Stephanie Rae Gass Email and Phone Number
Stephanie Rae Gass work email
- Valid
- Valid
Stephanie Rae Gass personal email
- Valid
Stephanie Rae Gass phone numbers
Information Security Governance: Policy, Privacy, Compliance & Risk Management • Cleared • MEng • CISA, CDPSE, CFE, GSNA, GSTRT, GLEG
Center For Internet Security
View- Website:
- cisecurity.org
- Employees:
- 262
-
Senior Director Of Information SecurityCenter For Internet Security Nov 2024 - Present -
Director, Information Security Governance, Risk And ComplianceCenter For Internet Security Mar 2022 - Nov 2024Responsibilities•Work closely with all levels within the organization to provide internal support and consultative advice pertaining to information security, privacy and artificial intelligence •Oversee the process with external auditors on behalf of the Information Security Office•Perform Risk Assessments and Regulatory Assessments •Evaluate Organizational Risks based on audit findings•Evaluate Organizational Compliance with applicable laws and regulations (GDPR, NIST 800-171, NIST CSF, NIST RMF)•Building of a sustainable audit program•Developing a privacy program, including integration of a privacy platform •In coordination with legal, incorporated a Cybersecurity Plan and Data Protection Plan into the CIS contractsEngagements•Speaker, MS/EI-ISAC Annual Meeting - Managing Cyber Threats through Effective Governance (2022 and 2023)•Speaker, MS/EI-ISAC Annual Meeting - Security and Compliance: Understanding the Difference; Hoping for the Best, Preparing for the Worst: Why Incident Response and GRC Go Hand-in-Hand (2024)Project•ISO 27001/27701 - Lead•FISMA Moderate- Lead•Continuing to oversee the SOC 2 and SOC for Cybersecurity programsBoard•AI Governance Board, Co-Chair 2024- -
Information Security Auditor, SrCenter For Internet Security Feb 2019 - Mar 2022Responsibilities•Work closely with all levels within the organization to provide internal support and consultative advice pertaining to information security•Work closely with external auditors on behalf of the Information Security Office•Perform Risk Assessments and Regulatory Assessments •Evaluate Organizational Risks based on audit findings•Evaluate Organizational Compliance with applicable laws and regulations (GDPR, NIST 800-171, NIST CSF, NIST RMF)Paper•Managing Cyber Threats through Effective Governance: A Call to Action for Governors and Legislatures - Contributing Author and Whitepaper LeadProject•SOC 2 Type 1 Organizational Alignment - Lead•SOC 2 Type 2 - Lead•SOC for Cybersecurity - Lead -
Information Security Compliance, Government And Itar LeadGlobalfoundries Aug 2017 - Feb 2019Responsibilities•Work closely with all levels within the organization to provide internal support and consultative advice pertaining to information security•Work closely with external and internal auditors on behalf of the IT organization - DHS, DoD, Certification Bodies, among others•Risk Management Lead, implemented and established the Risk Management Framework - Oversee the Global Risk Review Committee for IT Organizational Risks•Review Data Control Plans in collaboration with the Cyber Defense Team to ensure the Data Flow is secured based on the Data Types•Ensure information security compliance - DFAR/CDI/CUI, Export Controls (ITAR/EAR), NIST Risk Management Framework, ISO 27001, ISO 9001, Common Criteria, CFATS•Key Stakeholder in the Global Data Classification Project•Cleared employeeISO27001 Lead Auditor -
Internal AuditorSefcu Oct 2011 - Aug 2017Albany, Ny•Ensure the credit union is in compliance with all internal, Federal and State regulations.Responsibilities•Conduct financial, operational and compliance audits as outlined in the Annual Internal Audit Plan•Review operations and programs to determine if results are consistent with established objectives and goals, and if the operations or programs are being carried out as intended•Create audit reports outlining strengths and weaknesses in the control environment and compliance to all policies and procedures on Federal, State, and Credit Union level•Perform audits/reviews regarding operations, but not limited to audit program development, data collection and analysis, procedural analysis, internal control assessment, and preparation of finding summary and recommendation for corrective action •Conduct investigations or special audits as requested, including fraud investigations •Work closely with credit union management and staff to provide internal support and consultative advice•Participate in the monthly Fraud Committee Meetings -
Quality Control Specialist Consumer/Indirect LendingSefcu May 2010 - Oct 2011•Ensure that all lenders in the credit union are in compliance with all internal and Federal regulations pertaining to consumer lending.Responsibilities•Completed Branch Level & Individual Quality Control Audits on current lending processes and procedures•Presented weekly reports on select findings, utilizing Excel, Word and system generated reports•Design recommendations for areas of improvement with lenders•Assisted in the development of Lending Refreshers •Performed special audits on individual loans or lenders at the request of Management of Consumer and Indirect Lending or the Director of Retail Lending•Structured and outlined the procedures for the Consumer and Indirect Lending Quality Control Process•Participate in the monthly Fraud Committee Meetings -
Lead Service ProfessionalSefcu Apr 2008 - Apr 2010•Maintained the highest standards for management practices and business ethics while adhering to all State, Federal, and local regulations.•Developed action plans to increase branch growth opportunities and staff developmentResponsibilities•Responsible for all operations of the branch in the absence of the manager•Maintained compliance with all Federal / State / Local regulations and guidelines•Lead in audits of all negotiable inventory and branch procedures•Lending Authority, utilizing open-ended lending practices•Reviewed and detected counterfeit items attempted to be negotiated by members •Proposed and implemented branch specific policies and procedures to increase operational efficiency -
Research AnalystNfc Global (The National Fraud Center) Jan 2004 - May 2004•Performed due diligence investigations for financial, private, and government institutions•Conducted legal research for on-going cases•United States Court Project: Created a database for investigators to utilize when conducting investigations between different states and jurisdictions. The database also lays out each states’ court system
Stephanie Rae Gass Skills
Stephanie Rae Gass Education Details
-
Magna Cum Laude
Frequently Asked Questions about Stephanie Rae Gass
What company does Stephanie Rae Gass work for?
Stephanie Rae Gass works for Center For Internet Security
What is Stephanie Rae Gass's role at the current company?
Stephanie Rae Gass's current role is Senior Director of Information Security.
What is Stephanie Rae Gass's email address?
Stephanie Rae Gass's email address is st****@****ail.com
What is Stephanie Rae Gass's direct phone number?
Stephanie Rae Gass's direct phone number is +151849*****
What schools did Stephanie Rae Gass attend?
Stephanie Rae Gass attended The George Washington University - School Of Engineering & Applied Science, Utica College.
What skills is Stephanie Rae Gass known for?
Stephanie Rae Gass has skills like Auditing, Internal Audit, Credit, Fraud, Security, Internal Controls, Risk Assessment, Leadership, Internal Investigations, Due Diligence, Research, Aml.
Who are Stephanie Rae Gass's colleagues?
Stephanie Rae Gass's colleagues are Brendan Montagne, Leslie I., Adnan Madda, Wirut Jampakeed, Megan Incerto, Sam Merrell, Kelsey Vierow.
Free Chrome Extension
Find emails, phones & company data instantly
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial