Security Program Assessment, security roadmap, and risk assessment
Conducting quarterly C-level presentations to executives and board members on current and future cybersecurity initiatives and the organization’s information security posture
Evaluation, recommendation, implementation, and management of security products, technologies, and security awareness training
Developing tailored information security policies, plans, and procedures including Business Continuity/Disaster Recovery and Incident Response policies, plans, and playbooks.
Creating and reviewing Business and Privacy Impact Analyses (BIA/PIA)
Security questionnaire response lead and control implementation related to vendor and third party onboarding requirements.
Security architecture organizational and system-specific threat modeling and risk assessment
Penetration Testing (Internal/External Network, Web & Mobile Applications, IoT)
Software Development Life Cycle (SDLC) consulting
Governance, Risk Management & Compliance (GRC) program