Director, Business Iso (Information Security Officer)
CurrentBusiness Information Security Officer (BISO), focused on implementing, maintaining and monitoring an integrated infrastructure portfolio (on-prem & CSP) for Equifax, earning over $7B+/year. As such, I continually assess threats, potential impact on business goals, and implement strategies for mitigation to balance Risk Components [Risk v Threat v Severity v Priority]. I seek to understand, evaluate & articulate Business Security Risk to our stakeholders, including defense in depth controls. I work to engage control owners to proactively address control deviations or gaps. I ensure reduced decision cycles for Senior leaders in their role of managing business risk.• Regularly advises the CISO on security issues/deviations; ID's issues/solutions, e.g., ransomware • Ensures transparency and confidence in corporate security that protects PII by assessing, analyzing, and driving development of various controls around SOC1, SOC2 and ISO27001::2022, FIPPS, FISMA, PCI DSS, HIPAA, CIS and NIST/FedRAMP, StateRamp. Authored BOT, AI / ML, risk, & breach contract policy.• Face of security; evaluates/authors RFPs, and edits 1K+ contracts for cyber language. Delivers security audits to ensure due care/diligence; leads root cause analysis with Legal, Compliance. • Leads special teams, e.g., Global Ransomware development of strategy & tools, maturing the posture.