Thomas Locher

Senior technology leader in cyber risk, SDLC governance, and secure tech adoption — driving innovation and compliance across global financial institutions

Stäfa, Zurich, Switzerland

About

Accomplished senior technology leader with extensive experience shaping Cyber Risk Management, IT Governance, and SDLC/DevSecOps strategy within global financial institutions. Proven success in leading complex, large-scale transformations, significantly enhancing security frameworks (e.g., AI & Digital Assets), driving major efficiency improvements, and achieving substantial cost savings. Recognised for strategic leadership, deep technical expertise in optimising development environments and managing infrastructure risk, effective stakeholder engagement across business and regulatory bodies (FINMA, SEC, MAS, etc.), and industry contributions as a public speaker.

Experience

  • AI & Digital Assets Cyber Security Lead - CISO at UBS
    Jun 2024 - Present · 2 yrs 2 mos

    Responsible for evaluating emerging technologies and their impact on the firm's security framework, identifying gaps and control deficiencies, and defining necessary amendments to mitigate risk. This includes establishing new standards and policies, assessing overlaps and efficiency opportunities, and engaging with stakeholders and regulators to ensure alignment with evolving risk and compliance expectations. - Spearheaded the integration of AI and Digital Assets into the firm's security framework, enabling a major efficiency drive while ensuring regulatory compliance. - Developed and implemented global AI Security Guideline, AI Policy, Digital Asset Technology Guideline. - Engaged with global regulators (SEC, FINMA, MAS, BAFIN) to address technical requests, influencing industry best practices. - Strengthened internal control frameworks to mitigate AI and Digital Asset risks.

  • Credit Suisse ()
    • Senior Cyber Risk Lead - CISO
      Sep 2022 - Jun 2024 · 1 yr 10 mos

      Responsible for the Infrastructure portfolio of Credit Suisse (Windows, Linux, Network, Firewalls, Storage, DB, Hosting) to address control violations and oversee mitigation. Prime contact in relation to security, consultant for secure implementation and remediation. Managing the transformation of risk reporting of the portfolio during the merge. CISO Lead of the Source Code Migration stream as part of the merge activities. - Led the successful migration of 1,500 application repositories six months ahead of the legal merger close, ensuring regulatory approval with zero compliance issues. - Senior Cyber Risk Lead – Credit Suisse Infrastructure. - Achieved a 95% reduction in infrastructure risk violations (Windows, Linux, Network, Firewalls, Storage, DB, Hosting) through a collaborative, resource-efficient approach.

    • Head Global Development Efficiency "Ody Consult"
      Jan 2020 - Aug 2022 · 2 yrs 8 mos

      Leading an internal consultancy within a major global financial institution, responsible for defining strategic direction and overseeing the acquisition and delivery of complex initiatives across the SDLC and DevSecOps landscape. Acted as lead consultant and managed a team of specialists to evaluate technologies, methodologies, and processes, with a strong focus on data privacy, cross-border data transfers, and regulatory compliance - Global Focus - Built and managed a team of 16 DevSecOps Engineers, supporting development teams to improve project output by over 25% while maintaining cost neutrality. - Established an OSS Policy (2022) and led Log4J vulnerability mitigation efforts. - Migrated 12,000 developers and 20,000+ repositories from SVN to Git (2020-2021), aligning with industry standards, improving efficiency and reducing risk. - Delivered CHF4M+ in annual savings through tooling consolidation.

    • Head Swiss Development Efficiency "EnvMgmt"
      Jan 2017 - Dec 2020 · 4 yrs

      Leading an internal consultancy within a major global financial institution, responsible for defining strategic direction and overseeing the acquisition and delivery of complex initiatives across the SDLC and DevSecOps landscape. Acted as lead consultant and managed a team of specialists to evaluate technologies, methodologies, and processes, with a strong focus on data privacy, cross-border data transfers, and regulatory compliance. - Swiss focus - Transformed the Environment Management Team into a DevSecOps consultancy (focus Switzerland), enhancing development security and efficiency. - Led the migration to Java 8/9 (2019-2020). - Introduced database virtualisation (Liquibase), reducing test setup time by 30%. - Eliminated >600 redundant tools, cost savings of over CHF2M and reducing staffing requirements. - Deployed a Continuous Build Platform (Jenkins), reducing implementation cycle times by 70% and post-deployment incidents by 90%.

  • Manager Architecture Review Board (IT) at Swiss Re
    May 2002 - Apr 2008 · 6 yrs

    Definition and Set Up of Architecture Governance. Standards, Processes, Staffing. Standardized Review on a global scale, covering inhouse as well as external development. Definition of Software Life Cycle and Quality Metrics and Check Points.

  • Manager Java Support at Credit Suisse
    Aug 1999 - Mar 2002 · 2 yrs 8 mos