Richard Fry

Richard Fry Email and Phone Number

Senior Manager Governance Risk and Compliance @ NewDay
Huddersfield, GB
Richard Fry's Location
Huddersfield, England, United Kingdom, United Kingdom
Richard Fry's Contact Details

Richard Fry personal email

n/a
About Richard Fry

A highly experienced Security Leader with over 25 years front line security experience, who is both personable and highly technical, task focused, experienced in bringing best in class security solutions into full operation whilst understanding the business needs, works well leading a team of like minded individuals in a security aware organisation. Articulate and able to explain things to both technical and non-technical staff in a clear and pragmatic fashion.ISEB Certificate in Information Security Management Practices (CISM) DistinctionISEB Certificate in Information Risk Management (CIRMP).EC-Council Certified Ethical Hacker (CEH)Specialties: •Vulnerability & Compliance Scanning•Host and Network Based Intrusion Prevention •Anti-malware•Access Control •Web and Email Filtering/Data Loss Prevention •Presentation Skills•Negotiation Skills•Problem Solving•Interpretation and implementation of ISO27000 & PCI-DSS Controls•IT Risk and Threat Management•IT Vulnerability Management•Security Monitoring and Event Analysis•Policy, standards and baseline specification and governance.•Security Architecture

Richard Fry's Current Company Details
NewDay

Newday

View
Senior Manager Governance Risk and Compliance
Huddersfield, GB
Website:
newday.co.uk
Employees:
1205
Richard Fry Work Experience Details
  • Newday
    Senior Manager Governance Risk And Compliance
    Newday
    Huddersfield, Gb
  • Newday
    Principal Cyber Security Risk And Standards
    Newday Sep 2022 - Present
    London, London, Gb
    Focusing on InfoSec Risk, Policy, Standards, PCI Compliance and awareness. Leading the migration from PCI 3 to PCI 4, through a strategy of scope reduction and working closely with the QSA. Leading the migration of ISO 27001:2013 to ISO27001:2022Creating a controls and evidence based continuous compliance regime that allows evidence to be reused across multiple audit frameworks.
  • Noetic Cyber
    Product Advisor
    Noetic Cyber Jul 2021 - Jul 2024
    Boston, Massachusetts, Us
    Advising on the design and use cases of a ground breaking attack surface management product. Which has now been acquired by Rapid7 to enhance their portfolio of offerings.
  • Covéa Insurance
    Head Of Information Security And Risk
    Covéa Insurance Sep 2018 - Sep 2022
    Halifax, Gb
    Standing up a new multi skilled function within Covea. Accountable for defining and implementing Information Security and Risk best practices to support both regulatory compliance and contractual obligations.Leading 2 teams, Cyber Security Operations and Security Risk and Assurance. Cyber Security Operations is the operational side of the team and respond to security events and monitor the security controls for compliance. Risk and Assurance focus on the risk identification and control objective definition within project delivery and across the existing estate including Supplier security assurance reviews.Key achievements.• Defining and implementing a new Target Operating Model• Recruiting a complete team• Put in place a complete Information and IT Risk Management framework for both business as usual and project support.• Successfully achieving board approval of the IT Risk Appetite statements, Threats and Information types and classifications.• Put in place an IT Policy Governance framework to support the ISO27000 certification process.• Defining and implementing new ways of working across security, architecture and service teams• Successful implementation of a managed Security Operations centre to provide 24x7 monitoring and alerting.• Working with Service and Software Delivery/Engineering to successfully define new cloud secure operating support and development models in both an Agile and Waterfall methodology. • Providing an ISO27001 gap analysis and Security Maturity assessment that allowed me to develop a full IT Strategy.• Providing the board with a full Cyber Attack threat and Impact Assessment.
  • The Co-Operative Bank Plc
    Lead Enterprise Security Architect
    The Co-Operative Bank Plc Jan 2018 - Sep 2018
    This is a new function within the technology office of the bank and am accountable for defining and integrating the Security Architecture capability into the wider architecture function within the bank.My role also included:• Definition and delivery of the Cyber Security Strategy including Cloud Adoption.• Definition and delivery of a Security Architectural Governance process.• Definition and management of the Enterprise Security Principles.• Liaison with the other Security Functions within the bank. • Definition of the security controls and key performance and risk indicators, o People – capabilities and the level of expertise required within the organisation.o Process – What processes and outcomes are required to effectively manage information security.o Technology – What enterprise technology will be used to effectively manage risks in line with the Enterprise and Security Principles.• Defining and maintaining the Enterprise Security Architecture.• Development of logical security patterns. • Development and maintenance of security question sets for use in RFQ, RFI.• Maintaining an understanding of the Security Threat landscape.• Maintaining an understanding of the Enterprise Security Posture.• Definition and maintenance of the Enterprise Security Landscape (Catalogue) and the Approved List of Enterprise Security Control Technologies.
  • Dxc Technology
    Chief Security Architect
    Dxc Technology Sep 2017 - Jan 2018
    Ashburn, Virginia, Us
    Accountable for delivering world class information security solutions to Rolls Royce as part of the “EcoSystem Supplier Framework”, working with Rolls Royce senior stake holders (CTO, CISO and Head of Operations.) to advise and influence on emerging threats, counter measures and help define the global Rolls Royce Security Strategy.
  • Provident Financial Group - Provident, Satsuma & Glo
    Technical Domain Architect In Information And Cyber Security
    Provident Financial Group - Provident, Satsuma & Glo Aug 2016 - Aug 2017
    Bradford, Gb
    Accountable for the all elements of the Enterprise Security Architecture, working closely with the other architects and key stakeholders to drive the delivery of a cohesive security capability. Deputising for both the CISO and the CTO at numerous business and stakeholder meetings.My role also includes:• Definition and delivery of the Cyber Security Strategy including Cloud Adoption.• Definition and management of the Enterprise Security Principles.• Liaison with the Chief Information Security Officer’s organisation. • Defining the security information that must be captured as part of any documentation produced by the Solution Architects.• Definition of the security controls and key performance and risk indicators, o People – capabilities and the level of expertise required within the organisation.o Process – What processes and outcomes are required to effectively manage information security.o Technology – What enterprise technology will be used to effectively manage risks in line with the Enterprise and Security Principles.• Defining and maintaining the Enterprise Security Architecture.• Development of logical security patterns. • Development and maintenance of security question sets for use in RFQ, RFI.• Maintaining an understanding of the Security Threat landscape.• Maintaining an understanding of the Enterprise Security Posture.• Definition and maintenance of the Enterprise Security Landscape (Catalogue) and the Approved List of Enterprise Security Control Technologies.
  • The Guinness Partnership
    Information Security Architect
    The Guinness Partnership Oct 2015 - Aug 2016
    Gb
    Responsible for all elements of Information Security across the group, including risk assessments, control identification and strategy development. Accountable for maintaining PCI-DSS accreditation and ISO27001 certification.
  • Swinton Insurance
    Information Security Manager/Architect
    Swinton Insurance Sep 2011 - Sep 2015
    Salford, Gb
    Having successfully implemented a Vulnerability Management Program, Security Event Management processes and Operational Security disciplines, implemented IDS/IPS and built a strong IT Security Governance Framework. Had the opportunity to develop a risk based security architecture that allowed a high level of control and re-use of components at all levels.
  • Child Maintenance And Enforcement Commission
    It Security Manager/Architect
    Child Maintenance And Enforcement Commission Sep 2009 - Sep 2011
    Gb
    Whilst at the Commission I was responsible for developing security processes for the new computer system and took on the role of Security Architect working on the design of a Confidential network within a Restricted Datacentre.
  • Hbos Plc
    Operational Security Assessment And Governance Manager
    Hbos Plc Sep 1999 - Sep 2009
    Responsible for Threat, vulnerability and product exploitation
  • Holdene
    Computer Manager
    Holdene 1994 - 1999
  • Servo
    It Specialist
    Servo 1994 - 1999
    Birstall, West Yorkshire, Gb
  • Visionware
    Deputy Support Manager
    Visionware 1994 - 1994
    London, Gb
  • Dupont
    Developer
    Dupont 1989 - 1994
    Wilmington, De, Us

Richard Fry Skills

Information Security Management Security Information Security Computer Security Governance Pci Dss Vulnerability Management Information Technology Network Security Risk Management Management Security Architecture Design Iso 27001 Firewalls Security Policy Cism Mcafee Ips Data Security Antivirus Security Audits Payment Card Industry Data Security Standard Risk Assessment Vulnerability Assessment Information Assurance Security Awareness Application Security Incident Management Penetration Testing Access Control Cryptography Certified Information Security Manager Malware Analysis Policy Financial Risk Risk Mitigation It Governance Compliance Risk It Risk

Richard Fry Education Details

  • The University Of Huddersfield
    The University Of Huddersfield
    Systems Engineering
  • Thomas Peacocke Seconday School, Rye
    Thomas Peacocke Seconday School, Rye

Frequently Asked Questions about Richard Fry

What company does Richard Fry work for?

Richard Fry works for Newday

What is Richard Fry's role at the current company?

Richard Fry's current role is Senior Manager Governance Risk and Compliance.

What is Richard Fry's email address?

Richard Fry's email address is ri****@****rld.com

What schools did Richard Fry attend?

Richard Fry attended The University Of Huddersfield, Thomas Peacocke Seconday School, Rye.

What skills is Richard Fry known for?

Richard Fry has skills like Information Security Management, Security, Information Security, Computer Security, Governance, Pci Dss, Vulnerability Management, Information Technology, Network Security, Risk Management, Management, Security Architecture Design.

Who are Richard Fry's colleagues?

Richard Fry's colleagues are Temi Awodiya, Clement Hiza, Harry Cope, Mario Ochandio, Janet Pickford, Jamila T., Poldark Clarke.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.