Vp Of Information Security
CurrentDesigned and implemented an Information Security Program and guided business and technical stakeholders through control and process implementation leading to a successful SOC 2, HIPAA and PCI compliance audits. Operating the Information Security program by leading executive governance, and:- Continuous improvement by managing risk and implementing technical and process security controls to reduce risk and close compliance gaps.- Implemented secure software development policies; deployed code and container scanning and penetration testing services.- Implemented and operated security tools for vulnerability scanning, intrusion detection, DLP, etc.- Defined a PCI compliance strategy and led implementation and successful compliance attestation.- Led implementation of CCPA privacy compliance across Legal, Marketing, and Operations teams.- Leading SOC 2 Type 2 implementation.