Post Job Free
Sign in

Security Governance & Risk Management Leader

Location:
Pembroke, MA
Posted:
August 25, 2026

Contact this candidate

Resume:

Diana DeMarco

Pembroke, MA

781-***-****

*******@*******.***

SUMMARY With more than 20 years of leadership experience in security governance, risk management, and compliance, I excel at building, implementing, and overseeing complex security programs for diverse organizations. I am highly skilled in risk assessments, policy and plan development, business continuity planning, incident response, internal control testing, audit coordination, and third-party vendor risk management. My expertise spans major frameworks and standards including SOX, PCI, HIPAA, SSAE18, ISO 27001, SOC1/SOC2, FedRAMP, GDPR, and NIST, supported by advanced certifications such as CISA, CISM, CGEIT, CRISC, and CHSP. My career includes designing federal-level security programs, leading large-scale data center transitions, implementing vulnerability and access control programs, and driving remediation efforts that have earned clients significant regulatory award fees. I am a conscientious, results-driven security leader with deep experience managing remote teams, subcontractors, and cross-functional security operations across healthcare, financial, government, and enterprise environments. CERTIFICATIONS Certified HIPAA Security Professional (CHSP), Certified Information Security Auditor

(CISA), Certified Information Security Manager (CISM), Certified in The Governance of Enterprise IT (CGEIT), Certified in Risk, and Information Systems Control (CRISC). Currently pursuing AAISM - AI security credential. SIGNIFICANT ACHIEVEMENTS

• Risk program development, implementation, and ongoing compliance monitoring

• Design and implementation of Federal level Security Program

• Mitigated audit findings for Medicare client earning them CMS/HHS over a million-dollar award fee for the first time in their history

• Security lead for Federal Data Center relocation/transition

• Security lead for data center DR site development project

• Implementation of security incident management programs

• Implementation of access control program

• Implementation of account internal control and testing program

• Offsite storage secure records transfer/consolidation project (Medicare health records)

• Y2K project coordination – Completed with no issues

• ISO 27001 program implementation and creation of supporting process documentation

• Audit support (SOX, PCI, HIPAA, SSAE18, ISO 27001, SOC1, SOC2, FedRAMP, and GDPR) – successful outcomes

• Vulnerability management program implementation

• CrowdStrike implementation for a large healthcare client EXPERIENCE Cyber Security Consulting Freelance, (remote worker) 02/03/2025 – Present Cyber Security Consultant

• Perform internal risk assessments, author policy and procedure documents, coordinate external audits, support incident response, and other general security support based on customer need.

EXPERIENCE Federal Reserve Bank, Boston, MA

07/08/2024 – 01/07/2025 IT Compliance & Risk Management Specialist In this role, my primary function is to perform security control assessments utilizing FRB SAFR policy and risk framework. These assessments are performed for each in scope boundary with results driving the Authority to Operate (ATO) initiative. Additionally, performed the annual policy and procedure review and update, as well as review and update of the Business Continuity Plan. EXPERIENCE ATOS/Eviden, (remote worker)

12/15/2022 – 10/31/2023 Cyber Security Service Delivery Director, Client Digital Security, North America. Functional responsibility for a large healthcare client for the Boundary, IAM, Platform/Endpoint, Security Consultancy, Splunk Engineering group, CyberArk Engineering group, Proofpoint Engineering Group, Third Party Risk Team, and Vulnerability Management Group.

• Antivirus coverage/compliance

• Identity and access management

• Boundary services

• Third Party Risk Assessments for Federal Government customers

• Risk and POA&M tracking and reporting

• Security consulting services

• Audit support (SOX, PCI, HIPAA, SSAE18, ISO 27001, SOC1, SOC2, FedRAMP, and GDPR)

• Tenable vulnerability scanning

• Business continuity planning, testing, and support

• Security incident management

• Document security incident response protocol via playbooks

• Weekly, monthly, and quarterly reporting on all security services

• Primary interface with customer CISO and Security Management

• Service Now ticket management for all security teams

• SLA management

• Time management and approval

• P&L management

• Oversight for maintaining security tools (Splunk, CrowdStrike, CyberArk, Proofpoint, Tenable) EXPERIENCE ATOS, (remote worker)

02/01/2021 – 12/14/2022 CISO, Client Digital Security, North America

• Primary security contact for the client CISO

• NIST risk framework implementation and ongoing compliance monitoring

• New and existing vendor risk assessments

• Focused risk assessments (new IT tools)

• Policy and procedure development

• Account security plan development

• GAP analysis of SOW and client security policies

• Audit support (SOX, PCI, SSAE18, IHIPAA, ISO 27001, SOC1, SOC2, FedRAMP, and GDPR)

• Coordination and compliance tracking for required security awareness training

• Business continuity planning, testing, and support

• Security incident response support

• Internal control program development internal control testing EXPERIENCE ATOS, (remote worker)

3/2016 – 01/2021 Director, North America Client Security Management (Healthcare Market Lead) Direct the security governance activities of 20+ Client Security Managers in support of 100+ client accounts. The client industries supported include Manufacturing, Financial, Healthcare and Life Sciences, Entertainment, Transportation, Government, Energy, Technology and Education. Oversight responsibility for the Client Security Manager responsibilities listed below. The single point of escalation and accountability for Atos account team management and all clients for all matters related to Security. This oversight is for the Client Security Managers and the responsibilities listed below. EXPERIENCE ATOS, (remote worker)

8/2012 – 2/2016 Client Security Manager

• Security governance for several external Atos clients

• Audit support (SOX, PCI, SSAE18, HIPAA, ISO 27001, SOC1, SOC2, FedRAMP, and GDPR)

• Risk assessments and risk management program oversite

• Risk and POA&M tracking and reporting

• GAP Analysis of SOW and client security policies

• Account security plan development

• Security baseline reviews

• Security incident management oversite

• Business continuity planning, testing and support

• Implementation of security metrics and reporting

• Implementation of internal control testing program

• Security focal for all internal and external audits

• Interpreting and communicating security and regulatory requirements

• Coordination of security awareness training for account teams

• Creation of security documentation for assigned customer accounts

• Process improvements

• Mentoring/training of new Client Security Managers EXPERIENCE HEWLETT PACKARD (HP), Hingham, MA

2009–2012 National System Security Manager (CMS Medicare Contractor)

• Implementation and senior level oversight for security program

• Risk program development (remediation, tracking, and reporting)

• Risk and POA&M tracking and reporting

• Ongoing oversight and management for various subcontract organizations including development of Statement of Work, response for proposal solicitations and operating level agreements

• System security plan development

• Privacy, security, awareness, and training program development

• Business continuity plan/DRA development and testing

• Acting backup for Compliance Officer

• Business continuity planning, testing and support

• Incident response program including breach prevention and notification

• Paper and media sanitization program

• Physical and logical access control program

• Support for the compliance/ethics function and liaison to the Compliance Officer

• Preparation and coordination of internal and external audits, specifically, FISMA, FedRAMP, NIST, HIPAA, SSAE-18, SOC 1 and 2, ISO 27001, Office of Inspector General and CMS Business Partners System Security Program and Health and Human Services standards

• Remediation of potential and/or resulting findings, corrective action plan development, tracking and testing

• Implementation and ongoing maintenance of internal control and testing program

EXPERIENCE ELECTRONIC DATA SYSTEMS (EDS), Hingham, MA 2003 – 2009 National System Security & Facility Manager (CMS Medicare Contractor - NHIC)

• Plans, directs, and coordinates all information and physical security activities. Evaluates and monitors the effectiveness of existing security procedures to ensure corporate wide understanding and compliance with established policies. Develops and modifies procedures that protect corporate and Medicare assets and adhere to established security policies. Participates in the protection of confidential customer data and corporate information such as trademarks, logos, and copyrights through the monitoring of information releases and periodic function reviews. Oversee the administration and coordination of all electronic data security activities for all NHIC locations. Performs reviews of remote site security practices to ensure compliance with information and physical security procedures. Coordinates the communication and education of security practices between remote sites and maintains consistency of established security procedures.

• Coordinating security activities for all components of the organization. This includes remote sites and two warehouse facilities. The sites include Biddeford, Maine, Hingham, Massachusetts, Chico, California, Marysville, California, and Los Angeles, California

• Development and coordination of annual employee security awareness training program

• Budgeting for the information systems security and facilities departments

• Reviewing compliance with all components of customer and corporate security requirements and reporting vulnerabilities to management

• Oversight of facility compliance requirements/projects

• Establishing an incident response capability, investigating systems security breaches, and reporting significant problems to Management, and Customer.

• Confirming that technical and operational security controls are incorporated into new IT systems by participating in all business planning groups and reviewing all new systems/installations and major changes

• Ensuring that information and physical systems security requirements are included in new business proposals and Subcontracts involving the handling, processing, and analyzing of Medicare data

• Coordinating all external evaluations of the Business Partners System Security Program.

• Conducting annual risk assessment and system security plans.

• Ensuring that an operational business continuity and contingency plans are in place and tested.



Contact this candidate