JOSEPH TSO
New Hyde Park, NY ***** Phone: 718-***-**** Email: ******.***@*****.***
PROFESSIONAL SUMMARY
Business Partner Cybersecurity Information Security Cloud Security Data/Security Governance Privacy Management Incident Response Extensive knowledge of cyber/privacy regulations including NYS DFS 500 Cybersecurity Regulations, FFIEC, FINRA, NFA, CCPA, EU GDPR, and HIPAA Experience in IT/cybersecurity frameworks, e.g. NIST, COBIT, and ISO 27001 Industry experience includes financial services, insurance, E-commerce, entertainment, fashion, aerospace Panel advisor for Cybersecurity Resilience and Regulations
PROFESSIONAL EXPERIENCE
Scotiabank (Bank of Nova Scotia) - New York, NY August 2018 – Present
Chief Information Security Officer U.S.
Designed and implemented the Information Security and Cybersecurity program for Scotiabank US Global Banking and Markets division
Delivers US Board quarterly updates on the cyber program, cyber/IT risks, regulatory and compliance reporting
Leads team providing services for security advisory, governance, cyber risk management, and security assessment for third party vendors
Collaborates with global security stakeholders to ensure security controls are effective in the US
Advisor to the CIO and Global CISO on global projects and initiatives impacting the US
Co-leads identification and implementation of security tools with the Chief Information Security Architect
Delivered 40% reduction in US security risk index scores within the first 9 months by enhancing the vulnerability management program
Closed 80% of open audit issues within 90 days
Designed and executed regional threat risk assessment and internal security control testing
Championed creation of U.S. Cybersecurity training awareness program and phishing exercises. Reduction in phishing failure rate by >50% within 90 days
Championed the roll-out of the End User Computer Program using Clusterseven
Designed and implemented a vulnerability risk management program focusing on aged vulnerabilities/timely patch management
Created an access privilege re-certification campaign using SailPoint for shared folders and unstructured NPI data. Eliminated excess privilege accounts and restructured the provisioning for shared folder access
Key contributor to IT cloud project, providing risk-based decisions on security controls
Primary liaison with multiple US regulators [such as but not limited to] NY DFS, FINRA, and FRBNY
Leads cybersecurity incident response and associated planning
Transatlantic Reinsurance (TransRe) - New York, NY June 2017 – August 2018
Cybersecurity Program Manager
Designed and implemented the creation of the cybersecurity program based on the NIST Framework
Defined strategic initiatives to execute deployment of cyber policy, procedures, and security controls
Participant of the Cyber Risk Committee presenting to senior management and advising of cyber risks, program updates, and strategies
Defined IT/cyber policies and procedures ensuring conformity with regulations, legal and compliance
Championed the creation of the cyber risk management program, performed third party assessments, internal risk assessments, and control testing
Defined the incident response policy and procedures including selection of incident response monitoring, table-top exercises, and forensic investigation vendors
Implemented security controls [including but not limited to] Security Incident Event Management (Rapid 7 SIEM), Privileged Access Management (CyberArk PAM), hardware destruction, data classification/identification (Varonis), file behavior analysis software, penetration testing, vulnerability scanning, patch management, and Data Loss Prevention.
Coordinated all internal and external IT security audit/regulatory requests and engagements
Designed and implemented cybersecurity awareness training program and phishing exercises for employees
Structured Portfolio Management - Stamford, CT October 2010 – April 2017
Vice President of IT and Security
Led day to day operations of the IT department consisting of Security and Infrastructure
Designed and implemented the cybersecurity program based on NIST and ITIL framework
Defined security policies and procedures to satisfy regulatory requirements
Designed and implemented the cyber risk management program for Cybersecurity risk assessment, business impact analysis for management, and third-party risk assessments
Defined the business continuity plan for crisis management, disaster recovery plans, and disaster recovery sites
Designed and rolled out Cybersecurity awareness training for employees which include phishing exercises
Implemented Palo Alto intrusion prevention firewall for monitoring and blocking web traffic from malicious threats
Implemented Varonis for data governance and monitoring
Implemented SolarWinds Log and Event Manager for monitoring and alerting security events
Designed and implemented a vulnerability and patch management program
Built server farm that consists of over 200 VM and physical servers to support data modeling and applications
Magellan Aerospace – Corona, NY May 2005 – October 2010
Senior Security Engineer
Led day to day operations of the IT infrastructure for US divisions
Led a support team of 3 individuals for helpdesk and infrastructure
Championed and led migration of Active Directory
Championed and led migration of Exchange email systems
Designed and implemented security risk management program, conducting risk assessment for security compliance
ADVISORY / BOARD MEMBERSHIP
CyberStarts Venture Fund LTD Board of Advisors Herzliya, Israel April 2020 – Present
Provide strategic advice on potential early cybersecurity companies
Identify potential companies for investments and help in business development and growth of the company.
LIFARS Board of Advisors New York, NY January 2019 - Present
Provide strategic advice to the management of LIFARS related to the organization’s health and current cyber landscape
ISACA New York Metropolitan Chapter Volunteer Board of Directors New York, NY January 2019 - Present
Volunteer Board of Directors – Co-Chair Membership Committee
Provide strategic advice on the direction of local chapter membership and attracting new members
Host events and content for our NY members related IT governance and Cybersecurity
Created the sponsorship program for ISACA NY chapter
CERTIFICATIONS
Certified Data Privacy Solutions Engineer (CDPSE) - 5/2020 License Number: 2000869
FINRA Operations Professional Series 99 - 11/2018 CRD Number: 2739
Certified Information System Security Professional (CISSP) - 9/2017 License Number: 498251 Certified Information Security Manager (CISM) - 5/2018 License Number: 1840890 AccessData Certified Examiner (Computer Forensics) - 8/2015
ITIL V3 Foundation Certification - 12/2009 Certified Lean Six Sigma Green Belt - 3/2009
EDUCATION
Embry Riddle Aeronautical University - Daytona, FL Master of Science in Information Security and Assurance – With Distinction
Pace University - New York, NY Bachelor of Science in Computer Forensic – Summa Cum Laude