Chief Information Security Officer (Ciso)
San Francisco, California, Us
As a builder, defender, and a leader in a variety of challenging situations at Collective Health, I have had the unique opportunity to build and maintain the Security program at scale, while managing culture variables that eventually contributed to the organizational success from a security context. Among other responsibilities, the following are a few most notable duties in my current roleBuilt and led a team of Security architects to help manage the Product Security SDL program across Agile and DevSecOps disciplines within the product development teams while helping design Security disciplines in CI/CD/CA pipeline and other development workflows. Enabled security-as-code across the product lifecycle to perform automated security scanning, testing, and auditing. Responsible for building security into AWS and GCP distributed cloud compute services to stay in compliance with Enterprise Security Risk (specifically, HIPAA and SOC2 controls) and defined processes and tools within the Kubernetes environment for threat hunting, attack detection, and prevention. Built and operated vulnerability management program that consisted of vulnerability scanning, benchmark assessments, intrusion detection & prevention across the cloud and corporate systems. Responsible for architecting and deploying open source security program and respective tools to evaluate security risk across the open-source framework at Collective Health, while being able to assess the License violations and implementing corrective processes to help remediate both security vulnerabilities and license risk.Published BSIMM program to help build product Security maturity within the company and also support Compliance and regulatory initiatives; SOC2 Type 2 and in preparation for SOC1 and HITRUST. Drafted Breach determination and Incident response process within Security Incident workflow; that included elements such as Attack containment & eradication, gap analysis, attack surface analysis & remediation.