- Director, Supply-Chain Risk Management at Cargill (2025-10 - Present)
- Executive Director, Third Party Resiliency and Vendor Risk Management at Morgan Stanley (2024-04 – 2025-10)
- Led and managed team's strategic initiatives and projects to drive change and value in the third party risk domain.
- Performed analysis of the firm's data security and protection capabilities for data sent to third parties to identify current protection and security capabilities, identify key risks, and provide recommended remediation to key leadership stakeholders.
- Key contributor in defining the firm's data strategy as it pertains to the third party service lifecycle.
- Represented the third party program through being a member of the firm's data governance committee.
- Developed training to third party service owners to establish expectations and create transparency of the firm's third party lifecycle from planning to offboarding.
- Led tabletop exercises with internal stakeholders for third party contingency and exit planning.
- Collaborated with leadership from various business units to drive efficiency and remediation across the third party service lifecycle.
- Partnered with external service providers (BitSight, SecurityScorecard, BlueVoyant) to develop maturity plans for third party continuous monitoring efforts and sub-contractor discovery.
- Developed and operationalized a methodology to identify the firm's top critical vendors.
- Developed a third party service lifecycle flow that was socialized to internal stakeholders to educate the stakeholders on the third party lifecycle and to establish expectations of establishing a relationship with a third party.
- Key contributor in working groups to enhance third party program management and third party risk management.
Sr. Director, Information Security & Risk at Equifax (2018-08 – 2024-04)
- Successfully developed and implemented a strategic third party security risk management program to ensure 100% risk assessments of 4,000+ third parties were completed within SLA.
- Developed and implemented information and cyber security strategy and framework that consists of strategically integrated elements of NIST risk management and cybersecurity frameworks (NIST CSF, 800.53), ISO/IEC 27001, CIS and COBIT 5 to establish common controls framework across the enterprise.
- Performed annual enterprise-wide security risk assessments, highlighting risks to the enterprise and implemented risk mitigation.
- Devised impactful Key Risk Indicators (KRI) and Key Performance Indicators (KPI) to fortify security risk initiatives, seamlessly integrating them into program advancement.
- Developed key metrics and reporting to board of directors and executive leadership. Presented key metrics to security leadership team on a quarterly and monthly cadence.
- Collaborated with multiple departments to successfully developed third party security risk governance process to provide oversight and governance to the digital supply chain domain.
- Supported and facilitated regulatory and compliance activities for risk department (ISO 27001/27002, PCI-DSS, FedRAMP, FTC/MSAG, CFPB, HIPAA) to meet compliance objectives, and supported 100+ client audits and independent auditor examinations (SOC 1, SOC 2) to ensure objectives were met.
- Designed, developed and implemented CloudControl, a cloud security tool, to bring increased transparency and improved security to digital supply chains for organizations using Equifax products and services.
- Crafted sophisticated executive-level metrics and reporting mechanisms for pivotal risk factors within third-party collaborations, expertly tailored for quarterly board of director sessions and monthly executive and senior leadership deliberations.
- Developed business requirements and managed implementation of a third party GRC tool, ServiceNow, automating third party engagement processes and risk governance.
- Developed and implemented a risk methodology for internal audit to use during audits, ensuring a standardized approach to measure risks.
- Developed and operationalized third party breach process to report on the impact and risk to the organization, including executive reporting to enterprise executive level management and technology board of directors.
- Project manager in implementing security tools (CyberGRX, BitSight, Security Scorecard, Interos) that provide security risk insight to the organization.
Manager, Information Security & Risk at The Home Depot (2016-09 – 2018-08)
- Successfully developed and implemented a strategic third party security risk management program to ensure 100% risk assessments of 3,000+ third parties were completed within SLA.
- Developed and third party security risk policy, standards, methodology, and procedures to align with enterprise and regulatory requirements; operationalized within the enterprise.
- Project manager to identify the count of third parties the organization utilized for services, to develop and implement a comprehensive inventory to determine risks and security risk activity prioritization.
- Performed onsite and offsite assessments of critical service vendors, to include the documenting of the security control gaps, negotiating remediation plans for severe security control gaps, and validating the remediation.
- Project manager in implementing security tools (CyberGRX, Security Scorecard, Archer) that provide security risk insight to the organization.
Sr. Information Security Risk Consultant / Information Governance Consultant at Aflac (2015-05 – 2016-09)
- Successfully developed and implemented a strategic application security risk management program to determine risks for 3000+ applications.
- Established third party and application risk assessment methodologies, policies and procedures that align to organizational objectives and HIPAA/HITRUST standards.
- Performed onsite and offsite assessments of critical service third parties, documenting of the security control gaps in a risk register, negotiating remediation plans for severe security control gaps, and validation of remediation.
- Performed application security risk assessments, documenting security control gaps in a risk register, negotiating remediation plans, and validation of remediation.
- Presented identified risks to governance committees to ensure appropriate risk thresholds were achieved for applications and third parties.
- Successfully developed and implemented a strategic information governance program to identify and classify types of data in the organization.
- Business representative for Aflac's Information Governance initiative, to include interviewing stakeholders across the enterprise to gather business objectives in procuring an Information Governance and Archival System.
- Project manager in implementing an information governance, archival and legal hold system.
- Collaborated with the Legal department to update and mature records retention policy, ensuring compliance to federal and state regulations.
- Represented the organization in CISO coalition activities for information governance and risk activities.
Information Security Risk Analyst at SunTrust (Truist) (2012-05 – 2015-04)
- Successfully developed and implemented a strategic application security risk management program to determine risks for 4000+ applications.
- Performed application security risk assessments, documenting security control gaps in a risk register, negotiating remediation plans, and validation of remediation.
- Performed compliance testing (SOX, GLBA, PCI-DSS) on applications in-scope; supported assurance testing for SOC 1 independent auditor exams.
- Performed onsite and offsite assessments of critical service third parties, documenting of the security control gaps in a risk register, negotiating remediation plans for severe security control gaps, and validation of remediation.
- Project manager in implementing security tools (CyberGRX, BitSight, Security Scorecard, Interos) that provide security risk insight to the organization.
Network Operations Supervisor at USAN (2007-03 – 2012-04)
- Managed team of 6+ engineers to provide 99% network performance availability to clients.
- Established network operation policies and procedures to support organizational strategy and policies.
- Developed and presented organizational improvements to senior leadership team including formalized performance plans, critical business planning, process development and policy creation.
- Performed daily event and maintenance reporting for organization's executives and clients.
- Performed real time network surveillance of all USAN occupied sites, interfaces, and equipment in a 24x7 environment.
- Isolated and corrected all network and system events impacting service.
- Performed, monitored, and managed all production maintenance for organization's applications and systems.
Network Operations Engineer at United States Air Force (1999-09 – 2005-01)
- Supported and maintained multi-million-dollar networks and communication systems for USAF, DoD, and NATO.
- Coordinated the configuration, operation, restoration, and service improvements of computer networks and computer communication systems.
- Identified, directed, and reported corrective actions on all conditions adversely affecting transmission systems, circuits, and network system performance.
- Applied Communication Security (ComSec) and Information Security (InfoSec) techniques to ensure the confidentiality, integrity, and availability of confidential and sensitive data and systems.