Chief Information Security Officer
Current• Responsible for enterprise-wide Information Risk Management (IRM) program. • Accountable for all enterprise data protection, including information security policy and strategy, incident response, cyber threat intelligence, supplier risk management, client audit and go-to-market support, vulnerability management, regulatory compliance and controls assurance.• Implemented on time (2016-2019) and budget Information security master program, containing 110 security controls. Master plan was response to changing risk environment where threats like APT were considered. • Led PCI DSS program and achieved successful re-certification (from 2015 to 2020) enabling organization to have new business opportunities. • Adapted information risk management practices into company-wide STAMP project management methodology; • Influenced strong, company-wide security culture through awareness • Chaired Information Security Steering Committee