Chief Information Security Officer
CurrentLeading a diverse and talented team of cybersecurity professionals, I champion a new era of security at Crossover Health. My focus on cutting-edge technology and my commitment to creating a robust security culture has allowed us to stay ahead of the curve.➥ Responsible for leading the development and implementation of Crossover Health’s enterprise-wide information security programs, policies, standards, architecture and systems.➥ Manage department staff and budget, identify cost effective solutions to address risks in alignment with business objectives, negotiate vendor contracts and monitor service performance.➥ Review business contract language in SOWs, MSAs, and BAAs providing guidance to legal on requirements, terms, and commitments related to security, privacy, HIPAA and technology.➥ Perform IT security risk assessments, translating technical vulnerability, threat, control, configuration, and design data into business risks and identify cost effective remediations.➥ Create and manage a targeted and continuous information security awareness training program for all staff with established metrics to measure program effectiveness and identify training gaps.➥ Oversee all security compliance programs including customer audits, internal audits, vendor risk management, 3rd party penetration testing, HITRUST certification, and SOC2 reporting. ➥ Implement and maintain a centralized IAM solution to enable enterprise SSO across hundreds of systems, networks and applications with automated account provisioning via SAML.➥ Manage the incident response program including the implementation of security monitoring capabilities, development of response procedures, and leading incident response efforts.