 - Apr 2018
    Denver, Colorado, Us
    Lead all operations of Optiv's Compliance consulting team, including P&L ownership. Encompassing; team mentorship and leadership, methodology and offering development, sales and marketing support, back end operations, and client-facing consulting and executive-level presentations. Evangelized professional services offerings, responsible for creating and delivering marketing collateral such as blog posts, webinars, and in-person speaking engagements at events like Optiv’s ES3 & Executive Briefings, PCI Community Meeting roundtable discussions, and regional ISSA meetings.Achieved the highest effective margin percentage in the company. Multi-year presidents club award recipient.Operationally focused on consulting delivery, but also sales motivated to help drive increased revenue numbers.Completed the integration of the Accuvant and Fishnet compliance consulting teams into one cohesive team with standardized services.Lead MSSP offering for PCI ASV vulnerability management for hundreds of clients.Developed pricing metrics to facilitate accurate scoping of projects and the development of change orders, ultimately enhancing client satisfaction and profitability.
  • Fishnet Security (Now Optiv)
    Vice President - Pci Advisory Services
    Fishnet Security (Now Optiv) Apr 2015 - Jul 2015
    Overland Park, Ks, Us
    Selected to lead the combined Accuvant - FishNet Security PCI consulting practice moving forward.Responsible for growing the practice headcount to meet unprecedented demand for our PCI Advisory Services.
  • Fishnet Security (Now Optiv)
    Pci Practice Director
    Fishnet Security (Now Optiv) Sep 2013 - Apr 2015
    Overland Park, Ks, Us
    Leads a large experienced-team of PCI QSA's; delivering top-notch consulting services around the PCI DSS, PA-DSS and Experian EI3PA standards.
  • Elavon, Inc.
    Director Global Security Solutions - P2Pe/Tokenization Product Manager
    Elavon, Inc. Sep 2012 - Sep 2013
    Atlanta, Ga, Us
    Product Manager of Secure Payment Card Solutions for merchant clients.Focused on providing our merchant clients with payment solutions that ease security and compliance efforts, as well as lower risk using PCI Point to Point Encryption (P2PE) and Tokenization integrated payment terminals.
  • Accuvant (Now Optiv)
    Pci Practice Manager
    Accuvant (Now Optiv) Apr 2011 - Jul 2012
    Denver, Co, Us
    • Managed all aspects of PCI and Experian EI3PA consulting offerings. Gap Analysis & Reviews, Reports on Compliance (ROC), Reports of Validation (ROV), Strategy, ASV Scanning and Experian Assessments growing the service offerings annual revenue, but driving additional revenue in supporting services and product.• Primary QA lead for the PCI Program ensuring quality deliverables and maintaining the company's QSA certification in good standing.• Assisted hundreds of PCI-bound entities with remediation and program management: retail and ecommerce merchants, data storage and acquiring service providers.• Managed relationship between Accuvant and the PCI SSC. Managing employees’ training and certification requirements.• Maintained personal PCI QSA and ASV certifications for numerous years, as well was trained as an ISO 27001 ISMS Auditor.• Participated in all PCI Community Meetings obtaining more in-depth knowledge that is publicly available and participated as a team lead on the initial Special Interest Group (SIG) for scope reduction. Continued participation in the Point-to-Point Encryption (P2PE) SIG.• Developed and launched new service offerings as well as refined existing ones for higher efficiencies and client satisfaction.• Traveled throughout the US and Canada to deliver best practice consulting and presentations in compliance management.• Managed a tight-knit team of expert PCI & PA QSAs. Included internal and client project staffing, projections, employee reviews, and travel expense management.• Managed the PCI ASV scan service for numerous clients. The lead ASV researching and approving client false positives and delivering final attestations to the clients.• Worked with partners to develop online PCI Portal that offered an online knowledge base, online SAQ, remediation management and on-demand QSA support.• Supported sales and marketing to bring higher client awareness of compliance consulting services and the value of the services.
  • Accuvant (Now Optiv)
    Pci Program Manager
    Accuvant (Now Optiv) Aug 2006 - Jul 2011
    Denver, Co, Us
    Manage all PCI Program offerings for clients of Accuvant. PCI QSA and ASV certifications and well as an ISO 27001 ISMS Auditor.PCI On-Site Assessments "Level-1 Audit"PCI Quarterly External Scans as an ASVPCI DSS Gap AssessmentsPCI Remediation Assistance and Solutions DevelopmentPCI Portal Knowledge Base
  • Forsythe Solutions
    Sr Security Consultant
    Forsythe Solutions Jan 2002 - Aug 2006
    Skokie, Illinois, Us
    Senior Security Consultant with 10 years experience in Information Security. Obtained CISSP and CHSP (Certified HIPAA Security Professional -ISC2)Working concentration in vulnerability assessments, penetration tesing, high-level security architecture, acting Information Security Officer (CISO), PCI Compliance and ISO 17799 standards
  • Telenisus
    Senior Manager
    Telenisus Jan 2000 - Jan 2002
    Us
    National Leader - Vulnerability Assessment and Penetration TestingResponsible for developing and growing the Telenisus Attack & Penetration practice nationally. Actively interrogates various high profile Telenisus clients' networks for security vulnerabilities. Gives best practice security information to better secure Internet based security architectures. Clients range from financial institutions, major manufacturers, government, to "dot com" companies.
  • Ernst & Young
    Manager
    Ernst & Young May 1997 - Jan 2000
    London, Gb
    Manager in the eSecurity Solutions practice. Provided technical security consulting services to large multinational organizations in a broad range of industries. Responsible for Internet/Intranet threat and vulnerability testing for clients with a presence on the Internet. Used attack and penetration methodologies to interrogate client networks for security vulnerabilities and identify exposures. Gave best practice recommendations to clients on the formation of security architectures, policies and enforcement. Evaluated clients existing security policy and architecture to enforce the policies, such as firewalls, intrusion detection and logging systems. Provided risk-based solutions to help address security risks following a formal strategic plan. Implemented various security solutions including: firewalls, intrusion detection systems, VPN /Encryption, and Internet DMZ architectures for leading companies. Responsible for the daily administration and security of the eSS group's security lab.
  • Secure Computing Corporation
    Product Support Engineer
    Secure Computing Corporation Jan 1996 - May 1997
    Us
    Senior support and fully qualified Sidewinder and Borderware Firewall Install Engineer. Educated customer's System Administrators with firewall and Internet security concepts. Analyzed customer's networks for possible integration problems and security concerns. Actively participated in an Intrusion Response Team to support customers.
  • University Of Wisconsin Stout
    Computer Lab Coordinator
    University Of Wisconsin Stout Sep 1993 - Dec 1995
    Maintained security and availability of a local network of computers throughout the UW Stout campus. Performed malware removal and educated users on safe computing.
  • Cousins Submarines, Inc.
    Manager
    Cousins Submarines, Inc. 1989 - 1992
    Menomonee Falls, Wi, Us
    Managed a team of employees.

Brian Serra Skills

Pci Dss Information Security Security Computer Security Cissp Vulnerability Assessment Vulnerability Management Penetration Testing Network Security Information Security Management Information Technology Firewalls Iso 27001 Security Awareness Payment Card Industry Data Security Standard Leadership Encryption Data Security Payment Industry Security Architecture Design Ids Security Policy Identity Management Intrusion Detection Application Security Ips Security Audits It Audit Internet Security Web Application Security Dlp Hipaa Management Consulting Computer Forensics Cybersecurity Compliance Program Management Strategic Consulting Security Management Payment Card Processing Payment Gateways Payment Cards Information Security Policy Pre Sales Salesforce.com Management Procedure Creation Security Operations Management P2pe Security Assessments Openair Qsa Vpn Virtual Private Network

Brian Serra Education Details

  • University Of Wisconsin-Stout
    University Of Wisconsin-Stout
    Industrial Technology Concentration In Manufacturing Engineering
  • Brookfield Central
    Brookfield Central
    High School

Frequently Asked Questions about Brian Serra

What company does Brian Serra work for?

Brian Serra works for Target

What is Brian Serra's role at the current company?

Brian Serra's current role is Cybersecurity & Compliance Leader. Enhancing information security maturity across the IT enterprise and operational technology / industrial controls environments. Mentoring the next generation of cyber leaders..

What is Brian Serra's email address?

Brian Serra's email address is br****@****von.com

What schools did Brian Serra attend?

Brian Serra attended University Of Wisconsin-Stout, Brookfield Central.

What are some of Brian Serra's interests?

Brian Serra has interest in Science And Technology.

What skills is Brian Serra known for?

Brian Serra has skills like Pci Dss, Information Security, Security, Computer Security, Cissp, Vulnerability Assessment, Vulnerability Management, Penetration Testing, Network Security, Information Security Management, Information Technology, Firewalls.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.