Glen Willis
Seattle, WA ***************@*****.*** 952-***-****
www.linkedin.com/in/glenlorenwillis
PROFESSIONAL SUMMARY
Vision-driven and results-focused IT and risk management professional with more than 25 years of wide-ranging experience providing technical leadership and successfully managing complex and highly visible projects. Versatile background in all aspects of Cybersecurity and Software Delivery with expertise in the areas of IT governance practices, cybersecurity risk and compliance, and AI governance and implementation. Superior knowledge relating to governance, compliance, and technology operations with accountability for 24x7x365 uptime.
AREAS OF EXPERTISE
Cybersecurity / Privacy Law
Full Lifecycle Project Management
Acquisitions / Integrations
Information Systems Security
Portfolio Management / Strategic Planning
Change Management
Regulatory Compliance
Release Management / Software Delivery
Governance / Compliance
Software Development Lifecyle
Risk Management / Process Improvement
Government Sector
AI Governance and Implementation
EXPERIENCE AND KEY ACCOMPLISHMENTS
Kalles Group, Seattle, WA
Sep 2019 – May 2026
PRACTICE LEADER– CYBER AND RISK
Drive and support data privacy, cyber and technology risk and compliance initiatives on behalf of clients. Develop strategy, roadmap and implementation plans for enterprises and technology organizations. Distillation and prioritization of risk remediations plans. Drive compliance readiness across broad range of frameworks (NIST, SOC2, ISO2701, HIPAA, etc.) Identify third-party solutions to enable security and privacy initiatives. Manage executive engagement and support of security and privacy initiatives.
Microsoft Environment and Security Hardening – oversaw 50+ engagements across client organizations with varying profiles and needs. From gap assessment, findings, remediation recommendations, and co-implementation with client engineering teams.
Higher Educational Institutions – supported President, CFO, and IT Leadership across 6 local universities through the following services. Assessed the organizations technology portfolio with emphasized focus on general effectiveness of technology delivery and support and cybersecurity posture. Delivery of a multi-year roadmap to mature technology delivery and operations and to harden and mature security practices and security technologies. Provided analysis as input toward consideration to outsource the IT function, wrote and facilitated an RFI/RFP(s) that led to selection of a third-party vendor for transition of the IT function. Hardening security posture across Azure, AWS, and GCP platforms. Led FERPA compliance reviews. Led optimization of EPIC technology systems enhancements. Optimized onboarding processes for student enrollment periods. Penetration testing services and remediation. Zero Trust architecture implementation. Vulnerability management services. Cloud security hardening.
Application Security – led 20+ engagements focused on helping clients improve, mature, and secure applications software by introducing processes and tools to help strengthen SDLC practices.
CMMC Audit Readiness – led 7 initiatives to help various clients prepare for CMMC level 2 audit from initial assessment, to gap identification, to remediation planning and prioritization, to evidence artifacts collection, and audit preparation.
Financial Services Organization – led C-level team in defining a strategic technology modernization program and roadmap to move organization from hybrid on-prem/co-location/partial cloud posture to a strategic investment in cloud-native solutions across AWS and Azure platforms. Performed organization-wide skills and capabilities assessment and developed training roadmap for internal employees and upskill targets for new hires. Drove strategic workstreams across technology organization with velocity while addressing limiting dependencies and adjacent projects that needed rationalization to modernization program. Developed CIO Chief of Staff role and program. Supported and mentored new hire into role. Leveled up the ePMO program and process shifting toward a more strategic framing and orientation.
Spacecraft Design and Manufacturing Organization – led engagement to prepare satellite communications product manufacturing and operations program for ISO27001:2013 certification. Compliance program development and build out to ensure policy, process, and evidence artifacts met requirements. Planning and execution of controls and documentation remediation. Preparing organizational stakeholders for interactions with audit personnel. Organization successfully passed audit and received certifications.
Financial Services Organization – led engagement to establish and mature a Cybersecurity program to include completion of a broad organizational and technology assessment, development of a multi-year roadmap, and execution of program initiation and ongoing implementation. Results include quarter-over-quarter maturation of program, policies, practices and remediation and mitigation of identified risks.
Financial Services Organization – led engagement to deliver strategy and foundational architecture definition for a network segmentation project. Development of and presentation to executive steering committee a business case that led to approval in $2.3M in multi-year funding. Development of program and executive steering functions to enable effective governance for the initiative. Delivery of a multi-year program including technical delivery, organizational change management, vendor support, and technology procurement.
Wealth Management Organization – provided expert and detailed support related to a cybersecurity and privacy due diligence program being performed by a strategic vendor partner. Identification of steps to enhance and strengthen security and privacy processes and practices within a 90-day timeframe. Delivery of a multi-year roadmap to enhance and mature the cybersecurity and privacy programs. Led initial implementation efforts for most highly prioritized remediation and improvement targets.
Financial Services Company – led technology and organization transformation initiative working with C-level executive team. Focusing on delivery of strategic organizational structure, aligning technology plans around strategic investments and assets, addressing excessive operational and tactical workloads which limit the organization from progressing strategically, and delivering a refreshed technology roadmap.
Support C-Level teams in establishing governance and implementation programs for AI solution vetting and deployment of guardrails to guide committee-level decision making.
DISYS, Bellevue, WA
Jun – Aug 2019
CONSULTANT – SECURITY AND COMPLIANCE
Brief engagement to consult on NIST 800-53 Continuous Monitoring program for rationalization and efficiency. Focused on where the program had been tailored to generic federal expectations and where the work was manually intensive, costly and error prone. Additionally, provided strategic feedback on the broader information security program especially as it relates to stakeholder engagement and support.
Volt Solutions, St. Paul, MN
Oct 2017 – Feb 2019
SENIOR CONSULTANT – SECURITY AND COMPLIANCE
Established a team of five consultants to successfully perform cybersecurity risk assessments for post-market devices using FDA guidance and company information security policy.
Thomson Reuters, Eagan, MN
Nov 2015 – Mar 2017
DIRECTOR, INFORMATION SYSTEMS SECURITY OFFICER
Head of information systems security holding accountability for overall data security, integrity, availability, and privacy; security risk assessments for proprietary software products delivered to legal industry with an elevated focus on federal and state government accounts. Educated sales and marketing on information security features and merits of in-scope products, providing strategic input regarding capital business case decision points on investment in information security features and liaised with contract review department to interpret cybersecurity language ensuring well-informed decision-making regarding risk of acceptance or a potential need to negotiate terms.
Orchestrated thorough evaluations of legal technology solutions leveraging NIST 800-53 and NIST 800-171 for gap analysis and oversaw all third-party security assessments for the portfolio to support aggregated cybersecurity compliance with SOC2, ISO27001:2013, and other standards.
Spearheaded contract negotiations regarding RFP requirements and NIST/FEDRAMP/FISMA requirements.
Contributed to company’s bottom line boosting customer retention rates and expanding opportunities for new sales of legal technology solutions at the federal, state and local level by liaising with procurement department to address customer feedback / questions about security features, and publishing security white papers.
Thomson Reuters, Eagan, MN
May 2015 – Nov 2015
DIRECTOR, TECHNOLOGY GOVERNANCE AND QUALITY ASSURANCE
Project sponsor and owner for all Information Security initiatives including external audits for SOC2 achievement, development and delivery of security features and infrastructure tools, penetration testing, identification of security flaws, and remediation. Developed penetration testing program to identify and remediate possible security flaws prior to deployment and oversaw peak-usage production testing of software candidates to ensure new features would function at full scale.
Propelled Scale and Performance Assurance program to ensure quality, performance and velocity standards were maintained while adapting to increasing geography of new global and federated development organization.
Leveraged systems and software scanning capabilities to identify and remediate security risks within a scope of more than 250 software applications and 5,000 systems used by 250k+ unique users with uptime expectation of 24x7x365.
Maintained 100% on-time delivery of all scheduled software releases by advancing continuous build and deploy capabilities for an agile based SDLC within large-scale software development programs.
Optimized Data Center change management processes by redefining the role of Software BU function, resulting in enterprise-wide adoption.
Thomson Reuters, Eagan, MN
Aug 2014 – Apr 2015
DIRECTOR OF GOVERNANCE AND PLANNING - LATAM
Managed the integration of 17 acquired software delivery companies into the technology enterprise including corporate functions such as Finance and HR, merging with a single standard SDLC, and driving local efficiencies into each site while ensuring underlying systems, platforms and other technologies leveraged enterprise capabilities.
Thomson Reuters, Eagan, MN
Sept 2012 – Aug 2014
Thomson Reuters, Director – Technology Operations
Led operational delivery and excellence for multi-billion-dollar legal software platform including broad content management and orchestration built on java technology and legal SaaS application stack up built on .Net and various versions of restful API architecture. Uptime targets of .9999 consistently met. Led software release management program driving precision, clarity, and timeliness across monthly release activities.
PRIOR PROFESSIONAL EXPERIENCE
Thomson Reuters, Technology Manager
2008 – 2012
PA Consulting Group, IT Consultant
2007 – 2008
Circuit City Stores, Inc., IT Process Frameworks & Governance
2005 – 2006
United State Air Force – Air Traffic Controller
1991 – 1996
EDUCATION
Bachelor of Science in Psychology, minor in Military Science
Troy University
Troy, Alabama
PROFESSIONAL TRAINING
Certified Information Systems Security Professional - CISSP
2019
Cybersecurity and Privacy Law Certificate
2016