Ciso
Current•Role as CISO:- Information security management: I oversee internal security, including the management of the Information Security Management System (ISMS) and business continuity.- ISMS maintenance: I maintain the ISMS and continuity strategy (BCP) under ISO 27001 and ISO 22301, managing ICT risks and ensuring compliance with regulations and privacy laws in the Americas and Europe.- Supervision of security audits and compliance: I coordinate and supervise internal and external security audits, working with auditors and regulators, and maintaining strong relationships.- Communication with the board: I regularly present to senior management and committees on the state of security and regulatory compliance.- Risk management and compliance: I develop strategies to align security with regulatory requirements and enhance resilience.- Three lines of defense model: I maintain and optimize the three lines of defense model in information security.- Incident response: I oversee the monitoring of vulnerabilities and incidents, leading effective response efforts.•Role as Information Security Manager for professional services:- Security consulting: I lead consulting in ISO 27001, 22301, DORA, NIS2, GDPR, audits, and development of security management systems, articulating policies, standards, and security processes.- Virtual CISO (vCISO): I act as CISO for various companies, leading their security areas and/or strategic projects, aligning cybersecurity initiatives with each organization's specific objectives.- Client and stakeholder relationships: I maintain relationships with clients and stakeholders, ensuring satisfaction and SLA compliance.•Additional responsibilities in corporate governance:- Development of governance strategy: I lead the creation and implementation of the corporate governance strategy, establishing committees to strengthen organizational structure.