Mark E.S. Bernard **********@*****.***
British Columbia, Canada
HIGHLIGHTS OF QUALIFICATIONS
Provided Privacy and Security oversight during Alternate Service Delivery onboarding
project including data migration and SAP R3 implementation
Centralized Pharmaceutical BPCS ERP from 3 countries, Recertified ISO 9001
Directed integrated staff of 13 FTE Union employees and 25 contractors
Managed $5 million dollar budget
Managed TechOps for Oracle eBiz Suite ERP and Data W arehouse for 24,000 users x
19 ministries, $ 37 Billion processed in payments each year.
Led 10 month Negotiated Request for proposal, exiting /on-boarding value $25M.
Championed Transformation ISO 27001 registration and ITIL adoption.
Led Security, Privacy work-stream during $300M contract re-negotiation.
Led EDI onboarding new trading partners, MH12 & Advanced Shipment Notices.
HRIS Manager GL sub-ledger and Electronic Funds Distribution.
ACHIEVEMENTS
Led US Cloud Service Provider on 4 continents x 8 DC to ISO 27001 Reg./Cert..
Led 1st Canadian Government Entity to ISO/IEC 27001 Reg./Cert.
Led 1st Canadian Bank Trade & Wholesale Service to ISO 27001 Reg./Cert.
Recognized by NB Premier for Knowledge Management Leadership
PROFESSIONAL DESIGNATIONS
ISACA - Certified Information Security Manager (CISM)
ISACA – Certified in Risk Information Systems Control (CRISC)
ISACA – Certified in the Governance of Enterprise IT (CGEIT)
SABSA - Security Architecture Service Management (Test Module F2)
ISACA – Certified Information Systems Auditor (CISA)
ISC2 – Certified Information Systems Security Professional (CISSP)
PROFESSIONAL EXPERIENCE
Company: TechSecure Holdings Inc, Vancouver, British Columbia, Canada.
Scope: International, Privately Held Canadian Consultancy.
Title: Director, Governance, Risk & Compliance - Date of Service – Feb 2010/Current.
Reported to: self-employed, Direct reports – one, Annual budget - $100k.
Summary: As the Director of Governance, Risk and Compliance I am currently leading projects
designed to help my clients improve the effectiveness and efficiency of their existing programs. I
facilitated the adoption of ISO/IEC 27001 – ISMS, Audit, GAP Assessments, CyberSecurity
program design based on Defence-in-Depth and ISMS for many clients. This includes data
governance programs, risk management programs, compliance management programs,
RFP/RFI and integration with information security, software licensing management, Technical
Architect, Capacity Planning, Change Management, Release Management, ITIL,
Incident/Problem Management, Continuous Improvement, ISO 9001, ISO 27001, Service
Page 1 of 2
Management, Service Level Agreement, Procurement, Communication, Training/Awareness,
Strategic/Tactical planning, and Budgeting.
Company: Government of British Columbia, Victoria, British Columbia, Canada.
Scope: Local Canadian provincial government.
Title: Director of Technology Operations, Date of Service – November 2008 – February 2010.
Reported to: Executive Director, Direct reports – 13 Union employees and 25 contractors,
independent contractors, service providers, and an annual budget - $5 million.
Summary: As the Director of Technology Operations I played a strategic role actively
participating in annual strategic planning sessions and representing CAS as their CIO. I was the
sponsor of many projects including the creation of the Application Architecture. I led many
projects including the on-boarding of a new operational service provider, ISO/IEC 27001
registration/certification, and ITIL /Service Management adoption. I also provided oversight for
the daily planning, development and delivery of CAS Technology Operations and Oracle eBiz
Suite for 24,000 customers processing $37 billion annually. My role also included security,
software licensing management and negotiation, risk management, business continuity
planning, privacy, system configuration, system and database administration, region
management and change control, technical services, infrastructure capacity planning and the
development and implementation of security standards and policies to ensure that data and
systems integrity, stability and availability are protected. A few specific accomplishments
include:
• Led 1st Canadian Public Sector ISO/IEC 27001 Registration/Certification.
• Led Exit of 10 year incumbent & On-boarded Integrated ERP Service Provider
• Led TechOps during 10 month Negotiated Request for Proposal.
PROFESSIONAL DEVELOPMENT
Education
• University of Toronto Continuing Education HRM (not completed)
• Centennial College - AS/400 RPG Advanced File techniques (4.0 GPA)
• York University/Seneca College - Instructional Skills Workshop (completed)
Certifications
• BSI – ISO/IEC 27001 Lead Auditor (ISO27k LA)
• MICA Strategic People Development - Project Management Certificate (PM)
• ITIL - Foundation Workshop / Certificate
• ISACA - COBiT Foundation Workshop / Certificate
• Insights - Transformational Leadership program
• Certificate in Citicus
• IBM Canada, AS/400 (iSeries) 10 x Certifications:
Operator Workshop Structure, Tailoring & Basic
System Concepts and Tuning
Interactive Program Design
Facilities
Security Performance Analysis &
System Administration & Capacity Planning
Control Query
Recovery/Restart Planning
and Implementation
Relational Data Base Design
& Coding
Page 2 of 2