Jason Rusch Email and Phone Number
Jason Rusch work email
- Valid
Jason Rusch personal email
Jason Rusch phone numbers
I am a U.S. Navy veteran and accomplished Cyber Governance, Risk, Compliance, and Security (GRCS) professional with 25 years of experience. Proven ability to advise executive, business, legal, and IT leaders in the development and implementation of innovative GRCS strategies. Known for a “work smarter, not harder” philosophy (don’t recreate the wheel) that emphasizes practical alignment of GRCS programs with business objectives. Experienced in employing automation, simplicity, and stakeholder-driven controls to deliver results-driven outcomes across diverse industries and environments.Core Competencies• Governance, Risk, & Compliance (GRC) Strategy• Information Security & Risk Management• Data Governance Program Development & Management• Stakeholder Engagement, Coordination & Leadership• Process Automation & AI Integration• Regulatory Compliance Program Management• Cross-Industry Expertise• Project & Team ManagementControls & Requirements Summary• Control Frameworks – COSO, ISO 27002, HITRUST/CSF, NIST, CCM.• Attestations/Certifications – SOX, SOC2 Type 2, FedRAMP, ISO 27001.• Compliance Requirements - HIPAA, PCI-DSS, GDPR, PIPEDA, CCPA/CPRA, +.• Security Management – EPDR, DLP, HIDS, SIEM, IRM, IAM, TVM.• Risk Management – ISO 31000, FAIR, ERM.
Ashley Furniture Industries
View- Website:
- ashleyfurniture.com
- Employees:
- 10546
-
Director Of Governance, Risk And ComplianceAshley Furniture IndustriesNorth Port, Fl, Us -
Grcs Vciso Cyber ConsultingInfosec-Rusch Grc-S Consulting Apr 2024 - Sep 2024Lead organizations through the complexities of cyber governance and compliance. Assessing security postures, identifying vulnerabilities, and developing robust strategies to mitigate risks. I work closely with executive teams to align cybersecurity initiatives with business objectives, ensuring a seamless integration of security practices into the organizational framework.Key Support Areas• Cyber Governance: Establishing and maintaining a comprehensive cybersecurity governance framework that aligns with industry best practices and regulatory requirements.• Compliance Management: Ensuring adherence to key regulations such as GDPR, HIPAA, PCI DSS, and ISO 27001 through meticulous compliance readiness assessments and tailored action plans.• Risk Management: Conducting thorough risk assessments to identify potential threats and vulnerabilities, and implementing effective risk mitigation strategies.• Policy Development: Crafting and enforcing security policies and procedures that safeguard organizational data and systems.• Incident Response: Leading incident response planning and execution to swiftly address and recover from security breaches.• Security Training: Providing ongoing security awareness training to employees, fostering a culture of cybersecurity and due diligence within the organization. -
Layoff/Position EliminatedCareer Break Dec 2023 - Mar 2024AWS separation/re-organization, family and professional development.
-
Sr. Security Assurance ConsultantAmazon Web Services (Aws) Jul 2020 - Nov 2023Seattle, Wa, Us• Provided executive leadership with strategic consulting on diverse cloud projects, ensuring alignment with organizational goals, industry standards and requirements.• Designed controls to maintain security/compliance with regulatory frameworks, NIST, FedRAMP, CSA, HIPAA, SOC2, SOX 404, PIPEDA, CCPA, PCI-DSS.• Performed comprehensive security assessments utilizing AWS Security Baselines, CIS Benchmarks, and CSA Cloud Controls Matrix (CCM).• Directed high-impact projects such as data migration, analytics integration, and data modeling, improving operational efficiency and scalability.• Spearheaded initiatives for continuous compliance with data privacy and legal teams, ensuring organizational readiness for audits and assessments.• Designed cyber governance frameworks for clients that included R.A.C.I. methodologies and matrices. This allowed for the formal assignment of roles and responsibilities.• Developed risk assessment methodology for large financial services company that mapped risks to AWS services/controls, regulatory requirements and owners. -
Senior Manager Information Risk ManagementCognizant Apr 2018 - Apr 2020Teaneck, New Jersey, Us• Managed SOC 2 Type 2 annual attestation and program, program managed annual attestation and reporting to demonstrate internal controls, processing integrity and consistency.• Project Manager of annual risk/control assessments aligned with ISO 27002:2013.• Served as data governance lead, establishing and maintaining a comprehensive data catalog while ensuring data accuracy, integrity, and consistency across enterprise datasets.• Provided (SME) guidance on PCI-DSS compliance and supported privacy initiatives, assessing alignment with CCPA/CPRA, GDPR, and other regulatory frameworks. • Redesigned client data governance framework, including classifications, dictionary, and catalog, to improve structure, usability, and compliance for a primary client.• Architected a SOC 2 controls monitoring program, enabling proactive identification of changes, control deficiencies, and process issues to enhance continuous compliance.• Assisted in the development of a comprehensive risk and incident response guidance for IRM teams, strengthening organizational resilience and response capabilities. -
Senior Enterprise Compliance AnalystRooms To Go Mar 2017 - Apr 2018Seffner, Fl, Us• Led the development and execution of a comprehensive Risk and PCI Compliance program, enhancing organizational security posture and regulatory adherence.• Established a governance and control framework that aligned requirements with controls and risks, ensuring seamless integration with organizational objectives.• Designed and implemented a dynamic risk register, effectively aligning it with compliance and IT security metrics to provide actionable insights for stakeholders.• Architected enterprise vulnerability management program (NIST CSF).• Led Rooms To Go to first PCI-DSS assessment & compliant SAQ/AOC. -
Vp Of Information SecurityCiti Sep 2016 - Mar 2017New York, New York, Us• Spearheaded vulnerability control projects, developing "Corrective Action Plans" (CAPS). • Performed analysis on CAPS data, presented KRI’s for Global Information Security Risk meetings. -
Principal Enterprise Analyst (Governance & Compliance)Bright House Networks Aug 2013 - Sep 2016East Syracuse, New York, Us• Supported the development and implementation of a customized IT governance framework, enhancing alignment between business objectives, compliance, and risk management.• Collaborated with the SOC Team to develop and execute Information Risk Management (IRM) strategies, strengthening organizational resilience.• Designed and implemented the companies first PCI compliance program.• Partnered to align I.T. controls governance framework with ISO 27002:2013 standards.• Authored security architecture and PCI compliance strategy for a successful POS-POI project.• Successfully led BHN through its first PCI-DSS assessment & achieved a compliant ROC/AOC.• Led data discovery project to map out data locations, types, flow, status, access and owners. -
Security Assurance Architect (Risk-Vulnerability-Compliance)Humana Aug 2011 - Aug 2013Louisville, Kentucky, Us• Directed PCI compliance program, implemented a compliance governance management structure incorporating three distinct tiers: "Assessment Management," "Continuous Monitoring," and "Control Risk & Deficiency Management," supporting continuous compliance.• Supported governance projects to align HITRUST Common Security Framework with existing HIPAA controls and requirements. • Co-managed (TVM) vulnerability scanning program, partnered with key stakeholders to develop remediation action plans. • Successfully led Humana through first PCI-DSS assessment & achieved a compliant ROC/AOC. -
Manager Of Internal Controls & ComplianceHard Rock International Apr 2009 - Aug 2011Davie, Fl, Us• Managed and designed HRC’s first PCI compliance program.• Provided technical oversight for internal audits and annual financial audits of IT controls, ensuring alignment with regulatory and organizational requirements.• Led the development of the organization’s first formal (GRC) framework, incorporating elements from ISO 27002 and NIST standards.• Facilitated coordination among various IT teams to support control initiatives and IT risk management projects, fostering collaboration and process improvement.• Successfully led HRC’s through its first PCI-DSS assessment & achieved a compliant ROC/AOC. -
Corporate Compliance Analyst (Pci Consultant-Contractor)The Walt Disney Company Jul 2008 - Mar 2009Burbank, Ca, Us• Co-led the development and first PCI-DSS compliance program and assessment for TWD.• Performed as internal PCI lead, SME and project manager, coordinate efforts with external QSA. • Successfully co-led Walt Disney through its first PCI-DSS assessment & compliant ROC/AOC. -
Information Protection & Compliance Officer (Pci Consultant)Educational Testing Service (Ets) Dec 2007 - Jul 2008Princeton, Nj, Us• Developed and aligned PCI-DSS compliance program with existing governance and controls frameworks.• Performed internal self PCI-DSS assessment and authrored SAQ-D. -
Information Security & Compliance AdministratorQuality Carriers Oct 2005 - Dec 2007Tampa, Florida, Us• Led and developed the Sarbanes-Oxley (SOX) 404 compliance program, including the design, implementation of IT General Controls (ITGCs) and annual attestation.• Developed an enterprise IT governance framework based on ISO 27002and authored Management Information Systems (MIS) policies and procedures.• Updated/aligned risk/vulnerability control frameworks with I.T. governance framework. -
Information Security Systems AdministratorReilly Mortgage Group Mar 2005 - Jul 2005• Manage I.T. security systems including anti-virus, internet proxies, firewalls, Active Directory security. • Performed SOX 404 readiness review with control deficiency mitigation strategies. -
Information Security & Network Systems AdministratorCerebit Jan 2003 - Jan 2005Us• I.T. server systems administrator (Linux, SunOS, Windows), anti-virus, and IDS management. • Security and risk management/assessments, for internal and external clients. -
Tier 2 Technical Support - (Linux Subject Material Expert)Charter Communications Jan 2001 - Jul 2002Stamford, Connecticut, Us• Desktop/Network support engineer, cyber security subject material expert (SME).• Successfully lead customer support team for ISP network conversion of 300,000 @Home customers.• Constructed leading cable modem support and troubleshooting website.• Acting support team supervisor.• Employee of the month out of 300 support technicians. -
Tier 3 Network & Unix/Windows Systems Support (Contractor)Ups Logistics Technologies Feb 2002 - Jun 2002Towson, Md, Us• Support SunOS 2x/Solaris, Redhat Linux, MS Exchange/Active Directory (IAM) and end point anti-virus. -
Communication & Intelligence SpecialistUs Navy Jun 1990 - Aug 1992Washington, Dc, UsPositions & Roles· Intelligence Communications Specialist· Damage Control (Firefighter)· Boatswain Mate Apprentice Acknowledgements · National Defense and Sea Service Medal (Persian Gulf, Operation Desert Storm)· Southwest Asia Medal (w/ Campaign Star, Operation Desert Storm)· Letter of recommendation (Red Sea, Operation Desert Storm)· Sea Service Ribbon (Mediterranean NATO Joint Operations)
Jason Rusch Skills
Jason Rusch Education Details
-
Sullivan UniversityComputer Science (Data Communications) -
Payment Card IndustryPayment Card Industry Professional (Pci-Isa) -
IsacaEnterprise I.T. Governance (Cobit 5) -
Sans InstituteGiac Systems And Network Auditor (Gnsa) -
Global KnowledgeItilv3 Foundations -
IsacaRisk Assessment Program And Execution -
Sans InstituteProject Management For Information Security -
IsacaCobit 4.0 Expert -
Global KnowledgeProject Management For Information Technology -
Sans InstituteSans Mgt: 421 Leadership And Management Competencies -
Mis Training InstituteCobit) -
IssaNist Sp-800-53 -
Microsoft GroupMicrosoft Sql 2005 Security In Depth -
New HorizonsEcommerce Architect & Design
Frequently Asked Questions about Jason Rusch
What company does Jason Rusch work for?
Jason Rusch works for Ashley Furniture Industries
What is Jason Rusch's role at the current company?
Jason Rusch's current role is Director of Governance, Risk and Compliance.
What is Jason Rusch's email address?
Jason Rusch's email address is jr****@****ogo.com
What is Jason Rusch's direct phone number?
Jason Rusch's direct phone number is (800) 282*****
What schools did Jason Rusch attend?
Jason Rusch attended Sullivan University, Payment Card Industry, Isaca, Sans Institute, Global Knowledge, Isaca, Sans Institute, Isaca, Global Knowledge, Sans Institute, Mis Training Institute, Issa, Microsoft Group, New Horizons.
What skills is Jason Rusch known for?
Jason Rusch has skills like Information Security, Security, Pci Dss, Information Technology, Disaster Recovery, Information Security Management, Computer Security, Business Continuity, Governance, Security Audits, Vulnerability Management, Vulnerability Assessment.
Who are Jason Rusch's colleagues?
Jason Rusch's colleagues are Brett Kereky, Gabriel Mardirossian, Jose Reyes Santana, Dave Mckinnon, Lisa Waters, Mandi Ingerson, Debra Bauer.
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial