Project Manager Resume
2.00/5 (Submit Your Rating)
PROFESSIONAL EXPERIENCE
Project Manager
Confidential
Responsibilities:
- Expert development of 23 country GRC information security program
- Expert development of 23 country GRC privacy program
- Resolved privacy and organizational cyber risk incidents internationally for incident response / breach response
- Approved crisis management escalation handling
- Cyber wargaming tabletop exercise planning and DR Runbooks / playbook creation and strategy
- Resolved application security control issues and cloud OWASP resolution, especially within incident response handling
- Expert in GDPR, CCPA privacy and data protection program
- Designed privacy and information security by design control sets including within cloud environments
- Leveraged Microsoft expertise to design jurisdictionally relevant governance rules including the use of Azure rights management and O365 Safety & Compliance Center controls to effect international data protection governance across 23 countries.
- Drafted consents, privacy notices, data transfer agreements and other documents for lawful transmission of data.
- Built Legitimate Interest Tests, PIAs, DPIAs (including multi country implementing law compliance)
- Privacy and data protection expert across EU and Americas in particular
- Built WISP (written Information Security Program) and data protection plans globally
- Expert in information security GRC and Privacy GRC (ZenGRC, Archer, Metric Stream, UCF)
- Expertise within insider threat and detection/deterrents
- Advised on penetration testing standards and bug bounty program efforts
- Created regular flow - down assessments within privacy and information security domains to hold processors and sub-processors in compliance against negotiated terms, and served as data privacy expert to ensure flow-downs are current against global regulatory requirements.
- Filtered the present state of data protection capabilities with the development of data protection protocols to baseline capabilities and rationalize the same against operating jurisdictions to enhance the speed of the contracting process and reduce compliance risk.
- Advised on BCR (Binding Corporate Rules), SCC (Std Contractual Clauses), security monitoring tools, security tools legal requirements, privacy regulations and cyber regulatory regulations and rationalizing same against works council requirements, international and domestic laws and operational requirements.
- Recommending technology and technology revisions based on operational, legal and contractual requirements to meet international cyber security and data privacy GRC needs
- Guiding the CISO, GC and DPO to integrate GDPR data protection, privacy and cyber security regulatory operational and risk framework requirements into operations.
- Provided expert advice across all major departments regarding cyber regulatory risk
- Guiding Data Protection and GDPR (General Data Protection Regulation) strategy implementation teams
- Advising on and implemented data protection regulations and information security frameworks as a SME and counsel for subsidiary entities across 23 countries
- Implementing technologies as SME (Data Protection, Consent, Encryption, Privacy Tracking) as well as modifying legal agreements (DTAs, Model Clauses, Contract Addendums, Notices, Policy)
- Contract drafting of data protection protocols, MSA clauses with focus on privacy and security
- Creating technologies internally to effect compliance and data protection regulation globally within the organization
- Experience working with data science tools for manipulating and visualizing data (PowerBI).
Project Manager
Confidential
Responsibilities:
- Educating Board of Directors at all entities under the holding company on information security, data protection, data privacy Embedding Privacy By Design and Data Protection Regulatory into the 1st Line of Defense
- Liason to GC, Chief Privacy Officer, 2nd line Risk, 3rd line Audit to operationalize lawful data protection efforts within the 1st line.
- Advising on GDPR, GLBA, PbD, State Data Protection, Breach, Destruction, Notice, Financial Health, and Industry security and privacy regs to the 1st line in advance of Legal and Privacy
- Guiding CIO/CISOs/ Chief Privacy Officer across 6+ entities on data protection regulatory to ensure IT and CISO operations can meet regulatory requirements relative to the operationalizing the GRC landscape within 1st line tooling
- Designed and operationalized an information security program as CISO with both a 50 state touchpoint (and European Union) for a nationwide securities broker dealer
- Designed an information security governance program embedded into the 1st Line of Defense for 6 entities across the United States of America
