Stäfa, Zurich, Switzerland
Accomplished senior technology leader with extensive experience shaping Cyber Risk Management, IT Governance, and SDLC/DevSecOps strategy within global financial institutions. Proven success in leading complex, large-scale transformations, significantly enhancing security frameworks (e.g., AI & Digital Assets), driving major efficiency improvements, and achieving substantial cost savings. Recognised for strategic leadership, deep technical expertise in optimising development environments and managing infrastructure risk, effective stakeholder engagement across business and regulatory bodies (FINMA, SEC, MAS, etc.), and industry contributions as a public speaker.
Responsible for evaluating emerging technologies and their impact on the firm's security framework, identifying gaps and control deficiencies, and defining necessary amendments to mitigate risk. This includes establishing new standards and policies, assessing overlaps and efficiency opportunities, and engaging with stakeholders and regulators to ensure alignment with evolving risk and compliance expectations. - Spearheaded the integration of AI and Digital Assets into the firm's security framework, enabling a major efficiency drive while ensuring regulatory compliance. - Developed and implemented global AI Security Guideline, AI Policy, Digital Asset Technology Guideline. - Engaged with global regulators (SEC, FINMA, MAS, BAFIN) to address technical requests, influencing industry best practices. - Strengthened internal control frameworks to mitigate AI and Digital Asset risks.
Responsible for the Infrastructure portfolio of Credit Suisse (Windows, Linux, Network, Firewalls, Storage, DB, Hosting) to address control violations and oversee mitigation. Prime contact in relation to security, consultant for secure implementation and remediation. Managing the transformation of risk reporting of the portfolio during the merge. CISO Lead of the Source Code Migration stream as part of the merge activities. - Led the successful migration of 1,500 application repositories six months ahead of the legal merger close, ensuring regulatory approval with zero compliance issues. - Senior Cyber Risk Lead – Credit Suisse Infrastructure. - Achieved a 95% reduction in infrastructure risk violations (Windows, Linux, Network, Firewalls, Storage, DB, Hosting) through a collaborative, resource-efficient approach.
Leading an internal consultancy within a major global financial institution, responsible for defining strategic direction and overseeing the acquisition and delivery of complex initiatives across the SDLC and DevSecOps landscape. Acted as lead consultant and managed a team of specialists to evaluate technologies, methodologies, and processes, with a strong focus on data privacy, cross-border data transfers, and regulatory compliance - Global Focus - Built and managed a team of 16 DevSecOps Engineers, supporting development teams to improve project output by over 25% while maintaining cost neutrality. - Established an OSS Policy (2022) and led Log4J vulnerability mitigation efforts. - Migrated 12,000 developers and 20,000+ repositories from SVN to Git (2020-2021), aligning with industry standards, improving efficiency and reducing risk. - Delivered CHF4M+ in annual savings through tooling consolidation.
Leading an internal consultancy within a major global financial institution, responsible for defining strategic direction and overseeing the acquisition and delivery of complex initiatives across the SDLC and DevSecOps landscape. Acted as lead consultant and managed a team of specialists to evaluate technologies, methodologies, and processes, with a strong focus on data privacy, cross-border data transfers, and regulatory compliance. - Swiss focus - Transformed the Environment Management Team into a DevSecOps consultancy (focus Switzerland), enhancing development security and efficiency. - Led the migration to Java 8/9 (2019-2020). - Introduced database virtualisation (Liquibase), reducing test setup time by 30%. - Eliminated >600 redundant tools, cost savings of over CHF2M and reducing staffing requirements. - Deployed a Continuous Build Platform (Jenkins), reducing implementation cycle times by 70% and post-deployment incidents by 90%.
Definition and Set Up of Architecture Governance. Standards, Processes, Staffing. Standardized Review on a global scale, covering inhouse as well as external development. Definition of Software Life Cycle and Quality Metrics and Check Points.