Miami, Florida, United States
- Managed the organizations Information Security Risk Register - Managed Application Security Risk Assessments and remediation of identified findings - Implemented end to end process improvements and automations to reduce team workload and produce repeatable quantifiable scoring for Risk Assessments - Automated reporting of Identified Risks to upper management
- Managed and trained a team of 4 to handle Information Security contract reviews and customer security assessments - Generated $3 Billion in tracked revenue for successful contract reviews and customer security engagements - Worked with Compliance to ensure that VMware meets DFARS requirements - Assisted with the development of VMware’s external facing Trust Portal - Provided general guidance to Legal on new privacy regulations and their impact to the organization while working with various BUs to ensure that these requirements are met
- Built the VMware Information Security Governance Reviews program to assist sales and legal on reviewing the technical and organizational security measures of VMware's contractual engagements (ELAs, DPAs, MSAs, SOWs) and facilitation of customer security assessments - Conducted $2+ Billion in tracked revenue for successful contract reviews and customer security engagements - Worked with VMware Legal providing guidance on GDPR and Information Security to develop the DPA playbook for customer engagements - Led calls with customer Legal and Information Security teams for the VMware Information Security Governance Team - Collaboration with the Compliance team on process implementation for the distribution of Cloud Service Compliance reports to customers - Built an internal portal for Sales and Legal to access customer facing assurance materials, request compliance reports and support from Information Security on customer engagements. - Hosted Information Security Events in Japan, China, India, Singapore, England, Palo Alto, Atlanta and Austin - Developed Security and Legal expertise as a general objective and also in order to meet quickly-evolving requirements of the role
- Utilized the NIST Cybersecurty Framework to uplift all Information Security Standards - Worked on the creation of the Information Security Training and Awareness Program - Developed materials and assisted in the planning of Security Awareness days in Ireland, Bulgaria, and Palo Alto - Created materials focused on proper Information Security practices that were deployed globally - Assisted compliance team with preparing reports for SOX Auditors