← Return to Main Site

Career History

Formatted for Print & PDF (Ctrl+P)

Cliff Barbier

Enterprise Security Architect & Leadership Baton Rouge, LA https://cliffbarbier.com cliff.barbier@gmail.com

Executive Summary

Enterprise security leader with 20+ years of experience designing defensible architectures across cloud governance, automated Policy as Code, and enterprise digital transformations without sacrificing developer speed.

Professional Experience

Principal Enterprise Security Architect 2022 – 2025
NielsenIQ Remote

Led the global Cybersecurity Architect team. Created and managed enterprise-wide cybersecurity programs influencing the design of all infrastructure & product security.

4 Overlapping CIS Control approaches eliminated
50 Cloud service configurations created
20 Hours per week saved

Enhanced cloud security compliance across 20 development teams & all infrastructure teams by 14 points (as measured by CSPM) within one year by establishing 50+ cloud service configuration baselines across Azure, AWS, GCP, and SaaS via the Policy as Code program.

Standardized the enterprise security posture by eliminating four disparate CIS Control implementation approaches, achieved by architecting a Policy as Code program that unified configurations across design, engineering, SSDLC, and infrastructure, including ongoing monitoring.

  • Created and managed a Policy as Code (PaC) program for Azure, AWS, GCP, and SaaS environments, aligned with the CIS Controls and company policy.
    • Created and managed secure configuration baselines for public cloud services, as well as SaaS providers.
    • Created a methodology to produce secure configuration baselines including threat modeling, existing risk control strategies, and risk treatments.
    • Utilized AI to assist with coverage and validation of interdependent settings.
  • Partnered with IT, security, and development teams to embed the above Policy as Code paradigm into NielsenIQ’s existing processes and procedures in various ways.
    • Worked with cloud platform leadership to implement secure configurations as prevention policies using specific cloud provider tools.
    • Created rulesets for a Cloud Security Posture Management (CSPM) tool to scan running cloud services for noncompliance and malicious activity.

Increased GRC assessment efficiency for CIS Controls by 20 person-hours per week by successfully advocating for quantitative measurement and proving the practicality of implementing the CIS Controls Assessment Specification at NielsenIQ.

  • Advised and consulted on security across the enterprise to enable security by design.
    • Led security response in enterprise-wide public cloud governance group.
    • Drove GRC team’s transition from qualitative to quantitative evaluation of CIS Controls compliance.

Optimized operational effectiveness through strategic oversight.

  • Guided security strategy across the enterprise, directing design, engineering, and implementation efforts.
  • Oversaw & performed M&A planning for architecture risk, security, and integration of 11 acquisitions.
    • Finalized the architecture remediation of seven pre-existing acquisitions that were not yet fully integrated.
    • Created framework for future M&A architecture activities, used for a further three acquisitions.
    • Planned and oversaw the architectural integration of same-sized acquisition GfK into NielsenIQ, including planning pre-acquisition, adjusting plans for regulatory approval, and adapting plans as the integration progressed.
  • Presented to CISO, security leadership, security teams, and IT engineers.
  • Led a team of four Security Architects across three locations and two countries, including onboarding, training, coaching, and oversight.
Senior Enterprise Security Architect 2015 – 2022
Equifax Remote

Led the work of the global Security Architecture team, advising teams on security across the enterprise while establishing a team culture of autonomy, fun, collaboration, and respect.

Directed the global Security Architecture practice through a large-scale digital transformation in response to the 2017 Equifax breach. Built the Security Architecture & Advisement practice to such a high standard that Mandiant uniquely identified the team as the sole global security division requiring no corrective actions post-breach.

0 Corrective Findings from Mandiant
4.0 Process CMM Level Measured by Gartner
50+ Percentage Point Lift in Cloud Compliance
100+ Secure Configuration Baselines
21 M&A Due Diligence Security Evaluations
$100,000 Bug Bounty Budget Annual Savings

Implemented “Secure by Design” principles across 25 countries, increasing reviews before go-live by 80% after on-boarding, training, and coaching 20 architects.

Improved the maturity of the Security Architecture & Advisement team to CMM Level 4 as measured by Gartner, by creating repeatable, manageable, and scalable processes.

  • Created a Security Architecture & Advisement practice to perform security assessments & consult on all infrastructure and products to ensure security by design.
    • Reviewed new and changed systems across 25 countries, on-premises, in cloud service providers (GCP or AWS), or SaaS.
    • Created processes, procedures, and deliverables to review infrastructure architecture, application architecture, and associated business processes.
    • Enforced PII handling to comply with the Fair Credit Reporting Act (FCRA).
    • Partnered with BISOs to drive risk-based finding remediation.
    • Developed and automated a security controls scorecard for go-live decisions.
  • Guided product security strategy across the enterprise. Designed programs and architectures to enact that strategy. Directed engineering and implementation efforts.

Increased cloud security compliance posture by 50+ percentage points over four years by developing a Policy as Code strategy with 120+ secure configuration baselines, embedding scanning (pre-deploy & CSPM) into the global SSDLC.

  • Created and managed a Policy as Code strategy with over 100 secure configuration baselines for GCP, AWS, Azure, and SaaS cloud services, aligned with the Equifax security controls framework.
    • Created a methodology to produce secure configuration baselines by combining threat modeling, existing risk control strategies, and risk treatments.

Increased the security of all deployed applications, as measured by a reduction in pentesting results & bug bounty budget, by integrating the policy as code results into the automated security scorecard used by BISOs for all product go-live decisions.

  • Directed the implementation of the Policy as Code program into Equifax’s SSDLC.
    • Developed a governance model that embedded security into CI/CD automation.
    • Defined defaults in organization Terraform templates.
    • Created rulesets to scan Terraform plans to prevent misconfigured deployments.
    • Created rulesets for a CSPM tool to scan cloud services for noncompliance and malicious activity.

Minimized enterprise risk during corporate expansion, successfully folding in 11 acquired companies by designing risk-based security plans and in situ architectural remediation.

Reduced liability risk by an average 60% from 21 M&A targets by developing a program of CWE mapping due diligence security findings (DAST, SAST, & pentest), negotiating remediation with the target, and reporting to leadership.

  • Provided security architecture review, advice, and oversight for Mergers & Acquisitions.
    • Evaluated 21 M&A targets for security risks (including pentest and SAST results).
    • Created risk-based security plans to on-board 11 acquired companies.
    • Collaborated with acquired teams to remediate architecture in situ and transform architecture as information systems were moved to Equifax environments.

Accelerated global breach recovery by reviewing all enterprise information systems within 3 months, ensuring the security of high-profile services promised to the US Congress by aligning policies & architecture with NIST CSF standards.

  • Supported multiple cross-functional workstreams during Equifax's 2017 breach recovery.
    • Performed emergency security architecture reviews of all information systems.
    • Reviewed security architecture of multiple information systems used for the new Lock & Alert service and app, promised by our interim CEO to the US Congress.
    • Co-created post-breach security policies and controls based on NIST CSF and multiple post-breach consent orders & litigation.

Drove continuous improvement in security architecture, incident response, and team leadership.

  • Participated in ongoing incident response and post-incident remediation efforts.
    • Assessed remediation of critical vulnerabilities by affected teams.
    • Reviewed security architecture of affected information systems post-incident.
    • Identified strategic and/or product-specific architecture improvements and slipstreamed those findings back into BAU processes for remediation.
  • Created presentations, training, and other documentation for all audiences from CEO to IT operations teams.
    • Presented to various levels, including CISO, security leadership, security teams, product owners, IT engineers, and developers.
    • Crafted presentations for a security VP to present to security leadership, CISO and CEO.
  • Led a team of 12 Security Architects across six locations in four countries.
    • Interviewed, onboarded, trained, coached, and oversaw 20 team members total.
    • Established a team culture of autonomy, fun, collaboration, and respect.
IT Examination Analyst 2010 – 2014
Federal Deposit Insurance Corporation (FDIC) Travel

Conducted IT examinations (regulatory IT, cybersecurity, and operational resilience evaluations) of banks across four states.

Enhanced institutional risk posture across 175+ banking institutions by examining banks and delivering ratings to CEOs, CFOs, and Boards of Directors, evaluating their regulatory compliance with GLBA and 12 CFR Part 364.

Reduced systemic financial risk in high-volume payment systems for 15 regional banks by leading specialized audits of complex EFT architectures (ACH, Wire Transfer, Mobile Capture, etc.), identifying findings in high-volume payment processing systems.

Compliance Director / Security Services Manager / Security Engineer 2005 – 2010
TraceSecurity Travel

Provided direction and advice as the 3rd delivery hire, helping the company grow from 225 to more than 800 customers in 4 years.

Scaled security service operations to support a 250% increase in total customer growth by managing an engineering team servicing 225+ financial institutions and writing standardized delivery procedures for the organization.

  • Created process and procedure documentation for all services.
  • Performed information security services for over 100 high-profile customers and projects.
    • Penetration tests (internal and external)
    • Vulnerability assessments (in-person and network)
    • Social engineering (in-person, telephone, and email)
    • General information security consulting
    • Security training (annual and purpose-made)

Drove expansion into new regulated verticals by co-creating three new product offerings (IT Audit, Risk Assessment, and PCI-DSS) and architecting a proprietary GRC regulatory library to translate complex compliance standards for technical and executive audiences.

  • Managed an administrative team of assistants, student workers, proofreaders, and compliance experts to support company operations and security services.

Certifications

GIAC

  • GIAC Public Cloud Security (GPCS) #1551 (2025)

ISC2

Member ID #322057

  • Information Systems Security Architecture Professional (ISSAP) (2026)
  • Information Systems Security Management Professional (ISSMP) (2026)
  • Certified Information Systems Security Professional (CISSP) (2010)
  • Certified Cloud Security Professional (CCSP) (2024)
  • Certified Secure Software Lifecycle Professional (CSSLP) (2026)

Google Cloud (GCP)

  • Professional Cloud Architect (2026)
  • Professional Cloud Security Engineer (2026)

ISACA

  • Certified Information Systems Auditor (CISA) #0870547 (2008)
  • Certified Information Security Manager (CISM) #1014759 (2010)
  • Certified Data Privacy Solutions Engineer (CDPSE) #2116579 (2021)
  • Certified in Risk and Information Systems Control (CRISC) #1418052 (2014)