Jason Rusch

Jason Rusch Email and Phone Number

Director of Governance, Risk and Compliance @ Ashley Furniture Industries
North Port, FL, US
Jason Rusch's Location
Wesley Chapel, Florida, United States, United States
Jason Rusch's Contact Details

Jason Rusch work email

Jason Rusch personal email

n/a

Jason Rusch phone numbers

About Jason Rusch

I am a U.S. Navy veteran and accomplished Cyber Governance, Risk, Compliance, and Security (GRCS) professional with 25 years of experience. Proven ability to advise executive, business, legal, and IT leaders in the development and implementation of innovative GRCS strategies. Known for a “work smarter, not harder” philosophy (don’t recreate the wheel) that emphasizes practical alignment of GRCS programs with business objectives. Experienced in employing automation, simplicity, and stakeholder-driven controls to deliver results-driven outcomes across diverse industries and environments.Core Competencies• Governance, Risk, & Compliance (GRC) Strategy• Information Security & Risk Management• Data Governance Program Development & Management• Stakeholder Engagement, Coordination & Leadership• Process Automation & AI Integration• Regulatory Compliance Program Management• Cross-Industry Expertise• Project & Team ManagementControls & Requirements Summary• Control Frameworks – COSO, ISO 27002, HITRUST/CSF, NIST, CCM.• Attestations/Certifications – SOX, SOC2 Type 2, FedRAMP, ISO 27001.• Compliance Requirements - HIPAA, PCI-DSS, GDPR, PIPEDA, CCPA/CPRA, +.• Security Management – EPDR, DLP, HIDS, SIEM, IRM, IAM, TVM.• Risk Management – ISO 31000, FAIR, ERM.

Jason Rusch's Current Company Details
Ashley Furniture Industries

Ashley Furniture Industries

View
Director of Governance, Risk and Compliance
North Port, FL, US
Employees:
10546
Jason Rusch Work Experience Details
  • Ashley Furniture Industries
    Director Of Governance, Risk And Compliance
    Ashley Furniture Industries
    North Port, Fl, Us
  • Infosec-Rusch Grc-S Consulting
    Grcs Vciso Cyber Consulting
    Infosec-Rusch Grc-S Consulting Apr 2024 - Sep 2024
    Lead organizations through the complexities of cyber governance and compliance. Assessing security postures, identifying vulnerabilities, and developing robust strategies to mitigate risks. I work closely with executive teams to align cybersecurity initiatives with business objectives, ensuring a seamless integration of security practices into the organizational framework.Key Support Areas• Cyber Governance: Establishing and maintaining a comprehensive cybersecurity governance framework that aligns with industry best practices and regulatory requirements.• Compliance Management: Ensuring adherence to key regulations such as GDPR, HIPAA, PCI DSS, and ISO 27001 through meticulous compliance readiness assessments and tailored action plans.• Risk Management: Conducting thorough risk assessments to identify potential threats and vulnerabilities, and implementing effective risk mitigation strategies.• Policy Development: Crafting and enforcing security policies and procedures that safeguard organizational data and systems.• Incident Response: Leading incident response planning and execution to swiftly address and recover from security breaches.• Security Training: Providing ongoing security awareness training to employees, fostering a culture of cybersecurity and due diligence within the organization.
  • Career Break
    Layoff/Position Eliminated
    Career Break Dec 2023 - Mar 2024
    AWS separation/re-organization, family and professional development.
  • Amazon Web Services (Aws)
    Sr. Security Assurance Consultant
    Amazon Web Services (Aws) Jul 2020 - Nov 2023
    Seattle, Wa, Us
    • Provided executive leadership with strategic consulting on diverse cloud projects, ensuring alignment with organizational goals, industry standards and requirements.• Designed controls to maintain security/compliance with regulatory frameworks, NIST, FedRAMP, CSA, HIPAA, SOC2, SOX 404, PIPEDA, CCPA, PCI-DSS.• Performed comprehensive security assessments utilizing AWS Security Baselines, CIS Benchmarks, and CSA Cloud Controls Matrix (CCM).• Directed high-impact projects such as data migration, analytics integration, and data modeling, improving operational efficiency and scalability.• Spearheaded initiatives for continuous compliance with data privacy and legal teams, ensuring organizational readiness for audits and assessments.• Designed cyber governance frameworks for clients that included R.A.C.I. methodologies and matrices. This allowed for the formal assignment of roles and responsibilities.• Developed risk assessment methodology for large financial services company that mapped risks to AWS services/controls, regulatory requirements and owners.
  • Cognizant
    Senior Manager Information Risk Management
    Cognizant Apr 2018 - Apr 2020
    Teaneck, New Jersey, Us
    • Managed SOC 2 Type 2 annual attestation and program, program managed annual attestation and reporting to demonstrate internal controls, processing integrity and consistency.• Project Manager of annual risk/control assessments aligned with ISO 27002:2013.• Served as data governance lead, establishing and maintaining a comprehensive data catalog while ensuring data accuracy, integrity, and consistency across enterprise datasets.• Provided (SME) guidance on PCI-DSS compliance and supported privacy initiatives, assessing alignment with CCPA/CPRA, GDPR, and other regulatory frameworks. • Redesigned client data governance framework, including classifications, dictionary, and catalog, to improve structure, usability, and compliance for a primary client.• Architected a SOC 2 controls monitoring program, enabling proactive identification of changes, control deficiencies, and process issues to enhance continuous compliance.• Assisted in the development of a comprehensive risk and incident response guidance for IRM teams, strengthening organizational resilience and response capabilities.
  • Rooms To Go
    Senior Enterprise Compliance Analyst
    Rooms To Go Mar 2017 - Apr 2018
    Seffner, Fl, Us
    • Led the development and execution of a comprehensive Risk and PCI Compliance program, enhancing organizational security posture and regulatory adherence.• Established a governance and control framework that aligned requirements with controls and risks, ensuring seamless integration with organizational objectives.• Designed and implemented a dynamic risk register, effectively aligning it with compliance and IT security metrics to provide actionable insights for stakeholders.• Architected enterprise vulnerability management program (NIST CSF).• Led Rooms To Go to first PCI-DSS assessment & compliant SAQ/AOC.
  • Citi
    Vp Of Information Security
    Citi Sep 2016 - Mar 2017
    New York, New York, Us
    • Spearheaded vulnerability control projects, developing "Corrective Action Plans" (CAPS). • Performed analysis on CAPS data, presented KRI’s for Global Information Security Risk meetings.
  • Bright House Networks
    Principal Enterprise Analyst (Governance & Compliance)
    Bright House Networks Aug 2013 - Sep 2016
    East Syracuse, New York, Us
    • Supported the development and implementation of a customized IT governance framework, enhancing alignment between business objectives, compliance, and risk management.• Collaborated with the SOC Team to develop and execute Information Risk Management (IRM) strategies, strengthening organizational resilience.• Designed and implemented the companies first PCI compliance program.• Partnered to align I.T. controls governance framework with ISO 27002:2013 standards.• Authored security architecture and PCI compliance strategy for a successful POS-POI project.• Successfully led BHN through its first PCI-DSS assessment & achieved a compliant ROC/AOC.• Led data discovery project to map out data locations, types, flow, status, access and owners.
  • Humana
    Security Assurance Architect (Risk-Vulnerability-Compliance)
    Humana Aug 2011 - Aug 2013
    Louisville, Kentucky, Us
    • Directed PCI compliance program, implemented a compliance governance management structure incorporating three distinct tiers: "Assessment Management," "Continuous Monitoring," and "Control Risk & Deficiency Management," supporting continuous compliance.• Supported governance projects to align HITRUST Common Security Framework with existing HIPAA controls and requirements. • Co-managed (TVM) vulnerability scanning program, partnered with key stakeholders to develop remediation action plans. • Successfully led Humana through first PCI-DSS assessment & achieved a compliant ROC/AOC.
  • Hard Rock International
    Manager Of Internal Controls & Compliance
    Hard Rock International Apr 2009 - Aug 2011
    Davie, Fl, Us
    • Managed and designed HRC’s first PCI compliance program.• Provided technical oversight for internal audits and annual financial audits of IT controls, ensuring alignment with regulatory and organizational requirements.• Led the development of the organization’s first formal (GRC) framework, incorporating elements from ISO 27002 and NIST standards.• Facilitated coordination among various IT teams to support control initiatives and IT risk management projects, fostering collaboration and process improvement.• Successfully led HRC’s through its first PCI-DSS assessment & achieved a compliant ROC/AOC.
  • The Walt Disney Company
    Corporate Compliance Analyst (Pci Consultant-Contractor)
    The Walt Disney Company Jul 2008 - Mar 2009
    Burbank, Ca, Us
    • Co-led the development and first PCI-DSS compliance program and assessment for TWD.• Performed as internal PCI lead, SME and project manager, coordinate efforts with external QSA. • Successfully co-led Walt Disney through its first PCI-DSS assessment & compliant ROC/AOC.
  • Educational Testing Service (Ets)
    Information Protection & Compliance Officer (Pci Consultant)
    Educational Testing Service (Ets) Dec 2007 - Jul 2008
    Princeton, Nj, Us
    • Developed and aligned PCI-DSS compliance program with existing governance and controls frameworks.• Performed internal self PCI-DSS assessment and authrored SAQ-D.
  • Quality Carriers
    Information Security & Compliance Administrator
    Quality Carriers Oct 2005 - Dec 2007
    Tampa, Florida, Us
    • Led and developed the Sarbanes-Oxley (SOX) 404 compliance program, including the design, implementation of IT General Controls (ITGCs) and annual attestation.• Developed an enterprise IT governance framework based on ISO 27002and authored Management Information Systems (MIS) policies and procedures.• Updated/aligned risk/vulnerability control frameworks with I.T. governance framework.
  • Reilly Mortgage Group
    Information Security Systems Administrator
    Reilly Mortgage Group Mar 2005 - Jul 2005
    • Manage I.T. security systems including anti-virus, internet proxies, firewalls, Active Directory security. • Performed SOX 404 readiness review with control deficiency mitigation strategies.
  • Cerebit
    Information Security & Network Systems Administrator
    Cerebit Jan 2003 - Jan 2005
    Us
    • I.T. server systems administrator (Linux, SunOS, Windows), anti-virus, and IDS management. • Security and risk management/assessments, for internal and external clients.
  • Charter Communications
    Tier 2 Technical Support - (Linux Subject Material Expert)
    Charter Communications Jan 2001 - Jul 2002
    Stamford, Connecticut, Us
    • Desktop/Network support engineer, cyber security subject material expert (SME).• Successfully lead customer support team for ISP network conversion of 300,000 @Home customers.• Constructed leading cable modem support and troubleshooting website.• Acting support team supervisor.• Employee of the month out of 300 support technicians.
  • Ups Logistics Technologies
    Tier 3 Network & Unix/Windows Systems Support (Contractor)
    Ups Logistics Technologies Feb 2002 - Jun 2002
    Towson, Md, Us
    • Support SunOS 2x/Solaris, Redhat Linux, MS Exchange/Active Directory (IAM) and end point anti-virus.
  • Us Navy
    Communication & Intelligence Specialist
    Us Navy Jun 1990 - Aug 1992
    Washington, Dc, Us
    Positions & Roles· Intelligence Communications Specialist· Damage Control (Firefighter)· Boatswain Mate Apprentice Acknowledgements · National Defense and Sea Service Medal (Persian Gulf, Operation Desert Storm)· Southwest Asia Medal (w/ Campaign Star, Operation Desert Storm)· Letter of recommendation (Red Sea, Operation Desert Storm)· Sea Service Ribbon (Mediterranean NATO Joint Operations)

Jason Rusch Skills

Information Security Security Pci Dss Information Technology Disaster Recovery Information Security Management Computer Security Business Continuity Governance Security Audits Vulnerability Management Vulnerability Assessment Cobit Risk Assessment Iso 27001 Risk Management Sarbanes Oxley Act Active Directory Program Management Cissp Project Management Compliance Software Documentation It Audit Penetration Testing Hipaa Internal Audit Policy Auditing Cisa Financial Risk Ips System Administration Nist Enterprise Risk Management Strategic Planning Linux Cism Iso 17799 Threat And Vulnerability Management Intrusion Detection Payment Industry Enterprise Architecture Sox 404 Sas70 Security Management Risk Compliance Management Sox Documentation

Jason Rusch Education Details

  • Sullivan University
    Sullivan University
    Computer Science (Data Communications)
  • Payment Card Industry
    Payment Card Industry
    Payment Card Industry Professional (Pci-Isa)
  • Isaca
    Isaca
    Enterprise I.T. Governance (Cobit 5)
  • Sans Institute
    Sans Institute
    Giac Systems And Network Auditor (Gnsa)
  • Global Knowledge
    Global Knowledge
    Itilv3 Foundations
  • Isaca
    Isaca
    Risk Assessment Program And Execution
  • Sans Institute
    Sans Institute
    Project Management For Information Security
  • Isaca
    Isaca
    Cobit 4.0 Expert
  • Global Knowledge
    Global Knowledge
    Project Management For Information Technology
  • Sans Institute
    Sans Institute
    Sans Mgt: 421 Leadership And Management Competencies
  • Mis Training Institute
    Mis Training Institute
    Cobit)
  • Issa
    Issa
    Nist Sp-800-53
  • Microsoft Group
    Microsoft Group
    Microsoft Sql 2005 Security In Depth
  • New Horizons
    New Horizons
    Ecommerce Architect & Design

Frequently Asked Questions about Jason Rusch

What company does Jason Rusch work for?

Jason Rusch works for Ashley Furniture Industries

What is Jason Rusch's role at the current company?

Jason Rusch's current role is Director of Governance, Risk and Compliance.

What is Jason Rusch's email address?

Jason Rusch's email address is jr****@****ogo.com

What is Jason Rusch's direct phone number?

Jason Rusch's direct phone number is (800) 282*****

What schools did Jason Rusch attend?

Jason Rusch attended Sullivan University, Payment Card Industry, Isaca, Sans Institute, Global Knowledge, Isaca, Sans Institute, Isaca, Global Knowledge, Sans Institute, Mis Training Institute, Issa, Microsoft Group, New Horizons.

What skills is Jason Rusch known for?

Jason Rusch has skills like Information Security, Security, Pci Dss, Information Technology, Disaster Recovery, Information Security Management, Computer Security, Business Continuity, Governance, Security Audits, Vulnerability Management, Vulnerability Assessment.

Who are Jason Rusch's colleagues?

Jason Rusch's colleagues are Brett Kereky, Gabriel Mardirossian, Jose Reyes Santana, Dave Mckinnon, Lisa Waters, Mandi Ingerson, Debra Bauer.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.