I'm a versatile security compliance manager with 10+ years of hands-on experience in hardening and maintaining corporate security processes. My key strengths include:- Supporting an integrated security and risk management system, with a strong focus on cloud-specific controls and PII protection in the cloud- Engaging with other teams to fit processes to the corporate culture by selecting suitable controls and decomposing them into clear tasks for each unit- Achieving ISO/IEC 27001 certification, extending the scope of controls to meet ISO/IEC 27017, 27018, and becoming the first CIS-located office to confirm CSA STAR Level 2 and achieve the ISO/IEC 27701 certificate- Facilitating security audits (first-, second-, and third-party), Risk Management, Vendor Management, Information Security Systems Management, and Security Awareness- Gaining hands-on experience in custom implementation of generic controls and selecting proper compensating mechanisms depending on the acceptable risk level, from work experience as an external auditor to internal implementorMy passion is to break the rumor of security personnel creating endless restrictions. Instead, I believe that all restrictions must have a clear goal, which is explained to all affected and involved colleagues. This approach ensures that we are all responsible for what we do as a team.