Post Job Free
Sign in

Director, Cybersecurity Governance

Location:
United States
Posted:
August 06, 2026

Contact this candidate

Resume:

MONI MANIRUZZAMAN MBA, PMP, CISSP, CISM, MCP, CASP+, CRISC, CPM, CPS, CRMP, CICA

Web: Linkedin - Tel: 647-***-**** E-mail: ******@*****.***

CYBERSECURITY AI GOVERNANCE GRC

Cybersecurity, AI Governance, and IT Risk leader with 16+ years of experience delivering enterprise cybersecurity and technology programs, security architecture, portfolio governance, cyber risk management, executive reporting, cloud security, GRC, and regulatory compliance across highly regulated industries. Trusted CISO advisor with deep expertise in NIST, ISO 27001, OSFI, and enterprise risk frameworks, recognized for driving risk maturity, strengthening governance, and enabling secure digital transformation while protecting critical business assets.

EXECUTIVE PROFILE

Trusted advisor to executives with expertise in cyber risk assessments, portfolio governance, executive reporting, business case development, investment prioritization, and strategic decision-making.

Enterprise cybersecurity and IT risk leader with a proven track record of protecting revenue, reputation, regulatory compliance, and organizational resilience.

Experienced in AI governance, responsible AI, cloud security, security architecture, and enterprise risk management, enabling secure adoption of emerging technologies.

Extensive experience implementing and governing industry frameworks including NIST, ISO 27001, COBIT, SOX 302/404, PCI-DSS, HIPAA, COSO, and OSFI regulatory requirements.

Collaborative leader recognized for stakeholder engagement, financial analysis, ROI-driven recommendations, and delivery of secure digital transformation initiatives across regulated environments.

CORE SKILLS

Cybersecurity/AI Governance & Risk Mgt

Security Architecture & Cloud Security

GRC, Compliance & Control Frameworks

Cyber Risk, Controls & CISO Advisory

Portfolio Governance & Business Cases

Executive Reporting & Portfolio Analytics

Digital Transformation & GRC Platforms

Generative AI Security & Responsible AI

IAM, Data Protection & Security Operations

Stakeholder & Executive Engagement

PROFESSIONAL CERTIFICATIONS

Certified Information Systems Security Pro (CISSP)

Risk and Information Systems Control (CRISC)

Certified Information Security Manager (CISM)

Project Management Professional (PMP) – PMI

CompTIA Security Practitioner (CASP+)

Certified Internal Controls Auditor (CICA)

Microsoft Certified Professional – Azure (MSP)

Certified RMP (CRMP) - CISO perspective

Certified Control Specialist (CCS)

Certified Project Manager (CPM)

Certified Management Professional (CMP)

Certified Fraud Specialist (CFS)

TECHNICAL KNOWLEDGE:

Microsoft Copilot, Security Copilot, Azure, AWS, Archer GRC, ServiceNow, Splunk, Microsoft 365, Power BI, Excel.

PROFESSIONAL EXPERIENCE

CISO RISK PARTNER - CONSULTANT

Aviva Canada, Markham, ON Feb. 2025 - Present

CISO Risk Partner: Delivered first-line cyber risk oversight for the CISO, developing executive dashboards, KPIs/KRIs, and portfolio reporting to support governance and strategic decision-making.

Risk Assessment Leader: Led Aviva’s Group/Local markets IT risk assessments (RCSA), control testing, and cyber risk analysis across cloud, IAM, data protection, and individual/brokers channel risk.

Risk BI/MI Analyst: Monitored cyber and AI risk KPIs/KRIs, including model performance risks, vulnerability trends, and cloud security metrics, enabling proactive risk mitigation and control optimization.

Executive Risk Oversight: Supported enterprise cybersecurity portfolio planning by prioritizing initiatives, tracking risk remediation, and reporting program status to executive leadership.

Regulatory Compliance Specialist: Supported compliance aligned with OSFI B10/B13, NYCRR, ISO 27001, NIST CSF, ITGC, and Aviva’s iCare GRC frameworks.

GRC Platform Steward: Managed GRC tooling (iCare), maintaining accurate risk registers, event logs, control documentation, and audit readiness.

Governance Collaborator: Partnered with the Group in the UK and enterprise-wide locale market’s 1st, 2nd, and 3rd Lines of Defence to strengthen cyber governance and risk culture maturity.

Security Transformation Advisor: Advised business and technology leaders on AI governance, Generative AI risk, cloud security, identity, and secure adoption of emerging technologies.

AI Governance Advisor: Provided SME to the business and technology teams on AI and Generative AI risk, cloud security, identity, and governance to enable secure adoption of emerging technologies.

SR. CYBER SECURITY STRATEGIST – CONSULTANT

Ignite Security Solutions Group, Toronto, ON Feb. 2021 – Jan. 2025

Proactively Engages: Demonstrates a self-motivated balance of technical expertise and proactive engagement in guiding Ignite's clients towards cyber resilience to protect information assets.

Optimization Advisor: Recommended enhancements to clients' cybersecurity policies, procedures, standards, guidelines, SOW’s, and MSA’s aligning them more effectively with their objectives.

Risk Management Expert: Conducts detailed reviews and assessments of technical controls for client compliance across the key integrated frameworks like CMMC, NIST 800-53, ISO 27001, COBIT, PCI-DSS, HIPAA, FedRAMP, and NERC CIP to oversight AI, Generative AI, cloud, OT, IoT, and ML environments.

Compliance Evaluator: Diligently evaluated and tested clients' technical and procedural security controls for robust compliance with privacy legislations including GDPR, FIPPA, PIPEDA, Bill C-27, and PIPA.

Strategic Planner: Assisted clients in developing business cases and cybersecurity strategy recommendations supporting client investment decisions on cyber roadmaps and to remediate control gaps.

Advisory Leader: Provided expert advisory services to enhance clients' cyber risk management functions, encompassing various defense lines, CMMC, and vulnerability management.

CYBER SECURITY CONSULTANT – GRC Mar. 2020 – Feb. 2021

Empire Company Limited, Mississauga, ON, Canada

Spearheaded Cybersecurity Expertise: Delivered specialized Cyber Security SME guidance to enhance IS maturity across business units including PM, Internal control, Compliance, Audit, and third-party collaborations throughout the project lifecycle.

Implemented GRC Solutions: Successfully deployed a GRC platform, automating the majority of Security Improvement Programs (SIPs) to optimize productivity both business and IT.

Facilitated Knowledge Sharing: Conducted comprehensive training sessions on technology controls, security domains, and best practices to enhancing the expertise of the security team and third parties.

Assured Compliance through Reviews: Reviewed third-party cyber-related attestations, including SOC1/2, ISO/NIST/Audit certifications, and providing detailed reports to guarantee security coverage prior to finalizing MSA/LSA/LOA agreements.

BUSINESS PROCESS CONSULTANT

TD Bank, Toronto, ON, Canada Aug. 2018 – Feb. 2020

Pioneered Archer GRC IM Roadmap/Requirements: Pioneered the Archer GRC IM roadmap by developing business cases, portfolio analyses, and GRC requirements to prioritize cybersecurity initiatives. Prepared executive reporting and partnered with senior stakeholders to align investments with business objectives.

Analyzed EFM Strategies: Assessed potential Enterprise Fraud Management (EFM) risk strategies, evaluating their technological and business viability, and contributed to prioritization and impact analysis.

Enhanced Risk Assessment Processes: Critically evaluated existing risk assessment and gap remediation processes, recommending improvements to align with Archer 6.2 MVP process.

Directed Strategic Solutions in TRIMS: Offered strategic guidance to resolve complex issues within TRIMS, implementing diverse reporting requirements for both executive and operational levels to curtail risk exposure.

IS SECURITY CONSULTANT

General Electric (GE) Global Operations, Mississauga, ON, Canada Dec. 2017 – Jul. 2018

Launched and Managed EAR Campaign: Orchestrated and executed an Enterprise Access Review (EAR) campaign to align system and application access with regulatory standards, including SOX, PCI, and COSO.

Facilitated EAR Knowledge Sessions: Conducted training sessions for the security team, enhancing their understanding, and engagement in the EAR campaign.

Architected and Led InfoSec Awareness Program: Crafted and deployed a comprehensive strategy for company wide IS awareness program, focusing on training, education, and awareness to strengthen enterprise security.

Communicated Security Policies Effectively: Ensured widespread understanding and compliance with GE’s information security policies through clear, paced communication strategies.

Advocated for Cybersecurity Awareness: Promoted awareness of GE’s information security policies, SOWs, and guidelines, creating an engaging online presence with interactive activities to reinforce secure behaviors.

MANAGER, CYBER SECURITY GOVERNANCE

Rogers’s Communications, Brampton, ON, Canada Oct. 2015 – Dec. 2017

Pioneered SIP with Significant Budget: Spearheaded the Security Improvement Program (SIP) with a budget of approximately $7 million, positioning the company competitively against major players like BELL, TELUS, and 3rd party. Effectively communicated SIP status updates to the board.

Optimized IAM Practices: Streamlined Identity and Access Management (IAM) processes, enhancing availability, accessibility, and efficiency for both cloud and physical networks.

Synthesized GRC Reports with Frameworks: Analyzed and consolidated a range of Cybersecurity, Governance, Risk, and Compliance reports within the security department, aligning them with NIST, ISO, and ISF frameworks to reduce risk.

Enforced EAR CamGovernancepaign: Successfully rolled out the Enterprise Access Review (EAR) campaign, regulating system and application access in line with ISO-defined regulatory and business requirements.

Revamped IAM Roadmap: Developed and continually updated the IAM roadmap for enterprise systems, enhancing Rogers' ability to maintain robust tools, technology, and policies company-wide.

Assessed and Enhanced IS Metrics: Managed portfolio governance across multiple cybersecurity initiatives with executive reporting, resource prioritization, and risk tracking to the Information and Cyber Security Unit (ICSU), external auditors, and board members to gauge success.

Established Data Classification Process: Devised and implemented a comprehensive process to classify customer data within Rogers Enterprise (Public, Internal, Confidential, Restricted), aligning with ISO standards.

TECHNOLOGY RISK CONSULTANT

NAL Energy, Calgary, AB, Nov. 2012 – Sep. 2015

Oversaw Security Risk Assessments: Managed project-based security risk assessments, including SAL, MSA, and NAL’s End User access, to safeguard the company’s data and interests.

Directed IT Audit Unit: Led a diverse IT audit team, executing in-depth audit programs that supported the annual audit plan.

Ensured DISA STIG Compliance: Developed, monitored, and audited audit logs, events, and configurations across organizational units for DISA STIG compliance, targeting policy violations and vulnerabilities.

Pioneered SOX 404 and 302 Compliance Testing: Innovatively designed and implemented IT General Controls and Application Controls testing strategies for SOX 404 and 302, and SAS 70, to mitigate financial reporting risks.

Optimized Audit Processes: Provided integrated audit support to cross-functional teams, reducing compliance costs by 15% through strategic risk management and top-down financial statement analysis.

Improved Project Control Framework: Spearheaded the enhancement of project control and assessment frameworks, investigating unauthorized transactions and abuse cases to prevent financial losses.

EDUCATION & PROFESSIONAL DEVELOPMENT

MASTER OF BUSINESS ADMINISTRATION (MBA)

(Cybersecurity and Technology Management, American College, Washington, DC, USA)

PROJECT LEADERSHIP MANAGEMENT DIPLOMA

(Cornell University, Ithaca, NY, USA)

BACHELOR DEGREE, INFORMATION TECHNOLOGY

(American Intercontinental University, Atlanta, GA, USA).

COMPUTER SCIENCE DIPLOMA

(City College of Hong Kong, Kowloon, Hong Kong, China)

BACHELOR DEGREE, SCIENCE & TECHNOLOGY

(National University, Dhaka, Bangladesh).

MECHANICAL ENGINEERING TECHNOLOGY

(Barisal Polytechnic Institute, Barisal, Bangladesh)

PROFESSIONAL AFFILIATIONS

Member: Project Management Institute – Lakeshore chapter (PMI)

Member: Information Systems Audit and Control Association (ISACA)

Member: The International Information System Security Certification Consortium (ISC)

Member: Institute of Internal Audit (IIA)

ADDITIONAL PROFESSIONAL EXPERIENCE

IT AUDIT MANAGER - StoneMor Partners, L.P. Levittown, PA, USA - 2005 - 2012

SR, IT AUDIT CONSULTANT - Protiviti Inc, Philadelphia, PA, USA - 2004 - 2005

IT PM CONSULTANT - Software Process, Inc., Atlanta, GA, USA - 1998 – 2000

AREA MANAGER - Crown Central Petroleum, Atlanta, GA, USA - 1996 – 1998



Contact this candidate