Chief Information Security Officer
CurrentBuilt the information security program for Fortress Information Security - a company specializing in third-party risk management for critical infrastructure. As the Chief Information Security Officer (CISO) and a senior executive, I worked across all departments to ensure enterprise security to develop and implement a comprehensive information ad cyber security roadmap which achieving and maintaining SOC 2 Type 2 and DoD 800-171 Compliance.► Architected and implemented a comprehensive cyber security and GRC program► Recruited and developed both the Enterprise Security and IT teams► Designed and implemented internal controls to meet and exceed the requirements of both SOC 2 and DoD 800-171, with an emphasis on security and scalability► Developed and Implemented incident response, vulnerability management, responsible disclosure, supply chain risk management, penetration testing, and other defensive security programs to protect both Fortress and its customers► Managed and accountable for full P&L for Security and IT departments and reported to the Chairman of the Board