Post Job Free
Sign in

Chief Information Security Officer

Location:
New Hyde Park, NY
Posted:
June 14, 2021

Contact this candidate

Resume:

JOSEPH TSO

New Hyde Park, NY ***** Phone: 718-***-**** Email: ******.***@*****.***

PROFESSIONAL SUMMARY

Business Partner Cybersecurity Information Security Cloud Security Data/Security Governance Privacy Management Incident Response Extensive knowledge of cyber/privacy regulations including NYS DFS 500 Cybersecurity Regulations, FFIEC, FINRA, NFA, CCPA, EU GDPR, and HIPAA Experience in IT/cybersecurity frameworks, e.g. NIST, COBIT, and ISO 27001 Industry experience includes financial services, insurance, E-commerce, entertainment, fashion, aerospace Panel advisor for Cybersecurity Resilience and Regulations

PROFESSIONAL EXPERIENCE

Scotiabank (Bank of Nova Scotia) - New York, NY August 2018 – Present

Chief Information Security Officer U.S.

Designed and implemented the Information Security and Cybersecurity program for Scotiabank US Global Banking and Markets division

Delivers US Board quarterly updates on the cyber program, cyber/IT risks, regulatory and compliance reporting

Leads team providing services for security advisory, governance, cyber risk management, and security assessment for third party vendors

Collaborates with global security stakeholders to ensure security controls are effective in the US

Advisor to the CIO and Global CISO on global projects and initiatives impacting the US

Co-leads identification and implementation of security tools with the Chief Information Security Architect

Delivered 40% reduction in US security risk index scores within the first 9 months by enhancing the vulnerability management program

Closed 80% of open audit issues within 90 days

Designed and executed regional threat risk assessment and internal security control testing

Championed creation of U.S. Cybersecurity training awareness program and phishing exercises. Reduction in phishing failure rate by >50% within 90 days

Championed the roll-out of the End User Computer Program using Clusterseven

Designed and implemented a vulnerability risk management program focusing on aged vulnerabilities/timely patch management

Created an access privilege re-certification campaign using SailPoint for shared folders and unstructured NPI data. Eliminated excess privilege accounts and restructured the provisioning for shared folder access

Key contributor to IT cloud project, providing risk-based decisions on security controls

Primary liaison with multiple US regulators [such as but not limited to] NY DFS, FINRA, and FRBNY

Leads cybersecurity incident response and associated planning

Transatlantic Reinsurance (TransRe) - New York, NY June 2017 – August 2018

Cybersecurity Program Manager

Designed and implemented the creation of the cybersecurity program based on the NIST Framework

Defined strategic initiatives to execute deployment of cyber policy, procedures, and security controls

Participant of the Cyber Risk Committee presenting to senior management and advising of cyber risks, program updates, and strategies

Defined IT/cyber policies and procedures ensuring conformity with regulations, legal and compliance

Championed the creation of the cyber risk management program, performed third party assessments, internal risk assessments, and control testing

Defined the incident response policy and procedures including selection of incident response monitoring, table-top exercises, and forensic investigation vendors

Implemented security controls [including but not limited to] Security Incident Event Management (Rapid 7 SIEM), Privileged Access Management (CyberArk PAM), hardware destruction, data classification/identification (Varonis), file behavior analysis software, penetration testing, vulnerability scanning, patch management, and Data Loss Prevention.

Coordinated all internal and external IT security audit/regulatory requests and engagements

Designed and implemented cybersecurity awareness training program and phishing exercises for employees

Structured Portfolio Management - Stamford, CT October 2010 – April 2017

Vice President of IT and Security

Led day to day operations of the IT department consisting of Security and Infrastructure

Designed and implemented the cybersecurity program based on NIST and ITIL framework

Defined security policies and procedures to satisfy regulatory requirements

Designed and implemented the cyber risk management program for Cybersecurity risk assessment, business impact analysis for management, and third-party risk assessments

Defined the business continuity plan for crisis management, disaster recovery plans, and disaster recovery sites

Designed and rolled out Cybersecurity awareness training for employees which include phishing exercises

Implemented Palo Alto intrusion prevention firewall for monitoring and blocking web traffic from malicious threats

Implemented Varonis for data governance and monitoring

Implemented SolarWinds Log and Event Manager for monitoring and alerting security events

Designed and implemented a vulnerability and patch management program

Built server farm that consists of over 200 VM and physical servers to support data modeling and applications

Magellan Aerospace – Corona, NY May 2005 – October 2010

Senior Security Engineer

Led day to day operations of the IT infrastructure for US divisions

Led a support team of 3 individuals for helpdesk and infrastructure

Championed and led migration of Active Directory

Championed and led migration of Exchange email systems

Designed and implemented security risk management program, conducting risk assessment for security compliance

ADVISORY / BOARD MEMBERSHIP

CyberStarts Venture Fund LTD Board of Advisors Herzliya, Israel April 2020 – Present

Provide strategic advice on potential early cybersecurity companies

Identify potential companies for investments and help in business development and growth of the company.

LIFARS Board of Advisors New York, NY January 2019 - Present

Provide strategic advice to the management of LIFARS related to the organization’s health and current cyber landscape

ISACA New York Metropolitan Chapter Volunteer Board of Directors New York, NY January 2019 - Present

Volunteer Board of Directors – Co-Chair Membership Committee

Provide strategic advice on the direction of local chapter membership and attracting new members

Host events and content for our NY members related IT governance and Cybersecurity

Created the sponsorship program for ISACA NY chapter

CERTIFICATIONS

Certified Data Privacy Solutions Engineer (CDPSE) - 5/2020 License Number: 2000869

FINRA Operations Professional Series 99 - 11/2018 CRD Number: 2739

Certified Information System Security Professional (CISSP) - 9/2017 License Number: 498251 Certified Information Security Manager (CISM) - 5/2018 License Number: 1840890 AccessData Certified Examiner (Computer Forensics) - 8/2015

ITIL V3 Foundation Certification - 12/2009 Certified Lean Six Sigma Green Belt - 3/2009

EDUCATION

Embry Riddle Aeronautical University - Daytona, FL Master of Science in Information Security and Assurance – With Distinction

Pace University - New York, NY Bachelor of Science in Computer Forensic – Summa Cum Laude



Contact this candidate