Security Investigator, Global It
Tampa, Florida, Us
Executed and facilitated multiple continuous assessments: ISO 27001, Sarbanes-Oxley, SAS 70 Type II, PCI DSS, BCP/DR and Internal General Computer Controls (GCC).Combined company GCCs with other regulatory standards and controls (HIPAA, PIPEDA, PCI DSS, EU Directives) to streamline auditing processes by 50%, resulting in reduction of overall audit costsAuthored and edited the policy base for the company, balancing stringent auditing standards with the need to maintain efficient business operationsNegotiated and creatively resolved conflicting interests of auditing teams and operations personnel. Performed risk assessments and analysis of new client and vendor contracts, determining security needs and recommending pragmatic and risk-based security controls that satisfied contractual, regulatory requirements and the needs of the business unit.Conducted both physical and logical risk assessments at facilities worldwide to determine vulnerabilities or potential non-compliance.Produced reports and conducted briefings with all levels of staff that mapped vulnerabilities to threats and recommended appropriate mitigation strategies.Served as team leader for the Global Virus Response Team and Incident Response Team, executing plans during numerous domestic and global events.Served as the Investigator, where I had a hand in legal inquiries, auditing both remotely and on the ground, as well as providing both logical and physical security expertise.Conducted highly-sensitive internal investigations, providing reports and briefings directly to CxO staff members. Conducted external investigations along with the Company client base of clients, including financial/banking, telecommunications, consumer products and healthcare sectors. These events include local and state law enforcement, FBI, financial regulatory agencies and law enforcement entities from outside the U.S.