Stephen Thompson

Stephen Thompson Email and Phone Number

Building and improving business intelligence solutions for governance and management of enterprise risk, operational risk, IT risk, and information security. @ CoreLogic
Stephen Thompson's Location
Dallas-Fort Worth Metroplex, United States, United States
Stephen Thompson's Contact Details

Stephen Thompson work email

Stephen Thompson personal email

Stephen Thompson phone numbers

About Stephen Thompson

Senior program manager focused on assessing, developing, growing, and improving business intelligence (BI) systems for enterprise risk management (ERM), operational risk management (ORM), and compliance management capabilities and maturity. Qualified subject matter expert (SME) for audit of Information Technology (IT) control, Information Security (IS) control architecture and management, data migration, and data quality assurance. United States Navy Veteran. 13+ years of experience in assessing and fulfilling federal, state, and Payment Card Industry (PCI) IT compliance requirements for financial institutions, law firms, and government entities. 15+ years of experience in project management. 10+ years developing, managing, and testing solutions and applications of RSA Archer eGRC.

Stephen Thompson's Current Company Details
CoreLogic

Corelogic

View
Building and improving business intelligence solutions for governance and management of enterprise risk, operational risk, IT risk, and information security.
Stephen Thompson Work Experience Details
  • Corelogic
    Principal Information Security Manager
    Corelogic Oct 2022 - Present
    Irvine, Ca, Us
    Supervise IT development to ensure control compliance and assess risk. Onboard IT solutions to information security requirements. Establish reporting relationships with business owners and Exec Committee members and foster accountability for development teams. Build compliance dashboard, risk register, and other reporting mechanisms. Be a trusted advisor and mentor.
  • Acumen Grc Consulting, Llc
    Senior Consultant
    Acumen Grc Consulting, Llc Feb 2020 - Present
    Providing executive-level consulting, architecture, project management, team building, and product ownership / product management for enterprise risk management (ERM) and operational risk management (ORM) programs for medium and large financial institutions.Advocating for the business while delivering comprehensive BI solutions using software products such as Archer & ServiceNow by identifying, refining, and validating delivery of business product requirements.Providing information security oversight (DevSecOps) and data quality assurance for business intelligence (BI) systems. Planning and performing system migration and data transformation. Managing and validating data quality. Identifying information gaps and providing both strategic and tactical direction for prioritization and resolution.Establishing agile project management operating models, planning, and reporting using software products such as Jira and Rally. Providing transparent views of project status and risks.Recent Accomplishments• Helped Silicon Valley Bank (SVB) achieve goal of becoming a large financial institution by managing Galvanize HighBond and ServiceNow GRC software solutions, focusing on information system architecture, collection of foundational data inventories, defining / improving / validating data quality, migration of data from system to system, establishing customer support solutions, and establishing agile project management operating models and reporting systems.• Delivered enterprise compliance management solution improvements critical to Wells Fargo success, overseeing business user acceptance testing, business requirements gathering, dependency management, and internal testing / validation.• Assured successful initial business launch for Welkins Farms focusing on business operation planning, internal standards, licensing, and product quality control.
  • Apex Systems
    Information Security Assurance Analyst (Contract)
    Apex Systems Aug 2019 - Dec 2019
    Glen Allen, Va, Us
    Provided Allstate Insurance Company with control effectiveness testing for seven business-critical applications and their supporting databases, platforms, and security processes in support of new and emerging state laws impacting information technology and non-public personal data. Developed test plans, reviewed evidence, and produced assessment documentation.• Provided the support needed to complete end-of-year goals for state cybersecurity compliance review.• Provided support owners and business partners with coaching and insight on strengths and weaknesses, and prepared recommendations for continued process improvements and success.
  • Calance
    Business Systems Analyst Egrc (Contract)
    Calance Nov 2018 - Apr 2019
    Anaheim, California, Us
    Managed four projects at Toyota Financial Services to develop and deliver Archer eGRC software applications for internal business partners. Spear-headed the teams’ first adoption of Agile practices to develop software as a factory. Established and implemented team standards for documenting business requirements and application design. Documented to-be business processes. Provided operational troubleshooting and integration testing. • Established Atlassian Jira as a collaboration tool which improved resource estimation, project planning, and progress tracking. • Delivered applications which reduced the cost of Sarbanes-Oxley internal controls testing, improved processes for issue management and regulatory change management, and provided new capabilities for hosting an authoritative sources library.
  • National Bankruptcy Services, Llc
    Information Security Manager
    National Bankruptcy Services, Llc Nov 2017 - May 2018
    Dallas, Tx, Us
    Led a project for initial adoption of PCI DSS and consulted on compliance management practices. Established an inventory of IT components. Defined the scope of PCI compliance for IT systems and processes Defined organization-specific controls for satisfying PCI DSS requirements. Performed an assessment of IT systems to identify deficient or missing controls. Participated in development and review of information security policy and standards.• Responded to six client audits of IT controls and improved the company’s ability to accurately respond to clients’ compliance assessments.• Assessed and evaluated two new info sec solutions prior to acquisition resulting in improved network intrusion detection and source code analysis capabilities.• Saved the company $4.1M+ that was invested in more profitable projects.
  • Gm Financial
    It Grc Analyst
    Gm Financial Jan 2016 - Jul 2017
    Fort Worth, Texas, Us
    Assisted the company’s transition to Sarbanes-Oxley compliance for controls testing after acquisition by General Motors. Developed solutions and applications in RSA Archer eGRC for reporting on SOX-related IT controls. Documented business processes, project requirements, application design, and test plans for new security program.• Prepared and cross-referenced content for use in applications for Authoritative Sources, Policies, Control Standards, and Control Procedures.• Assessed control design and performance for vulnerability management, user access management, and network security.• Resulted in the company gaining new capabilities for governance and reporting on the state of controls for IT systems used for financial reporting.
  • Teksystems
    Information Security Grc Consultant (Contract)
    Teksystems Jun 2015 - Dec 2015
    Hanover, Md, Us
    Defined and evaluated comprehensive IT controls for Options Clearing Corporation security program to meet regulatory requirements imposed by U.S. Securities and Exchange Commission, Regulation SCI, for market utilities. Provided consulting, mentoring and technical advice to IT system owners.• Identified and corrected gaps between external regulatory requirements, NIST SP 800-53 security controls and NIST SP 800-64 software development lifecycle standards, internal policies, and IT controls.• Authored policies, documented procedures, and developed audit and reporting solutions in Microsoft Access, Excel, SharePoint, and RSA Archer eGRC software for the Director of IT, Director of Risk and Compliance.• Resulted in the client earning distinction by the Securities Exchange Commission as a leader in compliance achievement among its peers.
  • U.S. Bank
    Senior Information Security Risk And Compliance Specialist
    U.S. Bank Apr 2014 - Apr 2015
    Minneapolis, Mn, Us
    Managed the review and improvement of all information security policies and standards with business partners and technical subject matter experts. Supported the vulnerability remediation tracking program by validating evidence of remediation for host vulnerabilities.• Established RSA Archer eGRC as the source record for producing policy and standards documentation; • Updated policy and standards to reflect the new PCI DSS 3.0 requirements and expanded policy to address topics of social media use, system development, and information systems acquisition.• Improved the organization and quality of standards to provide better guidance, require less interpretation, and be more accessible for IT engineers and business managers to use and understand.
  • U.S. Bank
    Information Security Architect
    U.S. Bank Jan 2009 - Apr 2014
    Minneapolis, Mn, Us
    Supervised the BISO team’s risk assessment / compliance assessment engagements for 602 technology innovation projects. Directly supervised inclusion of security controls for 103 projects for the Payment Services line of business. Enforced PCI, SOX, FISMA, FFIEC, and HIPAA compliance requirements while strengthening ties as a trusted business partner and consultant. Provided information security consulting and mentoring to technology owners.• Authored over 350 risk assessments, root cause analyses, or remediation plans for information security incidents, findings, or compliance exceptions, which contributed to company’s recognition as the most innovative bank in North America.• Doubled team’s capacity for reviewing IT innovations and changes by implementing a triage process and new risk analysis scoring tools as part of the continuous improvement of service delivery.
  • Us Navy
    Aviation Electronics Calibration And Repair Technician
    Us Navy Jan 2003 - Jan 2011
    Washington, Dc, Us
    Supervised an inventory of over 100,000 calibrated measuring instruments aboard the aircraft carrier, USS Carl Vinson CVN-70, with a direct impact on all flight and nuclear power operations. • Supervised technical assistants in 53 work centers resulting in being awarded “Best in Fleet” for maintaining superior readiness of assets while forward deployed.• Provided career development mentoring and supervised the safety training program for a division of more than 70 personnel.
  • Blue Line Security
    Information Security Consultant (Freelance)
    Blue Line Security Sep 2001 - Oct 2002
    Provided IT risk assessment and managed security services to various business clients.
  • Fishnet Security
    Network Security Engineer / Assessor
    Fishnet Security Jul 1999 - Aug 2001
    Overland Park, Ks, Us
    Deployed, configured, and assessed firewalls and intrusion detection systems (IDS) and as a network security engineer. Responded and investigated information security incidents. Performed dozens of security control assessments for Fortune 500 companies and government entities. Developed my company’s penetration testing & security assessment team from concept to world-class competitor within two years.

Stephen Thompson Skills

Information Security Risk Assessment Pci Dss Project Management Management People Skills Communication It Risk Management It Compliance Management It Governance Penetration Testing Computer Forensics Technical Writing Software Documentation Data Analysis Firewalls Business Process Vulnerability Assessment Business Architecture Network Security Business Continuity Teacher Research Process Engineering Executive Coaching Continuous Improvement Coach Problem Solving Pattern Recognition Staff Development It Auditors Microsoft Sql Server Rsa Archer Egrc Sharepoint Designer Microsoft Office Network Engineering Statistical Data Analysis Threat Modeling Threat And Vulnerability Management

Stephen Thompson Education Details

  • University Of Missouri-Kansas City
    University Of Missouri-Kansas City
    Psychology With Minor Emphasis In Biology
  • Questrom School Of Business, Boston University
    Questrom School Of Business, Boston University
    Project Management
  • Sans Technology Institute
    Sans Technology Institute
    Information Security Management

Frequently Asked Questions about Stephen Thompson

What company does Stephen Thompson work for?

Stephen Thompson works for Corelogic

What is Stephen Thompson's role at the current company?

Stephen Thompson's current role is Building and improving business intelligence solutions for governance and management of enterprise risk, operational risk, IT risk, and information security..

What is Stephen Thompson's email address?

Stephen Thompson's email address is an****@****hoo.com

What is Stephen Thompson's direct phone number?

Stephen Thompson's direct phone number is (804)-254*****

What schools did Stephen Thompson attend?

Stephen Thompson attended University Of Missouri-Kansas City, Questrom School Of Business, Boston University, Sans Technology Institute.

What are some of Stephen Thompson's interests?

Stephen Thompson has interest in Children, Arts And Culture.

What skills is Stephen Thompson known for?

Stephen Thompson has skills like Information Security, Risk Assessment, Pci Dss, Project Management, Management, People Skills, Communication, It Risk Management, It Compliance Management, It Governance, Penetration Testing, Computer Forensics.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.