Joseph E.

AI Security Engineering & Technical Program Leader | AI-900, CISA, CISM, CISSP, CDPSE, CCSP, C|CISO, CRISC, PMP, ITILv3 | ISACA Calgary President | Driving Secure Compliance & Innovation at Enterprise Scale

Calgary, Alberta, Canada

About

I am an AI/Cybersecurity Leader at Microsoft with 15+ years of experience leading complex cybersecurity programs that enhance resilience, reduce risk, and enable secure cloud adoption at scale. I specialize in cloud security architecture, risk and compliance (NIST, ISO 27001, SOC 2), vulnerability management, and business continuity with proven success across the technology, finance, and energy sectors. I hold certifications including CISA, CISSP, CCSP, CISM, CRISC, PMP, ITILv3, CDPSE and renowned C|CISO, which I’ve applied to deliver strategic initiatives such as Identity and Access Management, Security Control Baselines, Zero Trust implementations, threat detection modernization and global regulatory compliance alignment. Outside of Microsoft, I serve as President of ISACA Calgary Chapter, where I champion professional development and cybersecurity community growth. I’m driven by a mission to help organizations securely unlock innovation through effective, business-aligned security strategies.

Experience

  • President at ISACA Calgary Chapter
    Sep 2024 - Present · 1 yr 10 mos

    President of ISACA Calgary

  • Microsoft (13 yrs 1 mo)
    • Senior Security Engineering Program Manager
      Oct 2020 - Present · 5 yrs 9 mos

      Led global-scale cybersecurity programs across identity governance, vulnerability management, threat protection, and data security—impacting millions of users in enterprise cloud environments. Designed and implemented Zero Trust architecture across 5 global regions, resulting in a 40% reduction in security incidents and faster compliance with ISO 27001 and FedRAMP. Deployed Microsoft Sentinel and Azure Security Center for real-time threat detection, enabling proactive monitoring and response for Fortune 100 clients. Drove governance and AI readiness strategies, incorporating generative AI risk assessments and automated compliance controls into customer environments. Collaborated with engineering, legal, and compliance teams to align security outcomes with customer expectations and evolving regulatory mandates

    • Senior Security Program Manager
      Dec 2016 - Oct 2020 · 3 yrs 11 mos

      Managed end-to-end delivery of Microsoft’s enterprise cybersecurity capabilities, including Identity & Access Management (IAM), vulnerability assessments, threat protection, and security posture management. Delivered security transformation roadmaps aligning controls with NIST CSF, CIS Controls, and local regulations.

    • Senior Security Technical Account Manager
      Jun 2013 - Dec 2016 · 3 yrs 7 mos

      Provided technical and strategic cybersecurity support for enterprise clients across MEA, with a focus on cyber defense, cloud migration, and GRC alignment. Consistently recognized for exceptional customer satisfaction, earning multiple Microsoft accolades including the “MEA CPE Heroes Award” and “Most Valuable Personality.” Acted as trusted advisor to CIOs and CISOs, helping align security programs with business continuity and digital innovation goals.

  • Senior Information Security Consultant at IBM
    Feb 2012 - Jun 2013 · 1 yr 5 mos

    Delivered risk assessment and remediation for telecom giants, Airtel across the MEA region, improving client compliance with ISO 27001 and internal security standards. Designed incident response strategies and conducted control gap analyses across multi-cloud environments.

  • Information Security Specialist at Intercontinental Bank PLC
    Aug 2008 - Feb 2012 · 3 yrs 7 mos

    Led internal security assessments and IT risk audits across core banking systems, ensuring regulatory alignment with the Central Bank of Nigeria’s cybersecurity guidelines. Reduced audit findings by 60% through proactive control design and improved awareness programs.

  • Information Security Analyst at Aeroland Travels
    Dec 2006 - May 2008 · 1 yr 6 mos

    Implemented access controls, data protection policies, and incident response protocols for Aero land Travel environment.