Phyllis Johnson

Phyllis Johnson Email and Phone Number

Corporate Vice President-Information Security @ New York Life
Tarrytown, NY, US
Phyllis Johnson's Location
Tarrytown, New York, United States, United States
About Phyllis Johnson

Information Security and Risk Management professional with demonstrated ability in developing, managing, and providing SME consulting on Information Security and Risk Management programs. Experienced in a diverse set of core competencies including:* Risk Assessment and Risk Assessment team management* Risk Management framework and methodology development* Governance, Risk and Compliance (GRC) program development* Risk Register development and reporting* Metrics development and reporting* Information Security policy development and exception management* Information Security Awareness* Information Security Officer and Liaison programs* Compliance to Industry standards and regulations such as HIPAA and ISO 27001/27002* Records Management* Business Continuity

Phyllis Johnson's Current Company Details
New York Life

New York Life

View
Corporate Vice President-Information Security
Tarrytown, NY, US
Company phone:
212-576-7000
Company email:
socialmedia@newyorklife.com
Phyllis Johnson Work Experience Details
  • New York Life
    Corporate Vice President-Information Security
    New York Life
    Tarrytown, Ny, Us
  • New York Life
    Corporate Vice President-Information Security
    New York Life Mar 2008 - Present
    New York, New York, Us
    • Manage the information security risk assessment function in the Chief Information Security Office for all IT infrastructure and application projects; including chairing meetings to discuss risk mitigation with business areas; providing follow up guidance on how to mitigate identified risks, and reviewing security designs for approval.• Developed the Information Security Risk Register to document key risk drivers and monitor actions towards their mitigation. Report Information Security risks to the Chief Risk Management Office for inclusion in the Enterprise Risk Register. • Chair the Information Security Risk Working Group to review the Information Security Risk Register and discuss emerging risks.• Managed the selection and implementation of the Governance Risk and Compliance (GRC) framework; including documentation of requirements, RFP process management, and vendor relationship management.• Developed GRC applications to maintain the Information Security Risk Register, monitor third party risk, and access HIPAA compliance. • Provide oversight of Information Security Policy, Policy Exception, Policy Awareness, and Risk Assessment functions for the enterprise.• Provide oversight of the enterprise Information Security Liaison and Security Officer programs; including providing guidance on how to mitigate risk within their respective business areas. • Member of enterprise wide councils including Records Management and Operational Risk Working Group (Alternate for the CISO)
  • New York Life
    Risk Engineer
    New York Life Mar 2001 - Mar 2008
    New York, New York, Us
    • Managed one of the two enterprise-wide Security Review Boards that review new and modified systems for security vulnerabilities.• Developed the Information Security Risk Model that is used to determine the risk level that new IT projects or system modifications will have on NYL. • Developed the questionnaire used to calculate inherent risk• Business Continuity Representative for the Chief Information Security Officer’s organization.• Performed gap analyses of domestic and International Security Programs to the ISO 27002 standard.• Participated in Health Insurance Portability and Accountability Act (HIPAA) regulatory reviews • Developed a metrics program report KRI progress against goals to the Chief Information Security Officer.• Managed New York Life submission to Industry and Peer group industry benchmark studies.
  • New York Life
    Director Information Security
    New York Life Aug 1998 - Mar 2001
    New York, New York, Us
    • Documented information security policies and technical security standards • Managed the Security Liaison Program, which provided training and support approximately 200 departmental security representatives throughout the company.• Developed and implemented Security Certification, Testing, and Training programs• Developed training programs, including an Introductory Security Liaison Computer Based Course • Wrote the Security Liaison Handbook that explained access control responsibilities and procedures.• Performed annual Security Liaison performance appraisals.• Arranged quarterly meetings and awareness presentations• Managed the server policy compliance program including selection and implementation of a server compliance product; and risk mitigation and follow up• Implemented a plan for risk assessment and mitigation of externally performed penetration tests.• Promoted security awareness by initiating an Information Security intranet site, issuing security alerts, publishing newsletters, and managing the company’s annual Information Security Awareness Day

Phyllis Johnson Skills

Information Security Business Continuity It Security Policies It Risk Management It Security Awareness It Security Assessments It Security Architecture Hipaa Iso 27001 Iso 27005 Disaster Recovery Vendor Management Sdlc Risk Management Project Management Governance Security Enterprise Architecture

Phyllis Johnson Education Details

  • Pace University - Lubin School Of Business
    Pace University - Lubin School Of Business
    Management Information Systems
  • Binghamton University
    Binghamton University
    Economics

Frequently Asked Questions about Phyllis Johnson

What company does Phyllis Johnson work for?

Phyllis Johnson works for New York Life

What is Phyllis Johnson's role at the current company?

Phyllis Johnson's current role is Corporate Vice President-Information Security.

What is Phyllis Johnson's email address?

Phyllis Johnson's email address is ph****@****hoo.com

What is Phyllis Johnson's direct phone number?

Phyllis Johnson's direct phone number is +160959*****

What schools did Phyllis Johnson attend?

Phyllis Johnson attended Pace University - Lubin School Of Business, Binghamton University.

What skills is Phyllis Johnson known for?

Phyllis Johnson has skills like Information Security, Business Continuity, It Security Policies, It Risk Management, It Security Awareness, It Security Assessments, It Security Architecture, Hipaa, Iso 27001, Iso 27005, Disaster Recovery, Vendor Management.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.