SEBASTIAN DRYWA
SECURITY EXECUTIVE • AI & AGENTIC SYSTEM SECURITY • DETECTION, RESPONSE & ENTERPRISE RISK
Cary, IL **************@*****.*** LinkedIn
CISSP • CISM • CCSP • CompTIA SecurityX • CompTIA PenTest+
PROFESSIONAL SUMMARY
Security leader with 14+ years running programs across multi-cloud (AWS, Azure, GCP) and SaaS-heavy environments. Built two security functions from scratch and currently own a $1.6M program covering governance, engineering, and 24x7 detection and response, still stepping in as incident commander when it counts. Early mover on AI security: wrote the enterprise AI governance framework, ran pre-approval risk assessments on agentic AI coding tools and AI agents, and work with OWASP LLM and Agentic Top 10, NIST AI RMF, and MITRE ATLAS in practice, not just on slides. Led distributed teams across the US, Europe, and India. Known for making security a business enabler: the goal is to make the right thing easier than the risky thing, not to be the department of no.
SELECTED ACHIEVEMENTS
•Hands-On Incident Command: Serves as incident commander for high-severity events, personally leading triage, containment, and recovery for active ransomware and targeted phishing campaigns before business disruption, protecting 500+ users and a 1.5M-member data ecosystem.
•Global Security Operations & ISMS: Owns the ISMS and the security tool portfolio across SIEM/SOAR, EDR/XDR, identity, endpoint/MDM, vulnerability management, and DLP, running 24x7 detection and response through an internal team and MDR partner, aligned to ISO 27001, SOC 2, and NIST CSF across a multi-cloud, multi-OS environment.
•Distributed Global Team Leadership: Built and led security teams from the ground up, twice, and previously built and trained an India-based NOC as lead engineer, establishing coverage across US, European, and Indian time zones.
•Security Program Build & Cloud Transformation: Built NAR's security function from zero as the first security hire, growing it into a $1.6M program with an internal team and two managed-service partners covering 24x7 operations. Kept evolving controls as the business moved from on-prem to cloud, reworking identity, data protection, and monitoring along the way, and consolidated a fragmented vendor portfolio into one managed platform while cutting spend about 20%.
•AI Security & Governance: Wrote the enterprise AI acceptable-use and governance framework, ran risk assessments and conditional approvals for agentic AI coding tools and low-code AI agents before rollout, and advises the CIO, C-suite, and Board on cyber risk and where AI changes the threat model.
CORE COMPETENCIES
Security & Infrastructure Tooling: Splunk & Rapid 7 (SIEM/SOAR) • Microsoft Defender & Defender for Cloud (EDR/XDR, CSPM) • Rapid7 (Vulnerability Mgmt) • Proofpoint (Email Security) • Zscaler (Secure Web Gateway, DLP) • Jamf & Intune (MDM) • Okta & Entra ID (Identity) • CyberArk & Delinea (PAM) • Automox (Patch Mgmt)
Governance, Risk & Compliance: ISMS / ISO 27001 • Enterprise Risk Management • Third-Party & Supply-Chain Risk • Security Policy & Standards • Audit Readiness • Vendor & Security Assessments
Security Operations & Architecture: Detection & Response • Incident Command & Crisis Management • Threat Intelligence • Vulnerability Management • IAM & Zero Trust • DevSecOps / SDLC Security • Agentic AI & LLM Security (OWASP LLM/Agentic Top 10, NIST AI RMF, MITRE ATLAS) • MTTD/MTTR
Cloud & Technical: AWS • Azure • GCP • Multi-OS (Windows, macOS, Linux) • Firewalls • IDS/IPS • Encryption • OWASP
Frameworks & Compliance: NIST CSF 2.0 • ISO 27001 • SOC 2 • PCI-DSS • HIPAA • GDPR/CCPA • CIS 20 • FERPA • GLBA
PROFESSIONAL EXPERIENCE
Cybersecurity Director National Association of Realtors, Chicago, IL Aug 2021 – Present
Security leader for a 1.5M-member national organization running on 20+ cloud workloads and 20+ SaaS platforms. Own a $1.6M program and the full ISMS: governance, enterprise risk, third-party risk, detection and response, incident response, tooling, and vendor strategy. Report to the CIO and brief the Board on cyber risk and where to invest.
•Incident Response Leadership (Hands-On): Serves as incident commander across an internal team and MSSP, personally leading detection, triage, and containment of active ransomware and targeted phishing campaigns before business disruption; drives post-incident reviews into root-cause findings and measurable improvements.
•Security Tooling & Infrastructure Ownership: Owns the security tool portfolio spanning Splunk and Microsoft Sentinel (SIEM), Microsoft Defender, Rapid7, Zscaler, Proofpoint, Jamf/Intune, and Okta/Entra ID with CyberArk and Delinea PAM, across a multi-cloud (AWS, Azure, GCP) and multi-OS environment, driving standardization, configuration baselines, change management, and lifecycle discipline.
•Operational Standards & Process Discipline: Established runbooks, escalation paths, and change-management practices; aligned incident response plans and playbooks to NIST CSF and ISO 27001 with regular testing and continuous-improvement cycles.
•Third-Party Risk, Vendor & Partner Management: Conducts vendor security assessments and due diligence across the supply chain; restructured the vendor portfolio from 4 contracts ($249K/yr) to a single managed platform ($200K/yr), managing MSSP, MDR, and vulnerability-management relationships while expanding coverage and reallocating internal capacity to strategic priorities.
•Risk, Audit & Compliance: Owns the ISMS and enterprise risk framework, maintaining security policies and standards and conducting regular risk assessments across hybrid cloud and SaaS environments, ensuring continuous audit readiness against ISO 27001, SOC 2, PCI-DSS, and NIST.
•Security Culture & Awareness: Reduced phishing susceptibility by 67% (30% to under 10%) through a targeted, behavior-based awareness program driving measurable behavior change.
•Executive Reporting & AI Governance: Delivers risk briefings and investment recommendations to the CIO and Board. Wrote the enterprise AI use and governance framework, ran the risk assessment and conditional approval for an agentic AI coding tool, tested low-code AI agents before deployment, and built controls for securing AI-enabled workflows.
IT Security Manager McHenry County College, Crystal Lake, IL Nov 2019 – Aug 2021
Founded and led the institution's cybersecurity program supporting ~9,000 students and 550 staff. Full ownership of strategy, operations, team building, budget, and compliance; no security function existed prior to this role.
•Security Program & Operations Build: Established the institution's first formal security function, standing up operating processes, monitoring, and governance aligned to NIST, ISO, PCI-DSS, FERPA, and GLBA that continue to run the program today.
•Compliance & Audit Leadership: Achieved PCI-DSS compliance for campus payment systems, eliminating all audit findings and reducing financial risk exposure across student payment infrastructure.
•Cross-Departmental Influence: Improved security effectiveness by 15% by partnering with IT, Finance, and administrative leadership to embed security practices into institutional operations.
IT Security Analyst Crate and Barrel, Northbrook, IL Nov 2018 – Nov 2019
Supported enterprise security operations across 114 retail locations and 7,500 employees in a multi-cloud environment (AWS, Azure, GCP).
•SIEM & Threat Detection Operations: Optimized SIEM and threat-intelligence workflows, improving detection fidelity, reducing alert fatigue, and enabling the security operations team to focus capacity on strategic threats.
•Multi-Cloud Identity & Governance: Standardized identity and access controls across AWS, Azure, and GCP, improving governance consistency and reducing identity risk across a globally distributed cloud environment.
•Security Automation: Developed automation for log analysis, IAM governance, and vulnerability remediation, reducing manual overhead and accelerating analyst response.
Information Security Technical Lead Roquette America, Geneva, IL Oct 2017 – Nov 2018
Led security initiatives during a major enterprise transformation supporting 100+ countries and ~11,000 employees across US, EMEA, and APAC.
•Global Security Infrastructure Deployment (US, Europe, India): Owned the deployment of F5 across US, European, and India-based sites, partnering directly with the India team to standardize application and network security controls across regions.
•Global Security Program Leadership: Directed security initiatives across US, EMEA, and APAC sites during enterprise transformation, advancing compliance posture, monitoring, and incident response at global scale.
•Cross-Regional Governance: Aligned cross-regional security operations under a unified governance framework, standardizing incident response across multiple regulatory jurisdictions.
•Infrastructure Security: Led firewall modernization, network segmentation, and perimeter hardening aligned to ISO 27001 and ITIL, reducing attack surface across globally distributed operations.
Network Engineer Roquette America, Geneva, IL May 2015 – Oct 2017
Designed and maintained secure LAN/WAN/DMZ environments supporting global network modernization.
•Global NOC Leadership (US & India): Served as lead network engineer while building and training Roquette's India-based NOC, establishing coverage and standardized procedures across US, European, and Indian time zones in a follow-the-sun model.
•Secure Infrastructure Foundation: Designed LAN/WAN/DMZ environments for regulated global operations, establishing the network security foundation for the organization's subsequent enterprise security transformation.
EARLIER EXPERIENCE
System Network Administrator — Merletto Inc., Aurora, IL 2014–2015
Computer Network Support Specialist — Power Construction, Chicago, IL 2012–2014
EDUCATION
Master of Science, Cybersecurity and Information Assurance — Western Governors University
Bachelor of Science, Cybersecurity and Information Assurance — Western Governors University
Associate of Applied Science, Computer Science (Network Administration) — Harper College
CERTIFICATIONS
CISSP CCSP CISM SecurityX PenTest+ CySA+ Security+ ITIL Foundation