Chief Information Security Officer
Current• Established the Bank’s Information Security Program: Developed a comprehensive program encompassing cybersecurity, access control and identity management, data security, and physical security.• Managed IT Risk Management Program: Implemented a dynamic IT risk management approach that includes continuous assessment of cybersecurity threats, establishing IT Key Risk Indicators (KRIs).• Created the Bank’s First IT and Cyber Incident Response Plan: Developed a scenario-based incident response plan detailing response steps and regulatory notification requirements.• Promoted Information Security Awareness: Fostered a culture of information security by providing employee training, conducting ongoing security-related communications, and performing bank-wide phishing simulation tests.• Third-Party IT Risk Management: Oversaw Information and cybersecurity risk of vendor engagements.• Managed Regulatory and Audit Compliance: Directed annual IT regulatory and audit examinations, including coordination with the head office audit team.• Led Security Operations: Monitored and managed cybersecurity intrusion traffic and alerts, reviewed bank-wide user access privileges, conducted firewall and configuration reviews, managed data loss prevention (DLP), remote access, patch management, and endpoint security.