George Guzman Email and Phone Number
Information security and technology risk professional with 20 years of experience in Hospitality, Financial, Non-Profit, Higher Education, and Federal government verticals. Proficient in aligning business goals with information security goals, while minimizing risk to the organization.Skills• Cyber Security Frameworks: NIST CSF, NIST 800-53, ISO27001, CIS• Data Security Regulatory Laws: PCI-DSS, HIPAA FERPA, SOX• Risk Management Frameworks: NIST 800-37, FAIR• Governance, Risk and Compliance: Risk and Controls management• Third Party & Vendor Risk Management: Risk Assessments• Operational Security: vulnerability management, PKI, IAM, DLP, endpoint, incident response
Marriott International
View- Website:
- marriott.com
- Employees:
- 179195
-
Business Information Security Officer, Global Information SecurityMarriott International May 2024 - PresentUnited States• Serve as business information security officer (BISO) supporting the Global Operations division. • Provide guidance on interpretation and compliance with security policies, standards, and controls.• Support Global Operations on implementation of security initiatives, security control adoption, security vulnerability remediation, security modernization, and risk issue management.• Publish and present monthly security briefs to lines of business.• Brief CISO and security leadership on business goals and priorities for successful collaboration. -
Business Information Security Leader, Information SecurityFreddie Mac Nov 2017 - May 2024Mclean, Virginia, United States• Served as business information security officer (BISO) supporting the Finance, Risk, Legal, HR, Audit, Multifamily, and IT divisions. • Provide guidance on interpretation and compliance with security policies, standards, and controls.• Supported lines of business on implementation of security initiatives, such as NIST 800-53 security control adoption, identity and access management governance, security vulnerability remediation, security modernization, and risk issue management.• Publish and present monthly security briefs to lines of business.• Brief CISO and security leadership on business goals and priorities for successful collaboration. -
Director Of Information SecurityUsac Dec 2016 - Oct 2017Washington D.C. Metro Area• Established an accreditation and authorization process at USAC to align with NIST 800-37 Risk Management Framework.• Identified, Selected, and Implemented NIST 800-53 controls on key systems.• Launched new security capabilities to reduce risk, such as, data loss prevention technology (Proofpoint), endpoint encryption (Dell DDPE), Splunk SIEM, and advanced endpoint security (Carbon Black).• Strong focus on vulnerability management that reduced vulnerabilities by 1500%. -
Director, Compliance And Data Privacy ServicesThe George Washington University Aug 2013 - Dec 2016Washington D.C. Metro Area• Developed the GWU information management program, which was a framework to categorize and protect information assets. • Collaborated with the Division of Information Technology and the Office of General Counsel to establish a new data classification model, new information security standards, and record retention requirements. • Conducted annual assessments to identify and remediate risks to regulated information.• Served as the university HIPAA privacy officer and chaired the HIPAA governance committee at GW, which consisted of key university stakeholders and schools involved in the management of health information. • Key contributor in the university Payment Card Industry Data Security Standard (PCI-DSS) Compliance Program. -
Director, Compliance And Risk ServicesThe George Washington University Mar 2011 - Aug 2013• Established formal vulnerability remediation process. The process scanned, discovered, and remediated security vulnerabilities on over 3500 systems on the GWU network. • Developed an IT Risk Register that cataloged risks aligned to services supported by the Division of Information Technology. Risks ranged from security vulnerabilities, technical debt, business continuity issues, and regulatory compliance gaps.• Rolled out GRC application for tracking risks, workflow, remediation, and system profiles on Agiliance. Reported progress on a weekly basis to CIO. • Collaborated with the Office of the Vice President for Research to support principal investigators achieve Federal compliance required of sponsored research grants.• Co-authored the Information Security Policy and the Records Management Policy -
Senior Manager, Information Security Office, Global Security DepartmentCaci International Inc Feb 2004 - Feb 2011• Established formal vulnerability remediation process. The process scanned, discovered, and remediated vulnerabilities on 8000 systems and reduced vulnerabilities by 75%.• Rolled out self-service patching for employee endpoints. The new capability provided flexibility in patching and improved time to patch by 50%.• Streamlined the intrusion detection topology that increased coverage and reduced cost.• Chaired monthly security roundtable with key IT stakeholders across company. • Developed first SOX-compliant security awareness online training program. -
Sales Engineering DirectorCable And Wireless Feb 2002 - Feb 2004As Director of Sales Engineering, was responsible for producing dynamic sales engineering team capable of supporting US internet services sales department. Product portfolio and expertise spanned internet connectivity (T-1 through OC-3), security services, routing, hardware, and web hosting services.
-
Sales Engineering ManagerUunet Feb 1998 - Feb 2002Hired as a Sales Engineer and was promoted to manage two Sales Engineering teams (domestic and international). Product portfolio and expertise spanned internet connectivity (T-1 through OC-3), security services, routing, hardware, and international transit/private line services. -
Systems Engineer IiiCaci International Inc Jan 1997 - Feb 1998Member of the Corporate Information Systems department. Responsible for desktop IT support and wide area network support. -
Helpdesk ManagerWorld Bank Group Feb 1995 - Dec 1996Member of the Investment Division. Responsible for the management of the IT help desk that provided desk top, local area network, wide area network, and securID/token support for the division.
George Guzman Education Details
-
Business Administration
Frequently Asked Questions about George Guzman
What company does George Guzman work for?
George Guzman works for Marriott International
What is George Guzman's role at the current company?
George Guzman's current role is Business Information Security Officer, Global Information Security.
What schools did George Guzman attend?
George Guzman attended University Of Maryland Global Campus, Virginia Tech - Pamplin College Of Business.
Who are George Guzman's colleagues?
George Guzman's colleagues are Harvey Kellman, Sara Altieri, Rajesh Dhawal, Marcus Jenkins, Ana Ruiz Ruiz, Manoj Vetal, Fabian Rich.
Not the George Guzman you were looking for?
-
-
2fsu.edu, republicahavas.com
-
-
George Guzman
Asu Cronkite School Of Journalism & Mass Communication | Class Of '22 | Marine Veteran |La Puente, Ca2marines.com, fokker.com1 +31 78 XXXXXXXX
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial