Chief Information Security Officer
CurrentAs CISO, my responsibility has been to establish a new Cybersecurity division to protect systems for nearly 1 million residents and 6000 users. As the leader of this team, I have:Established a 17 person cybersecurity division responsible for monitoring, incident response, vulnerability management, application security, and compliance.Determined, communicated and implemented a strategy to implement cybersecurity best practices based on the Center for Internet Security framework. Advised other senior level positions on security threats, risks and counter measures in ways that are understandable to non-technical leaders.Provided technical guidance to other teams and participated as a SME in architecture discussions.Lead the division in implementing major security initiatives such as establishing a SOC, vulnerability management, MFA and user education.Participated in multiple major RFPs as a security subject matter expert.Supported the risk management department in acquiring cyber security insurance.Improved security governance by drafting County policy and establishing department level standards.Worked with other leadership to ensure security posture was maintained or improved as part of the County’s temporary shift to remote work in response to COVID-19.Worked with internal audit to assess process effectiveness and track gap remediation.Assessed risk in the form of reviewing changes, new initiatives, potential purchases and contracts.Represented Gwinnett County IT in the UASI federal grant program and lead the cyber security working group.