Sr. Director, Cybersecurity Governance, Risk, & Compliance
CurrentStrategically evolved enterprise GRC frameworks and led high performing teams to accommodate rapid shifts in the software industry, driving cloud and on-premise application compliance with agility and precision.Pioneered compliance methodologies tailored to enterprise needs, successfully navigating the intricacies of ISO, SOC2, PCI-DSS, HIPAA, and NIST 800-53/FedRAMP frameworks over multiple scoped environments within the SaaS Industry.Led a cross-functional initiative to integrate GRC processes with advanced cloud services, enhancing security postures and ensuring seamless regulatory compliance for software solutions.Developed a dynamic Security Risk Committee, directly interfacing with the C-Suite to inform executive decisions with robust risk intelligence and forward-looking threat analysis.Initiated and supervised an ongoing talent development program for my team, cultivating a group of leaders proficient in current GRC practices and cloud security technologies.Implemented an impactfule Security Risk program which utilizies a streamlined approach and helps feed enterprise risk management and educates the business.Orchestrated a transformative update to security governance protocols, incorporating contemporary compliance standards and automated reporting to bolster organizational resilience.Championed a robust vendor management overhaul, leveraging deep industry insights to enhance operational efficiencies and secure strategic partnerships in the cybersecurity landscape.Assist and inform leadership in the strategic development and execution of a holistic cybersecurity strategy, translating complex regulatory requirements into actionable policies that advance business continuity and data integrity.