Vice President, Technology Risk
- Led enterprise-wide risk oversight for various technology programs (e.g., Data Loss Prevention, Identity and Access Management, Virtual Desktop Infrastructure etc.).
- Created a capability reference model to influence the Identity and Access Management program to improve the strategy and roadmap of capabilities and controls.
- Introduced the MITRE ATT&CK framework into the risk management function to guide in assessing and reviewing remediation plans based on Tactics, Techniques, and Procedures (TTPs) leveraged by penetration testers.
- Evaluated and monitored remediation plans related to risk assessments, regulatory reviews, and penetration test which ensured issues were mitigated and associated risk were reduced to acceptable levels.