Vice President, Technology Risk
Led enterprise-wide risk oversight for various technology programs (e.g., Data Loss Prevention, Identity and Access Management, Virtual Desktop Infrastructure etc.).• Created a capability reference model to influence the Identity and Access Management program to improve the strategy and roadmap of capabilities and controls.• Introduced the MITRE ATT&CK framework into the risk management function to guide in assessing and reviewing remediation plans based on Tactics, Techniques, and Procedures (TTPs) leveraged by penetration testers. • Evaluated and monitored remediation plans related to risk assessments, regulatory reviews, and penetration test which ensured issues were mitigated and associated risk were reduced to acceptable levels.