Jorge Andrés Serrano Email and Phone Number
Lead Senior Consultant, certified as a ISO27001 LA and ISO27032, with more than 9 years of experience, focused on the detection, analysis, respond and treatment of technological and cyber risks and Business Risks providing support in Cybersecurity, Privacy and Trusted Technology with passion for aligning security architecture plans and processes with business goals. Improvement of Security Information processes, IT general controls, platforms assessments: Windows, Unix, cloud environments (AWS) and SAP's Systems (ERP). Management of Ethical Hacking Tools such as: Tenable, Kali Linux, Open Vass, BurpSuite; SIEM tools like a Wazuh, Exabeam; and Compliance Tools like a Vanta, Align, MetricStream. With high knowledge in cybersecurity and international frameworks such as NIST, ISO27005, COBIT 5, ITIL V.3 y 4, TOGAF, ISO27000, ISO27001, ISO22301, SOC reports and Law Sarbanes Oxley (SOX).
Next Audit & Consulting Sas & Llc
View- Website:
- nextayc.com
- Employees:
- 3
-
Cybersecurity ManagerNext Audit & Consulting Sas & Llc Jul 2024 - PresentMedellín, Antioquia, Colombia -
Consulting Specialist CybersecurityMinsait Mar 2023 - Jun 2024Medellín, Antioquia, ColombiaExecution of consulting projects in information security, risk management, data privacy and GRC, specifically in:-GAP Analysis (As Is) of cybersecurity capabilities.- Improvements to SOC (Security Operation Center) services such as redefinition of correlation rules, development of playbooks, SOC reliability, sizing of event monitoring platforms.-Cybersecurity strategic advice.-Implementation of Information Security Management Systems.-Design and implementation of response to cybersecurity incidents.-Design and implementation of business continuity management. -
Cybersecurity And It Governance, Risk And ComplianceMillicom (Tigo) Sep 2022 - Mar 2023Medellín, Antioquia, Colombia1) Review of the design of Informatión Security, Cybersecurity and IT controls2) KPI measurement of IT SOX and Security/Cybersecurity Controls .3) Compliance and control of Security, Cybersecurity and IT controls and Entity level controls4) Implementation of action plans identified in the improvements detected by control entities5) Aligning security and IT plans and processes with business/comercial goals of the company. -
Cyber Security Lead ConsultantNext Audit & Consulting Feb 2022 - Sep 2022Medellín, Antioquia, Colombia- Responsibility for developing security strategies for companies and for overseeing the implementation and execution of said strategies, especially as a Chief Information Security Officer (CISO).- Elaboration of SOC Reports.- Design and implement the information security and cybersecurity management system aligning security architecture plans and processes with business goals in diferents clients and sector such as telecommunications, energy, retail, oil & gas, etc.- Design and implementation of agile cybersecurity audits.- Vulnerability management: Developed vulnerable test environment and ethical hacking for training and testing of various cyber capabilities.- Implementation of the information security event and incident management model. -
Information Technology Governance Functional ConsultantTata Consultancy Services Jun 2021 - Feb 2022Medellín, Antioquia, Colombia-Design, define, improve policies and controls of IT and Information Security, based on frameworks such as NIST, ISO27001, COBIT 5 and ITIL.-KPI measurement of Security Operation Center (SOC).-Segregation duties analysis in SAP's Systems and Inhouse development.- responsible for the SOC report. -
Senior Iii Technology RiskEy Aug 2018 - Jun 2021Antioquia, ColombiaCoordination and Execution of information security projects, such as: -Vulnerability management: Developed vulnerable test environment and ethical hacking for training and testing of various cyber capabilities.- Incidents and events management: Redesign of policies of incidents/events of information security, process based such as ITIL and NIST frameworks and KPI measurement- Segregation of duties: analysis in SAP's Systems and Inhouse development.- Hardening: Application security on operative Systems and data base. Information Systems Baselines.- Cybersecurity audits: verifying controls base on frameworks such ISO 27001, NIST 800-53 and COBIT.- Created Cybersecurity best practice communications to educate staff of clients against known threats.- Design and maintain security policies, define and improve security policies and controls and review of domains of ISO27001, in the following sectors, Energy, Technology, Telecommunications, etc.- Elaboration of SOC reports, type 1, 2 and 3. -
Information Technology Lead AuditorSpradling Group Mar 2018 - Aug 2018Bogotá D.C., ColombiaEstablish, design, coordinate and execute the Annual IT Internal Audit Program and Information Security Program based on:• Process map. • Organizational requirements.• Requirements of international standards.• Criticality of the processes.• Results of previous audits.-Communication and writing of the audit findings (Strengths, opportunities for improvement, observations, non-conformities). Preparation of audit reports to the Management.-Evaluation data quality and define migration plan to SAP.- Design, Audit and implementation continuity Business plan. -
Senior ConsultantPwc Colombia Oct 2017 - Mar 2018Bogotá D.C., ColombiaCoordination and Execution of information security projects, such as: -Vulnerability management: Developed vulnerable test environment and ethical hacking for training and testing of various cyber capabilities.- Incidents and events management: Redesign of policies of incidents/events of information security, process based such as ITIL and NIST frameworks and KPI measurement- Segregation of duties: analysis in SAP's Systems and Inhouse development.- Hardening: Application security on operative Systems and data base. Information Systems Baselines.- Cybersecurity audits: verifying controls base on frameworks such ISO 27001, NIST 800-53 and COBIT.- Design and maintain security policies, define and improve security policies and controls and review of domains of ISO27001, in the following sectors: Financial/banking, retail, Technology, etc. -
Information Security Consultant-AuditorEy Jul 2014 - Oct 2017BogotaExecution of security information projects, such as: vulnerability management, incident and events management, developing of the segregation of duties of the different Systems of the application layer in the following clients, SOX Compliance: in the following sectors: Telecommunications, financial, Oil & Gas, Energy, retail, etc. -
Microsoft ConsultantPalmtree Consulting Mar 2014 - Jul 2014Responsible for the analysis, development and implementation of solutions in SharePoint 2013, InfoPath and Microsoft Office 365.
Jorge Andrés Serrano Education Details
-
Ingeniería De Sistemas
Frequently Asked Questions about Jorge Andrés Serrano
What company does Jorge Andrés Serrano work for?
Jorge Andrés Serrano works for Next Audit & Consulting Sas & Llc
What is Jorge Andrés Serrano's role at the current company?
Jorge Andrés Serrano's current role is Information Cybersecurity Lead Consultant.
What schools did Jorge Andrés Serrano attend?
Jorge Andrés Serrano attended Universidad Piloto De Colombia.
Who are Jorge Andrés Serrano's colleagues?
Jorge Andrés Serrano's colleagues are Cindy Garcés, Viviana Barrera Pineda, Nelson E. Camargo P, Matias Joel Vanella, Leidy Carolina Miranda Quintero.
Not the Jorge Andrés Serrano you were looking for?
-
-
Jorge Borja Serrano
Data Analyst @ Promigas | Mathematician & Ms. Applied Statistics | Statistical Analysis, Machine LearningBarranquilla -
-
Jorge Andrés Serrano
Performance Testing Engineer At Scotiabank ColpatriaBogotá D.c. Metropolitan Area2gmail.com, colpatria.com
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial