CISO and global Technology Manager with experience managing teams of technologists and application developers, deploying solutions to meet business needs. Focus on operational efficiency and effectiveness through appropriate use of technology. Budgetary responsibility for headcount, and capital and expense management. Vendor selection and negotiations. Staff development and coaching. Embedding security across the dimensions of corporate, secure SDLC and testing, and product & services.Successfully set up the ISMS and risk management processes, delivered SOC2 Type 2, ISO 27001, and TruSight examinations. Focus on improving risk management/remediation across the organisation. Enhanced our vendor risk processes for our use of SaaS and cloud, and responded to security questionnaires (RFP, SIG, DDQ, KY3P, FSQS), and move to continuous compliance monitoring. Passionate about secure SDLC/DevSecOps practices and the provenance and assurance of software delivery from requirements through to distributed/deployed products. Embedding security-by-design practices in the software pipeline. Open-source projects. CICD pipelines, including CircleCI, Azure DevOps, and Github Actions.Managing IT across multiple cloud providers (AWS/GCP/Azure) and 120+ SaaS providers including Google, Microsoft, Zoom, Slack, Atlassian. Automation and self-service options for help desk requests. Focus on data access management and non-human, system access to these ecosystems as vectors for supply chain attacks.Previous responsibilities have included managing the “critical infrastructure” of major financial services companies, engineering of corporate systems and application monitoring services, infrastructure risk.Specialties: Managing technical architects/engineers, inc program/project management, technology strategy/roadmap. Vendor negotiation/evaluation. Cyber Security and Risk Management, administrative/technical/physical controls assessment and implementation, Compliance Frameworks (ISO, NIST, SCF), DevsSecOps & CI/CD, Security Testing, Cloud Hosting Services and shared responsibility model, System/Network Monitoring, Metrics and Analytics, Identity Management products, oAuth, JWT, Kerberos, PKI/HSM/cryptography, firewalls, threat modeling, databases (PostgresQL, MS SQL) and enterprise messaging (MQ Series/Tibco RV/Kafka), programming (Daml, Python, Java). Containerization (Docker, Kubernetes, GKE).
Listed skills include Active Directory, Integration, Unix, It Strategy, and 46 others.