Director Governance Risk & Compliance (Information Security)
Franklin Lakes, New Jersey
- Reported to CISO and directed global group of 30 cybersecurity professional consisting of IT Compliance, Policy Management, Cybersecurity Assurance & Trust, Governance & Risk and IAM- Responsible for hiring, developing and retaining talent with necessary knowledge and skills to achieve objectives- Prepared executive presentations for Information Security Risk Council and Audit Committee highlighting cybersecurity risks, incidents, threats and vulnerabilities.- Directed all GRC workstreams for IS Strategic Transformation Program including risk management, key security control testing, policy lifecycle management and data governance- Managed multi-million dollar budget with detailed tracking ensuring completion of initiatives on schedule and within budget along with planning and forecasting throughout the year- Improved overall risk management and compliance capabilities to reduce cybersecurity risk and increase process maturity through implementation of industry leading practices- Guided IT compliance program ensuring requirements including SOX, SOC2, ISO 27001, PCI, HIPAA Security Rule, etc. are achieved - Managed performance of application risk and control assessments as part of post-acquisition integration work to identify control gaps across global technology ecosystem - Developed maturity assessment model based on NIST cybersecurity framework and ISO 27001 to evaluate maturity level across domains- Coordinated InfoSec Risk Council comprising executive leaders meeting regularly to review cybersecurity risks, incidents and related compliance topics- Directed implementation of GRC solutions including SAP Access Controls, SOX Express/FCM Archer GRC, Identity Governance- Managed IT Compliance due diligence for two multi-billion dollar acquisitions and identified control gaps requiring remediation to ensure compliance- Involved in developing Cybersecurity Trust Center to provide customers SOC2 attestation reports and ISO 27001 compliance certificates.