Cambridge, Massachusetts, United States• Manage and continuous improvement of organizational ISMS.
• Manage and conduct regular updates and reviews of organizational risks.
• Maintain and improve IS policies and procedures, ensuring compliance with industry certifications.
• Manage and improve high-risk systems and external party security and risk assessment processes (TPRM).
• Conduct periodic internal audits.
• Plan and manage f...
Jan. 2015 - Oct. 2023
NTTManager, ISMS & Business Continuity | Compliance, Risk & ISO 27001
Massachusetts, United States• Spearheaded ISO 27001 certification lifecycle—defined scope, authored policies, built metrics/reporting, and hosted audits; reduced audit findings by 50% over 8 years.
• Developed an Excel-based Statement of Applicability tool, cutting audit prep time by 25%.
• Supported Brazil’s ISO 27001 certification and enabled remote audit readiness for Chile, reducing travel costs.
• Built and sustain...