Principle Information Security Analyst
CurrentPROJECT LEAD• Designed and implemented Sealy’s Information Security Governance standards and policies in line with the NIST CSF, NIST 800-53-r5, and the Essential Eight.• Developed and implemented Sealy’s Cybersecurity Risk Management Framework• Developed and implemented Sealy’s Cyber Incident Response Plan and corresponding playbooks.• Designed and implemented Sealy’s Information Security Training Program.• Led Risk Assessments to Identify Business/Information Technology risks. Led remediation efforts on identified risks in tandem with risk owners.• Essential Eight Maturity Uplift. • Led Internal Incident Response efforts.• Monthly Information Security reporting to the executive team and senior management.OTHER PROJECTS AND ONGOING TASKS• Evaluated and made recommendations on Cybersecurity architecture, including new security solutions, and providing implementation guidance to minimise interruption to services.• Architectural review and redesign of Sealy’s information flow, email, and email filter solutions, to facilitate a single solution for all international locations.• Collaborated on the Implementation of Sealy’s CyberArk PAM solution.• Worked with vendors to provide services such as Penetration Testing and MDR.