Reported to CEO. Hired as fifth employee to implement robust security function, protect innovative intellectual property and valuable R&D information from global cyber criminals, and establish greenfield IT function, under under rigid financial controls. Hired and managed two employees.
● Defended critical information assets from internal and external threats by developing and implementing a complete information security architecture, with minimal budget, focused on controls from the Center for Internet Security (CIS) and the National Institute of Standards and Technology (NIST 800-53 and CSF).
● Enabled the enterprise to commence and sustain operations; designed and implemented the entire technology ecosystem, directed build-out, selected and managed vendors.
● Built a culture of communal responsibility for managing privacy and IT security risk by championing a strategy of continual security performance measurement, quantitative risk analysis, and leading security awareness training; created comprehensive corporate security policies, guidelines, and standards.
● Optimized security spending effectiveness and prioritized security investment through risk management using NIST 800-39 and the industry standard quantitative model Factor Analysis of Information Risk (FAIR). Enhanced management’s decision effectiveness by providing data-driven analyses of costs and risks within business needs and strategies.