Head Of Information Security
CurrentRisk Management & Security Integration: • Conducted comprehensive vulnerability management and risk assessments, integrating security measures into project delivery. • Developed and implemented policies and procedures, increasing the organization’s security level.Identity & Access Management: • Effectively managed user accounts, implementing 2FA and SSO to improve access security. • Integrated HR processes to automate access management, reducing request processing time.Legal & HR Support: • Participated in investigations and forensic analyses, ensuring timely and accurate data delivery. • Achieved full GDPR compliance, preventing potential fines.Client & Partner Support: • Provided client security consulting, harmonizing requirements and recommending secure configurations to increase client satisfaction. • Established strong relationships with key partners through effective communication on information security matters.ISMS Framework Development & Improvement: • Developed and modernized the ISMS framework, implementing metrics and reporting systems to improve process transparency. • Successfully led ISO 27001 certification, including recertification to the latest standard version with no nonconformities.Compliance & Audits: • Conducted internal and external audits for ISO 27001 and PCI DSS, ensuring continuous compliance with standards. • Consistently achieved PCI DSS certification annually, enabling the company to expand its client base.Security Operations: • Led incident management and threat detection efforts, reducing response time. • Implemented threat prevention measures, reducing security incidents.Building a High-Performing Team: • Built a highly effective information security team within a short timeframe, optimizing the use of limited resources. • Developed and implemented clear and efficient security processes, enhancing department efficiency.