Mark Lubas, Cisa
AeroLeads people directory · profile

Mark Lubas, Cisa Email & Phone Number

Information Security Leader | Cybersecurity Risk Management | Cyber Compliance Management | ERP GRC Implementation Leader | IT Audit Leader | Controls Management
Location: Oakland, New Jersey, United States 12 work roles 1 school
LinkedIn matched
✓ Verified July 2026 3 data sources Profile completeness 71%

Contact Signals

LinkedIn Profile matched
3 free lookups remaining · No credit card
Role
Information Security Leader | Cybersecurity Risk Management | Cyber Compliance Management | ERP GRC Implementation Leader | IT Audit Leader | Controls Management
Location
Oakland, New Jersey, United States

Who is Mark Lubas, Cisa? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Mark Lubas, Cisa is listed as Information Security Leader | Cybersecurity Risk Management | Cyber Compliance Management | ERP GRC Implementation Leader | IT Audit Leader | Controls Management based in Oakland, New Jersey, United States. AeroLeads shows a matched LinkedIn profile for Mark Lubas, Cisa.

Mark Lubas, Cisa previously worked as Director Information Security - GRC at Bd and Director Cybersecurity Strategy at Bd. Mark Lubas, Cisa holds Bachelor Of Science (B.S.), Accounting And Finance from Rutgers, The State University Of New Jersey-Newark.

Profile bio

About Mark Lubas, Cisa

Experienced Cybersecurity professional with 20+ years inspiring global teams to achieve excellence in process discipline, increased cybersecurity maturity and reduced risk. Experience in Cybersecurity Program Management, Governance Risk & Compliance, Cyber Risk Management & Reporting, NIST Cybersecurity Framework (CSF), ISO 27001, IT Audit, SAP Access Controls, Identity Access Management, Policy Life-cycle Management, SOC2 Reporting, and IT SOX Compliance. Have been a speaker at GRC conferences and I enjoy sharing knowledge and teaching others about cybersecurity.I am passionate about:- Raising awareness about importance of good cybersecurity practices - Leading teams to accomplish strategic initiatives- Evaluating controls and cybersecurity risks to strengthen overall cybersecurity posture- Utilizing technology to efficiently analyze data and provide meaningful insights to drive change- Establishing effective processes with appropriate controls- Leveraging solutions to drive process effectiveness and continuously improve efficiency

12 roles

Mark Lubas, Cisa work experience

A career timeline built from the work history available for this profile.

Director Information Security - Grc

Bd

Franklin Lakes, New Jersey, United States

- Program Leader for SEC Cybersecurity Disclosure initiative including development of 8-K cyber incident response and materiality evaluation process as well as preparation for 10-K risk management reporting- Directed GRC group to ensure completion of risk management activities, cybersecurity policy development, SOC2 & ISO 27001 compliance, global training & awareness campaigns and phishing simulations- Program Leader for IS Assessment Remediation initiative covering enterprise IT and OT with goal of increasing capability maturity and reducing cybersecurity risk- Delivered executive updates on cybersecurity program to Cybersecurity Risk Committee and regularly updated steering committee regarding SEC cybersecurity Disclosure requirement readiness

Sep 2023 - Feb 2024

Director Cybersecurity Strategy

Bd

Franklin Lakes, New Jersey, United States

- Directed Cybersecurity Strategy including program updates to executive leadership and Board of Directors Audit Committee- Collaborated with cybersecurity leadership to develop cybersecurity metrics program to measure and monitor key performance indicators and identify areas for improvement- Directed cybersecurity program management office providing PMP certified project managers for strategic security initiatives across IT, OT and Product Security- Served as program director for IS assessment remediation program to increase our cybersecurity capability maturity aligned with NIST cybersecurity framework and reduce risk. - Developed and directed global cybersecurity training and awareness program including identification of mandatory training courses and annual cybersecurity awareness month campaign- Directed Cyber Wargame simulation exercise for Crisis Management Team, Executive Leadership Team and Board of Directors; included scenario formulation, identification or injects, consultation with trusted agents and reporting- Established company-wide phishing simulation program which leveraged threat intelligence to craft monthly automated email campaigns for all associates and contingent workers- Designed dashboards to monitor global cybersecurity training compliance and phishing simulation results to deliver insights for executive leadership and influence use behaviors to strengthen company-wide cyber hygiene- Assisted with development of Board of Directors cybersecurity engagement strategy which included National Association of Directors cyber risk oversight training

Feb 2020 - Sep 2023

Director Governance Risk & Compliance (Information Security)

Bd

Franklin Lakes, New Jersey

- Reported to CISO and directed global group of 30 cybersecurity professional consisting of IT Compliance, Policy Management, Cybersecurity Assurance & Trust, Governance & Risk and IAM- Responsible for hiring, developing and retaining talent with necessary knowledge and skills to achieve objectives- Prepared executive presentations for Information Security Risk Council and Audit Committee highlighting cybersecurity risks, incidents, threats and vulnerabilities.- Directed all GRC workstreams for IS Strategic Transformation Program including risk management, key security control testing, policy lifecycle management and data governance- Managed multi-million dollar budget with detailed tracking ensuring completion of initiatives on schedule and within budget along with planning and forecasting throughout the year- Improved overall risk management and compliance capabilities to reduce cybersecurity risk and increase process maturity through implementation of industry leading practices- Guided IT compliance program ensuring requirements including SOX, SOC2, ISO 27001, PCI, HIPAA Security Rule, etc. are achieved - Managed performance of application risk and control assessments as part of post-acquisition integration work to identify control gaps across global technology ecosystem - Developed maturity assessment model based on NIST cybersecurity framework and ISO 27001 to evaluate maturity level across domains- Coordinated InfoSec Risk Council comprising executive leaders meeting regularly to review cybersecurity risks, incidents and related compliance topics- Directed implementation of GRC solutions including SAP Access Controls, SOX Express/FCM Archer GRC, Identity Governance- Managed IT Compliance due diligence for two multi-billion dollar acquisitions and identified control gaps requiring remediation to ensure compliance- Involved in developing Cybersecurity Trust Center to provide customers SOC2 attestation reports and ISO 27001 compliance certificates.

Jan 2015 - Jan 2020

Director Integrated Systems Compliance (Information Technology)

Bd

Franklin Lakes, New Jersey

- Directed IT Compliance function ensuring adherence to IT SOX compliance methodology for documenting, testing and evaluating IT controls- Coordinated external audit IT Audit engagement and facilitated leadership compliance sessions- Prepared executive summaries on IT SOX compliance program and remediation activities to address control deficiencies- Led Integrated Systems Compliance group focused on IT Compliance and directing IT SOX controls compliance program including management of external audit engagement- Directed Internal Controls Management team and drove process governance for Compliant User Provisioning, Elevated Privileged Management, Risk Analysis & Remediation, User Access Reviews and Segregation of Duties - Provided leadership guidance for strengthening controls to enhance effectiveness and drive efficiency via automation thereby reducing risk of control deficiencies due to manual processes- Delivered risk and compliance insights to leadership enabling strategic decisions on prioritization of initiatives to drive remediation activities and reduce risk - Engaged global business process leaders to advocate for advancement of Internal Controls Management processes and foster alignment between business and IT processes- Guided execution of SAP security role design gate governance process to ensure segregation of duties analysis is proactively performed to prevent inherent SoD conflicts from being included in design of roles- Implemented SAP security role design gate governance process to ensure segregation of duties analysis is proactively performed to prevent inherent SoD conflicts from being included in role design

Jun 2014 - Jun 2016

Global Process Leader - Finance To Manage & Internal Controls Management

Bd

Franklin Lakes, New Jersey

- Directed business process and Internal Controls Management teams consisting of eleven internal controls professionals responsible for implementing and supporting global business process design utilizing SAP solutions- Directed team to implement globally standardized processes using SAP ECC 6.0 and SAP GRC solutions.- Guided multinational team through design, test, train and implement phases to ensure deployment of a uniform process across the enterprise.- Partnered and collaborated with business leaders and key stakeholders to define global business requirements to incorporate into design to deliver process improvements- Guided global finance and internal control process community through change management to help drive adoption and utilization of new enterprise-wide business process capabilities- Collaborated with business, regional and functional leaders to implement global design governance methodology to ensure sustainment of SAP enterprise process design- Utilized leadership skills to ensure alignment between business process and IT teams to accomplish critical implementation tasks by leveraging an integrated team approach- Led effort with Internal Audit and E&Y to establish framework for internal controls embedded within process design to sustain and enhance SOX compliance- Worked with business leaders to understand project demand and asses business impact as part of portfolio management and requirement prioritization process- Provided executive updates on implementation progress and risk areas requiring leadership attention to focus organizational resources- Collaborated with IT Compliance and Systems Validation teams to implement cross functional matrix spanning 100+ process areas and identifying key risks and controls necessary to strengthen process design

May 2009 - Jun 2014

Associate Director, Continuous Assurance

Bd

Franklin Lakes, Nj

• Established Continuous Assurance group within Global Internal Audit Department, with responsibility for directing Global SOX Compliance Function and performing continuous control assessments.• Served as framework architect on SOX implementation team and was responsible for building and deploying the BD global SOX Compliance methodology leveraging COSO and COBIT control framework models• Directed staff of seven control analysts across three regions with responsibility for creating strategy, performing risk assessments, internal control reviews, and segregation of duties analysis to support 50+ locations • Collaborated with IT to ensure pervasive IT controls and SAP application controls are incorporated into compliance framework and leveraged to address business risks• Provided independent assurance to executive management and the Audit Committee that compliance is maintained as required by the Sarbanes-Oxley Act of 2002 (SOX)• Created SOX Section 302 Sub-Certification and Management Representation letter process for key executive leaders, line managers and controllers as well as provided training for functional leaders• Utilized project management skills to lead global project which implemented approach for performing continuous controls monitoring utilizing technology to interrogate business transactions and identify exceptions• Responsible for monitoring internal controls over financial reporting and providing finance leaders with executive summary of key issues and control deficiencies

Jan 2003 - May 2009

It Audit Manager

Bd

- Managed team team of three IT auditors performing audits across applications (SAP, JDE Edwards, etc.), security and privacy audits, infrastructure reviews (Oracle, UNIX, Lotus Notes, etc.),and data center audits.- Performed special projects for executive management resulting in risk identification for Audit Committee.- Executed annual risk assessment to determine IT Audit scope for each fiscal year- Mentored IT Audit Staff members and provided knowledge transfer on IT, Audit and information security related topics- Performed annual IT risk assessment to identify applications, systems and technology items which have key risk indicators and require audit consideration- Produced audit committee books to summarize IT audit observations and provide perspective on internal controls- Provided internal control guidance on emerging risk areas impacting SAP application utilization across the business

Jan 2000 - Dec 2002

Supervising Senior Auditor - Integrated It, Financial And Business Process Audits

Bd

Franklin Lakes, Nj (With Global Travel)

Lead team of audit professionals to conduct inetegrated finance, operations and IT audits using technology such as ACL, Direct Link and others analyze business transactions and evalaute internal controls in SAP and non-SAP environments.Performed audit risk assessments, engaged with business leaders to understand financial, operational and IT risks as input into establishing audit programs focused on meeting defined audit objectives as well as providing value to the organziation through identification of process improvement opportunities.

Jun 1996 - Dec 1999

Supervising Senior It Auditor

Performed IT, operational and process oriented audits using computer assisted audit techniques (CAAT) to analyze data and identify control weaknesses as well as opportunities for process improvement. In addition, contributed to financial audits working in an integrated audit approach to cover both financial as well as IT internal control evaluations. Also, trained staff on use of ACL and other CAAT tools to improve audit efficiency.

Jan 1995 - May 1996

Senior Auditor

Performed financial, operational, process and IT audits across business units and corporate functions. Assisted in the training of staff auditors.

Jan 1993 - Dec 1994

Staff Auditor

Performed financial audits across various corporate functions such as general accounting, treasury, fixed assets, etc.

Feb 1992 - Dec 1992

Staff Accountant

Peformed various general accounting activities including journal entry preparation, fixed asset depreciation analysis,etc.

Jan 1991 - Jan 1992
1 education record

Mark Lubas, Cisa education

FAQ

Frequently asked questions about Mark Lubas, Cisa

Quick answers generated from the profile data available on this page.

What is Mark Lubas, Cisa's role at their current company?

Mark Lubas, Cisa is listed as Information Security Leader | Cybersecurity Risk Management | Cyber Compliance Management | ERP GRC Implementation Leader | IT Audit Leader | Controls Management.

Where is Mark Lubas, Cisa based?

Mark Lubas, Cisa is based in Oakland, New Jersey, United States.

What companies has Mark Lubas, Cisa worked for?

Mark Lubas, Cisa has worked for Bd, Liz Claiborne, and Nabisco Biscuit Company.

How can I contact Mark Lubas, Cisa?

You can use AeroLeads to view verified contact signals for Mark Lubas, Cisa, including work email, phone, and LinkedIn data when available.

What schools did Mark Lubas, Cisa attend?

Mark Lubas, Cisa holds Bachelor Of Science (B.S.), Accounting And Finance from Rutgers, The State University Of New Jersey-Newark.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.