-20 years of Information Security and Technology (I&T) Governance, Risk, and Compliance/Controls (GRC) and Operations leadership success in both professional services and industry.-15+ years Big Four business, cybersecurity, and technology governance, risk, and compliance advisor to global Fortune 500 CROs, CISOs, and CAEs in assessing, designing, and implementing a leading practice first, second, and third line of defense IS/IT risk management functions and teams.-Built the Enterprise Risk Management (ERM) department from scratch for Fortune 60 company.-Extensive Big Four consulting experience advising the following clients: Investment Management Firms ranging in size between $1T and $7+ Trillion in Assets Under Management (AUM); Banking/Credit Union/Financial Services with assets between $95 Billion and $2 Trillion; Health Care companies with annual revenues between $40B and $100+ Billion, and Retail/Transportation/ Technology companies with annual revenues between $2.5B and $600+ Billion.-Advisor to key clients: The Vanguard Group, Inc./BlackRock, Inc./T. Rowe Price Group, Inc./Franklin Templeton/General Electric (GE) Capital/General Motors Financial (GMF)/Credit Agricole Corporate and Investment Bank (CACIB)/Sallie Mae/City National Bank (Royal Bank of Canada)/State Employees Credit Union of North Carolina/Walmart, Inc./CSX Corporation/J.B. Hunt Transport Services, Inc./Playa Hotels and Resorts/McGraw Hill/ServiceNow/Pinterest/Pfizer/Merck/Humana.-$20+ Million Annual Sales | $1M - $5M Annual Managed Revenue | Up to 20+ Resources (Direct/Indirect).-Led internal audits and advisory consulting engagements in the business, cyber, and technology risk domains (e.g., Identity and access management; privileged account management; cloud governance and strategy; cloud security; IT asset obsolescence; supplier/third party risk management program; data privacy audits; data governance, management, and operations audits; etc.); Conducted risk assessments to develop multi-year audit plans.-Well versed in interpreting and socializing SEC, FFIEC, Gramm Leach Bliley Act (GLBA), OCC, GDPR/CCPA, NIST Cybersecurity Framework (CSF)/Risk Management Framework (RMF), COBIT, ISO2700X, ISO31000, COSO Integrated Framework, COSO ERM, and other technology and cybersecurity guidance and frameworks.
Listed skills include Writing, Variance Analysis, Litigation, Coso, and 233 others.