Manager, Computing Services
Florida, United States
Leadership role included several global cyber security activities during a 5 year tenure. Roles included corporate policy and governance, Payment Card Industry (PCI) compliance, system security plans, and eGRC tools (Archer). Created a PCI compliance program utilizing certified internal security assessors (ISAs), external consultants, and a QSA firm to assess 200+ PCI areas on a 12 month cycle. Provided vision to eCommerce application teams, infrastructure areas, and call centers regarding the path forward to attaining PCI compliance. Identified and quantified risk, as it relates to compliance misalignment. Led process development and oversaw implementation of governance, risk, and compliance. Developed a System Security Plan (SSP) Program to review systems, create security plans, identify security gaps, quantify risk, and meet public sector security plan requirements. Tied the SSP process to risk and compliance offering a single repository for audit documentation to be utilized for HIPAA, SOX, PCI, internal audit and other assessment needs.