Keith May, Cissp, Iso/Iec Security Risk Management
AeroLeads people directory · profile

Keith May, Cissp, Iso/Iec Security Risk Management Email & Phone Number

VP - CISO Risk Officer at Citi
Location: Dallas-Fort Worth Metroplex, United States 6 work roles 1 school
1 work email found @sabre.com 1 phone found area 940 LinkedIn matched
✓ Verified August 2026 4 data sources Profile completeness 100%

Contact Signals · 1 work email · 1 phone

Work email k****@sabre.com
Direct phone (940) ***-****
LinkedIn Profile matched
3 free lookups remaining · No credit card
Current company
Role
VP - CISO Risk Officer
Location
Dallas-Fort Worth Metroplex, United States
Company size

Who is Keith May, Cissp, Iso/Iec Security Risk Management? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Keith May, Cissp, Iso/Iec Security Risk Management is listed as VP - CISO Risk Officer at Citi, a with 10 employees, based in Dallas-Fort Worth Metroplex, United States. AeroLeads shows a work email signal at sabre.com, phone signal with area code 940, and a matched LinkedIn profile for Keith May, Cissp, Iso/Iec Security Risk Management.

Keith May, Cissp, Iso/Iec Security Risk Management previously worked as Senior Consultant- Cybersecurity Risk Management at Williams-Sonoma, Inc. and Principal – GRC Cybersecurity, Sabre Technology, Engineering, and Operations Risk & Security at Sabre Corporation. Keith May, Cissp, Iso/Iec Security Risk Management holds Computer Science from East Texas State University.

Company email context

Email format at Citi

This section adds company-level context without repeating Keith May, Cissp, Iso/Iec Security Risk Management's masked contact details.

*@sabre.com
68% confidence

AeroLeads found 1 current-domain work email signal for Keith May, Cissp, Iso/Iec Security Risk Management. Compare company email patterns before reaching out.

Profile bio

About Keith May, Cissp, Iso/Iec Security Risk Management

Highly accomplished and dynamic leader who drives successful information security risk management initiatives and delivers results. Adept at executing information security management programs and leading security GRC integrations. Deep domain knowledge and comprehensive understanding of information technology and information security sectors to provide robust protection for critical assets. Recognized for strategic vision, communication, and collaboration.CORE COMPETENCIES- Risk Management - Risk Assessment- Security Metrics / Visualization- Vendor Risk Management- Information Security Management Systems- Regulatory Compliance- Information Security Policies / Standards- Tool Evaluation and Selection- Cloud Security- Agile DevelopmentPROFESSIONAL DEVELOPMENT- PECB Certified ISO / IEC 27005 Lead Risk Manager- PECB Certified ISO / IEC 27001 Senior Lead Implementer- (ISC)2 Certified Information Systems Security Professional (CISSP)- HITRUST Certified CSF PractitionerFRAMEWORKS AND TECHNOLOGIES- ISO / IEC 27001:2022- ISO / IEC 27005:2022- ISO 31000:2018- NIST 800-53 - NIST CSF - COBIT 5- COBIT 2019- Archer - ServiceNow - Prisma Cloud - Prisma Access- Qualys- Sonatype- Veracode - Tenable- Nessus- Microsoft: Excel, Word, Visio, PowerPoint, SharePoint

Listed skills include Information Security, Business Continuity, Vendor Management, It Strategy, and 11 others.

Current workplace

Keith May, Cissp, Iso/Iec Security Risk Management's current company

Company context helps verify the profile and gives searchers a useful next step.

Citi
Citi
VP - CISO Risk Officer
Mumbai, Maharashtra
Website
Employees
10
AeroLeads page
6 roles · 24 years

Keith May, Cissp, Iso/Iec Security Risk Management work experience

A career timeline built from the work history available for this profile.

Vp - Ciso Risk Officer

Current

New York, New York, Us

Drive Risk and Control Agenda including policy dissemination, process reviews, risk/control identification, KRI assignments, and developing, enhancing and documenting processes to improve efficiency and strengthening the control environment.Identify and assign key metrics (KPI/KRI) to support effective monitoring and management of operational risks including control assurance and ensuring corrective action plans are raised to address identified gaps.Provide strong oversight of CAP remediation activities both for Audit and control issues including quality completion of Risk Exception documentation and annual renewals.Supporting assigned technology platforms ensuring the timely remediation of corrective action plans relating to both self-identified and and Audit issues.Supporting assigned technology platforms during internal and external audits.Assist with all interactions including deliverables management, audit fieldwork, business monitoring and meetings.

Apr 2024 - Present

Senior Consultant- Cybersecurity Risk Management

San Francisco, Ca, Us

Assess, Document, and Improve WSI Cybersecurity Risk Posture

Sep 2023 - Apr 2024

Principal – Grc Cybersecurity, Sabre Technology, Engineering, And Operations Risk & Security

Southlake, Texas, Us

Ensured ISO compliant implementation, integration, and coordination of information security risk management activities. Managed policy and exception management program team consisting of 3 FTEs and 1 indirect FTE. Performed iterative security risk assessments to identify, analyze, and evaluate emerging risks in dynamic global environment. • Led diverse cross-functional teams in ISO 27001 Certification Readiness project, achieving 93% compliance rating (0 gaps, 8 Opportunities for Improvement) in an independently performed gap analysis.• Authored and maintained global information security policies and standards covering 100% of the ISO 27001 control requirements.• Implemented cost-efficient structured content management system (SharePoint + Power Automate), improving user experience, advancing the information security communication strategy, and automating management of all ISMS documents.• Established risk acceptance criteria and standard risk assessment and treatment methodology in company GRC system (Archer), achieving consistent repeatable assessment results while eliminating process inefficiencies associated with manual collaboration and monitoring activities. • Developed risk hierarchy and risk register in GRC platform, tying into specific portfolios to better inform key decision makers on types of risk incurred.• Decreased quarterly metric reporting cycles and eliminated need to manually produce functional dashboards and scorecards by developing and implementing key indicator management (KRIs / KPIs) in the Archer GRC system, providing near real-time metric view of risk.• Improved policy exception requests processing, lowering rejection rates 90% and reducing processing times from 10 days to 2.1 days by redesigning Archer advance workflows.

2016 - Oct 2023

Vice President Technology & Information Risk / Identity & Access Management 2009 - 2014

New York, Ny, Us

Directed Group Information Security for Access Management for Solomon Smith Barney and Private Bank. Managed Level III Entitlement Support consisting of 6 FTEs tasked with initiating role-based access controls (RBAC). Oversaw third-party information security assessments on high-risk providers to identify, document, and mitigate information security issues.• Developed role-based access controls (RBAC) for Morgan Stanley Solomon Smith Barney retail business processes and applications, placing 86% of users under role management, eliminating separation of duties issues and ensuring principle of least privilege.• Reduced provisioning times from an average of 10 days to 0 days.• Initiated governance practices for enterprise roles by identifying role owners, creating change request mechanisms, and hosting change advisory board for stakeholders, ensuring only reviewed and approved access was provided to business systems. • Achieved 100% on time completion rate of semi-annual role certifications and entitlement reviews. • Implemented Global Wealth Management role certification process to enable delta entitlement reviews (entitlements outside user’s functional role), eliminating 1.7M required semi-annual reviews.

2009 - 2014 ~5 yrs

Vp - Identity & Access Management, Citigroup Global Wealth Management

New York, New York, Us

Acquired by Morgan Stanley

2007 - 2009 ~2 yrs

Vp - Business Information Security Officer

New York, New York, Us

Business Information Security Officer (BISO) aligned with Citigroup Private Label Credit Card line of business to provide leadership on all aspects of corporate information security initiatives. • Acted as primary liaison between Executive Business Leadership and Corporate Risk and Security function. • Led Risk Control Self-Assessments (RCSA) to ensure that information risk was identified, developed mitigating controls, tracked and reported mitigation efforts, and managed risk acceptance process. • Primary Information Security point of contact for internal and external audits completed 41/41 internal and external reviews with 0 information security findings issued. As a result, LOB qualitative inherent risk rating for information security improved from Med-High to Low.• Led Business Security Incident Response Team (BSIRT) ensured security events were properly identified, evaluated and responded to.• Conducted thorough in-depth postmortem activities ensuring lessons learned were incorporated in operating procedures.• Conducted third-party information security assessments (TPISA) for critical suppliers.

2003 - 2006 ~3 yrs
Team & coworkers

Colleagues at Citi

Other employees you can reach at citibank.com. View company contacts for 10 employees →

1 education record

Keith May, Cissp, Iso/Iec Security Risk Management education

  • East Texas State University
    East Texas State University
    Computer Science
FAQ

Frequently asked questions about Keith May, Cissp, Iso/Iec Security Risk Management

Quick answers generated from the profile data available on this page.

What company does Keith May, Cissp, Iso/Iec Security Risk Management work for?

Keith May, Cissp, Iso/Iec Security Risk Management works for Citi.

What is Keith May, Cissp, Iso/Iec Security Risk Management's role at Citi?

Keith May, Cissp, Iso/Iec Security Risk Management is listed as VP - CISO Risk Officer at Citi.

What is Keith May, Cissp, Iso/Iec Security Risk Management's email address?

AeroLeads has found 1 work email signal at @sabre.com for Keith May, Cissp, Iso/Iec Security Risk Management at Citi.

What is Keith May, Cissp, Iso/Iec Security Risk Management's phone number?

AeroLeads has found 1 phone signal(s) with area code 940 for Keith May, Cissp, Iso/Iec Security Risk Management at Citi.

Where is Keith May, Cissp, Iso/Iec Security Risk Management based?

Keith May, Cissp, Iso/Iec Security Risk Management is based in Dallas-Fort Worth Metroplex, United States while working with Citi.

What companies has Keith May, Cissp, Iso/Iec Security Risk Management worked for?

Keith May, Cissp, Iso/Iec Security Risk Management has worked for Citi, Williams-Sonoma, Inc., Sabre Corporation, and Morgan Stanley.

Who are Keith May, Cissp, Iso/Iec Security Risk Management's colleagues at Citi?

Keith May, Cissp, Iso/Iec Security Risk Management's colleagues at Citi include Vinith P, Sandeep Singh, Emmy S., Sarah Yammer, and Gokula Krishnan S.

How can I contact Keith May, Cissp, Iso/Iec Security Risk Management?

You can use AeroLeads to view verified contact signals for Keith May, Cissp, Iso/Iec Security Risk Management at Citi, including work email, phone, and LinkedIn data when available.

What schools did Keith May, Cissp, Iso/Iec Security Risk Management attend?

Keith May, Cissp, Iso/Iec Security Risk Management holds Computer Science from East Texas State University.

What skills is Keith May, Cissp, Iso/Iec Security Risk Management known for?

Keith May, Cissp, Iso/Iec Security Risk Management is listed with skills including Information Security, Business Continuity, Vendor Management, It Strategy, Business Analysis, Financial Services, Risk Management, and Sdlc.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.