Head Of Information Security
CurrentFostering a Risk-based Secure Operations by Leading, managing, and directing the organizational Information Security program. Working closely with the CEO & President, to administer the Information Security governance program, as well as with the CFO, implementing security initiatives, policies, regulations and procedures. Responsible for developing, directing, and executing the corporation’s strategic, tactical, and operational information security goals in alignment with corporate business goals, reducing risk to an acceptable level.Responsible for developing global security strategy based on ISO27001 standards and implementing across the enterprise. I am responsible for the architecture, engineering of all of the following domains and implementing and aligning a Global Security Program as well as strategic alignment with globalized team. I am also responsible for the strategic and tactical direction for all areas listed below.Technology:Encryption, PKI, TLS, Data Loss Prevention (DLP), Firewalls, IDS/IPS, Internet Content Filtering, Secure tunnels, Security Gateway, EDR HIDS/HIPS, Multi-factor AuthenticationOperations:SOC/SIEMArchitectureForensic Analysis (disk and network)Threat ModelingCERT/CSIRTBlue/Red/Purple teamingForensic Analysis (disk and network)Mgmt:Architectural ReviewIncident Handling PlanResource planning/managementLegalAudit/ComplianceSecurity AwarenessRisk Management Frameworks, Assessment Methodology, Assessment ProcessAwareness TrainingCloud Security ArchitectureFrameworks:ISO 27001 / ISMS developmentNIST FrameworkITIL