Led the global Cybersecurity Architect team. Created and managed enterprise-wide cybersecurity programs influencing the design of all infrastructure & product security.
Enhanced cloud security compliance across 20 development teams & all infrastructure teams by 14 points (as measured by CSPM) within one year by establishing 50+ cloud service configuration baselines across Azure, AWS, GCP, and SaaS via the Policy as Code program.
Standardized the enterprise security posture by eliminating four disparate CIS Control implementation approaches, achieved by architecting a Policy as Code program that unified configurations across design, engineering, SSDLC, and infrastructure, including ongoing monitoring.
- Created and managed a Policy as Code (PaC) program for Azure, AWS, GCP, and SaaS environments, aligned with the CIS Controls and company policy.
- Created and managed secure configuration baselines for public cloud services, as well as SaaS providers.
- Created a methodology to produce secure configuration baselines including threat modeling, existing risk control strategies, and risk treatments.
- Utilized AI to assist with coverage and validation of interdependent settings.
- Partnered with IT, security, and development teams to embed the above Policy as Code paradigm into NielsenIQ’s existing processes and procedures in various ways.
- Worked with cloud platform leadership to implement secure configurations as prevention policies using specific cloud provider tools.
- Created rulesets for a Cloud Security Posture Management (CSPM) tool to scan running cloud services for noncompliance and malicious activity.
Increased GRC assessment efficiency for CIS Controls by 20 person-hours per week by successfully advocating for quantitative measurement and proving the practicality of implementing the CIS Controls Assessment Specification at NielsenIQ.
- Advised and consulted on security across the enterprise to enable security by design.
- Led security response in enterprise-wide public cloud governance group.
- Drove GRC team’s transition from qualitative to quantitative evaluation of CIS Controls compliance.
Optimized operational effectiveness through strategic oversight.
- Guided security strategy across the enterprise, directing design, engineering, and implementation efforts.
- Oversaw & performed M&A planning for architecture risk, security, and integration of 11 acquisitions.
- Finalized the architecture remediation of seven pre-existing acquisitions that were not yet fully integrated.
- Created framework for future M&A architecture activities, used for a further three acquisitions.
- Planned and oversaw the architectural integration of same-sized acquisition GfK into NielsenIQ, including planning pre-acquisition, adjusting plans for regulatory approval, and adapting plans as the integration progressed.
- Presented to CISO, security leadership, security teams, and IT engineers.
- Led a team of four Security Architects across three locations and two countries, including onboarding, training, coaching, and oversight.