Francisco Igual

CEO

Campbell, California, United States32 yrs 3 mos experience
Highly Stable

Key Highlights

  • Over 20 years in Information Security and GRC.
  • Active participant in international standards bodies.
  • Leader in Cybersecurity risk management initiatives.
Stackforce AI infers this person is a Cybersecurity and GRC expert in the FinTech industry.

Contact

Skills

Core Skills

CybersecurityRisk ManagementGovernanceGrcData Management

Other Skills

Analytical SkillsStrategyBudget ProposalsRisk ComplianceBudgetingNISTRisk AssessmentCommunicationInterpersonal SkillsITGCInformation Security PolicySecurity PolicyVulnerability AssessmentSecurity ComplianceRegulatory Compliance

About

Information Security professional with more than 20 years of experience assessing, designing and building comprehensive GRC programs with local, regional and global reach. Focused on the Technology and FinTech industries, with deep understanding of information security regulatory requirements, risk management frameworks, information security standards and best practices. Senior leadership influencer, leader and motivator of technical and non-technical staff and partnership builder across business and technology stakeholders. Active participant in international standards bodies; enhancing and promoting information security standards as part of the PCI Board of Advisors and supporting the publication of thought leadership concepts with the ISACA Journal Committee. Professional Strengths • Development of Information Security Policies and Standards • Information Security Risk Management • Compliance with Domestic and International Information Security regulations • Information Security Controls Management (design, implement, monitor, refine) • Build and lead teams to drive positive change in the organization • Cross team collaboration and influence • Empower team members to thrive

Experience

Zscaler

Senior Director Cybersecurity Risk Management

Jul 2024Present · 1 yr 8 mos · San Jose, California, United States

Soaprojects, inc.

Cybersecurity GRC

Jan 2024Jul 2024 · 6 mos · Mountain View, California, United States

Career break

Professional development

Nov 2023Dec 2023 · 1 mo · San Francisco Bay Area

  • Sharpening the saw, reconnecting with family and myself while preparing for my next professional adventure.
  • Blogging CyberGRC concepts and approaches I’ve learned over the years, hoping to give back to the industry and most importantly challenge my own way of approaching Cybersecurity: https://cybergrc.blog

Workday

Senior Director Cybersecurity Risk Management

Jul 2020Nov 2023 · 3 yrs 4 mos · Pleasanton, California, United States

  • Leading Workday’s Cybersecurity Risk Management programs aimed to identify, measure and drive mitigation of Cybersecurity risks faced by the organization. Coaching people managers to achieve their full potential and to grow their teams within the Security and GRC domains.
  • Key results: High performing teams helping the business understand the impact of Cybersecurity risks and support them with the creation of mitigation strategies while keeping senior leadership engaged in decision making. Driving remediation of Security issues, by guiding the business on the prioritization of work based on impact and severity.
  • Leading Workday’s Cybersecurity Governance programs aimed to support security risks mitigation through enterprise wide strategies to set policy, educate workmates and measure effectiveness of security controls.
  • Key results: Creation and publication of policies, standards and guidelines to address key risks. Deployment of continuous education and awareness campaigns to elevate workmates knowledge around security controls. Execution of a ongoing controls assurance program to understand the effectiveness of controls and their impact on risk mitigation.
Analytical SkillsStrategyBudget ProposalsRisk ComplianceBudgetingNIST+9

Salesforce

Senior Director Information Security GRC

Aug 2018May 2020 · 1 yr 9 mos · San Francisco Bay Area

  • Led Salesforce initiatives to identify and address security control breakdowns.
  • Key results: Designed a controls monitoring program to rely on automation for controls effectiveness validation. Drove controls standardization by promoting centralized processes and controls. Built a streamlined process, tools and governance structure for Security Issues and Exceptions Management. Mitigated Security & Compliance risks by driving faster closure of issues & detailed analysis of security exceptions.
  • Led the Security GRC Data Management initiative
  • Key results: Key process and data identified & documented. Defined next phased for data classification and management.
Interpersonal Skills

Pci security standards council

Member of the Board of Advisors of the PCI Security Standards Council

May 2011Jul 2018 · 7 yrs 2 mos

Analytical SkillsStrategyBudget ProposalsRisk ComplianceBudgetingCommunication+9

Paypal

Senior Manager, Technology Risk & Security Compliance Management

Aug 2009Jul 2018 · 8 yrs 11 mos

  • Designed and led improvements to the Information Security GRC program; ensuring information security standards are inclusive of domestic and international regulatory standards (NIST, ISO, PCI, etc.) and obligations (NY DFS, CSSF, etc.), controls are designed to comply with those defined standards, external audits and assessments are completed effectively, resolution of control gaps is timely achieved, controls’ effectiveness across platforms is monitored and operational rhythms are supported by proper GRC tools.
  • Built from the ground up, the Technology Risk Management program for the Chief Technology Officer organization; designed to identify, mitigate and monitor technology risks in alignment with the Enterprise Risk and Compliance framework.
  • Established and operationalized a wide enterprise initiative to assess processes and technology against PayPal Information Security standards, identifying controls owners, consolidating implemented controls and driving remediation of acknowledged gaps.
  • Created a controls management framework to prioritize information security controls monitoring mechanisms and testing frequency based on Inherent Risk, Control Effectiveness, Scope of Applicability, Criticality of Data and Viability of Automated Monitoring.
  • Operationalized an Issues Management program to address information security control breakdowns, partnering with Internal Audit, ERCS, Privacy, Legal, Technology and Product to drive proper and timely remediation and validation of controls.
  • Defined Objectives and Key Results (OKR) metrics for the Security Compliance and Issues Management teams. Creating dynamic data driven dashboards for operational consumption and leadership decisions making.
  • Hand-picked by Senior Leadership to participate in PayPal’s Emerging Leaders Program in Singapore.
Analytical SkillsStrategyInterpersonal Skills

Soaprojects, inc

Manager, Information Technology Assurance

Jul 2008Aug 2009 · 1 yr 1 mo

  • Performed Information Technology General Controls optimization projects based on AS5 guidelines for Internet and Financial organizations; optimizing time and cost spent during internal and external testing of controls.
FinTechAnalytical SkillsStrategyBudget ProposalsRisk ComplianceBudgeting+10

Intuit

External Consultant, Information Technology Assurance

Mar 2008Jun 2008 · 3 mos

  • • Assessed adherence of company’s access controls to the SAS70 standard. Including scope determination, controls design, user access rights evaluation, clean up and establishment of new access management processes.
Security ComplianceITGC

Isaca

Journal and CobIT Committees member

Jan 2007Nov 2020 · 13 yrs 10 mos

  • Reviewed Journal articles before publishing.
Analytical SkillsStrategyBudget ProposalsRisk ComplianceBudgetingCommunication+5

Pricewaterhousecoopers

Manager, Information Technology Assurance

Jan 2007Mar 2008 · 1 yr 2 mos

  • • Led Information Technology General Controls engagements supporting integrated financial audits, defining technology scope, driving budget decision making, coordinated resource allocation, supervised assessment execution and results quality.
Security ComplianceITGC

Deloitte

Senior Manager, Information Technology Risk Consulting

Jan 2002Dec 2006 · 4 yrs 11 mos

  • Led information security controls readiness assessments for Technology, Financial and Manufacturing clients in various markets, including North America, Latin America and Europe.
  • Led the implementation of the Human Resources Management System for the Mexican Federal Government. Led the implementation of network security controls for the Mexican IRS including the Security Operations Center. Led the Information Classification for the Mexican SEC based on the ISO 17799 standard and governmental regulations.
  • Acted as the liaison point with solution providers such as Microsoft, Seguridata, Mercury Interactive and HP to drive business development opportunities.
Security Compliance

Arthur andersen & co.

Manager, Information Technology Risk Consulting

Sep 1998Jan 2002 · 3 yrs 4 mos

  • Led Information Technology General Controls audits for Financial, Hospitality and Manufacturing clients.
  • Led Information Technology consulting services such as, information security assessments, disaster recovery planning (DRP), application systems integrity and control reviews, and security architectures definitions.
  • Led the creation of Information Security Policies & Procedures for the Central Bank of Mexico. Led Information Security Assessments for the National Bank of Costa Rica and the International Bank of Costa Rica based on the ISO 17799 standard.
Security Compliance

Ddemesis

Manager, Technology and Education

Sep 1993Aug 1998 · 4 yrs 11 mos

  • Led the Technology training division for company’s personnel and clients. Built strategic alliances with software vendors to drive knowledge sharing and training opportunities for the company.
  • Formed and led a software development quality assurance (QA) team, building a standardize frameworks for developing, testing and delivering products to market. Led development of an ERP for a media planning organization. Led development of an ERP for a brokerage firm.

Education

Harvard University

Certificate — Managing Risk in the Information Age

Jan 2019Jan 2019

Instituto Tecnológico Autónomo de México

MBA

Jan 2002Jan 2005

Instituto Tecnológico Autónomo de México

Diploma — Development of Managerial Skills

Jan 1997Jan 1998

Universidad La Salle, A.C.

BS — Bachelor of Cybernetics Engineering and Computer Science

Jan 1991Jan 1996

Stackforce found 100+ more professionals with Cybersecurity & Risk Management

Explore similar profiles based on matching skills and experience