Business Information Security Officer (Biso)
CurrentServe as a line of business lead with defining the enterprise security policies and standards, consulting with business and technology areas, overseeing vendor security governance, vulnerability and risk management, identity and access management services, incident response and security operations, and supporting legal and regulatory compliance efforts.- Successfully bridged the communication gap by translating complex cybersecurity requirements into clear, concise, and easy-to-understand language for non-technical audiences- Used “Threat of the Month” content to tell an effective story about risk mitigation efforts in the org- Infused threat intelligence from CISA into organizational cybersecurity efforts- Developed and communicated architectural patterns to mitigate cloud configuration vulnerabilities- Drove software vulnerability mitigation efforts using SAST & DAST tools- Championed IAM modernization with enhanced multi-factor authentication via Single Sign-On solutions- Led enterprise initiative to remediate exposed secrets in source code- Developed and executed a cybersecurity tabletop exercise that elevated the NIST CSF Respond and Recovery maturity level, enhancing incident response readiness across the organization.