Ciso At National General
Current•Advised senior executives and the Board of Directors on security program strategy, risk management, and regulatory compliance (Sarbanes-Oxley, HIPAA, PCI, GDPR), driving informed decision-making in a highly regulated industry.•Enhanced threat detection and incident response capabilities, reducing mean time to detect (MTTD) and mean time to respond (MTTR) to malicious events; aligned response processes with Privacy and Legal teams for comprehensive breach handling.•Cultivated a robust security culture by implementing collaborative training programs, including phishing simulations, streamlined phishing reporting, and secure coding workshops for developers, resulting in heightened organizational awareness and resilience.•Streamlined application security by integrating advanced testing and remediation protocols into the Software Development Lifecycle (SDLC), significantly improving application quality and reducing vulnerabilities.•Achieved a 93% reduction in system vulnerabilities enterprise-wide, mitigating cyber risks while ensuring 100% system availability and operational continuity.•Cybersecurity lead for M&A activities, including cybersecurity evaluation of prospective acquisitions and integration planning