Ralph Aboujaoude Diaz

CEO

United Kingdom20 yrs 3 mos experience

Key Highlights

  • Led global GRC strategy for a major healthcare company.
  • Pioneered cybersecurity initiatives across diverse industries.
  • Established a global Intelligent Automation program.
Stackforce AI infers this person is a Cybersecurity and Governance expert with extensive experience in Healthcare and Manufacturing sectors.

Contact

Skills

Core Skills

Governance, Risk, And ComplianceGrc StrategyCybersecurityCybersecurity GovernanceAutomation

Other Skills

Technology QualitySOX programmeQuality, Risk, and Compliance servicesComputer System ValidationIT Management SystemAuditRisk ManagementCybersecurity programIndustrial/OT cybersecurityRisk treatment strategySecurity by designCybersecurity championDigital TrustCybersecurity researchData-driven analysis

About

Follow me if you are looking for a sarcastic and funny perspective on technology, workplace, cybersecurity, automation and AI. The statements, views, or opinions expressed in my LinkedIn profile and related articles represent my own views and not necessarily those of my employer.

Experience

Haleon

Global Head - Digital & Tech Governance, Risk, and Compliance

Sep 2025Present · 7 mos · London Area, United Kingdom

  • I currently lead Governance, Risk, and Compliance (GRC), including the Technology Quality area, within Haleon’s global Digital and Technology organisation. As a member of the Digital and Technology leadership team, my role influences Haleon-wide initiatives through the development and execution of GRC strategy. I provide governance over how technology products are delivered across Haleon, ensuring they are designed and implemented in a compliant manner, with all regulatory and compliance requirements fully considered and adhered to.
  • My role is accountable for:
  • Defining and leading the Digital and Technology GRC strategy, including the IT Management System and Computer System Validation/Assurance processes. I also lead and deliver Haleon-wide GRC transformation initiatives, focused on simplifying and enabling compliance across Digital and Technology.
  • Leading Haleon’s Technology SOX programme, working closely with external audit partners and internal finance leadership, including the CFO, Financial Controller, and Head of Finance Risk. I am accountable for the development of all SOX documentation and regularly present to the Haleon Audit and Risk Committee.
  • Providing Quality, Risk, and Compliance (QRC) and Computer System Validation (CSV) services across Digital and Technology teams, ensuring adherence to all applicable regulatory and compliance requirements, including SOX, GxP, Privacy, PCI-DSS, Anti-Bribery and Corruption (ABAC), Sanctions, Responsible AI, and Generative AI.
  • Establishing and overseeing the Technology Internal Controls Framework, and leading compliance and risk governance forums across Digital and Technology.
Governance, Risk, and ComplianceTechnology QualityGRC strategySOX programmeQuality, Risk, and Compliance servicesComputer System Validation

Philip morris international

Global Head - R&D and Operations Cybersecurity

Jun 2023Sep 2025 · 2 yrs 3 mos · London, England, United Kingdom

  • Acting as the primary responsible for first line of defense functions, I led PMI’s global cybersecurity program and BAU services across R&D and Operations business units (covering Product Innovation, Product Engineering, Quality Regulatory Affairs, Manufacturing Engineering Services, Manufacturing Solutions and Services, Supply Chain and Track & Trace Solutions).
  • I was responsible of the planning, orchestration and delivery of a global Industrial/ OT cybersecurity program across all PMI factories, in alignment with ISA/IEC 62443 series of standards.
  • I was also in charge of designing and executing the cybersecurity program for Product to fortify “Device to Cloud” defense for smoke-free portfolio, which includes heated tobacco (IQOS), e-vapor, and oral smokeless products.
  • My role, also acting as the global BISO and working closely with the CISO, was to bridge the gap between security and business interests, contributing to security awareness and overseeing the strategy implementation across all areas of the business units. As the cybersecurity champion for the business, my responsibilities covered a wide range of activities (from project to BAU), including defining and prioritizing risk treatment strategy, developing capabilities across the cybersecurity value chain, orchestrating the execution of risk treatment activities, and embedding “security by design” across processes and technologies.
Cybersecurity programIndustrial/OT cybersecurityRisk treatment strategySecurity by designCybersecurity championCybersecurity

Hfs research

Vice President & Practice Leader - Digital Trust & Cybersecurity

Aug 2021Jun 2023 · 1 yr 10 mos · London, England, United Kingdom

  • Built and led the Digital Trust and Cybersecurity research practice. I successful managed to setup a global research team and delivered a wide range of initiatives for global service providers and enterprise clients.
  • I don’t look at cybersecurity as a tech-only puzzle. My research agenda gravitates around two domains, augmentation and protection, and focuses on six core thematic research pillars: the remit and goals of the CISO in the hyperconnected world, reducing the IT risk and security skill gap, augmenting IT and security functions (across the 3 lines of defense) with intelligent solutions, trusting the cloud security environment, managing identity and access risks, and responding to modern security threats.
  • My custom research projects allowed me to work very closely with cybersecurity executives in Global 2000 enterprises. The goal of such projects was to provide data-driven analysis and strategic recommendations in areas such as ransomware, zero trust, digital identity, next generation SOC, cyber risk quantification, cloud security, Security-as-a-Service (SECaaS) models, GRC, Cyber Ranges, and security automation and orchestration.
Digital TrustCybersecurity researchData-driven analysisStrategic recommendationsCybersecurity

Gsk

3 roles

Senior Director - Core Tech Strategy and Transformation

Promoted

Sep 2020Aug 2021 · 11 mos

  • I was part of the Core Tech Strategy & Transformation Leadership Team in the capacity of Senior Director. Working closely with the CISO leadership team, my key objective was to build/design/operate a new global Cybersecurity and Control Governance function aimed at managing and governing cybersecurity risks across GSK corporate and business-unit specific areas.
  • Led the design, build and deployment of a global environment to manage privileged access across IT and OT environments (supported by CyberArk, SailPoint, Splunk and Imperva solutions).
  • Led the deployment of new breed of managed security services (looking beyond cybersecurity-centric services, delivered through traditional MSSP models, and deploying a more evolutionary model that unifies cybersecurity and compliance “by design”).
  • Designed the Cybersecurity Target Operating Architecture and Model for Haleon, the new consumer healthcare company.
  • Led the global Security Governance program with an “automation-first” mindset. I managed the deployment of advanced automation and monitoring mechanisms via different technological enablers (dedicated off-the-shelf solutions, custom build engine, RPA, Intelligent Automation, ML) to continuously monitor and measure the operating effectiveness of existing risks and controls.
Cybersecurity GovernanceManaged Security ServicesAutomationPrivileged Access Management

Director - Core Tech Strategy and Transformation

Promoted

Oct 2019Aug 2020 · 10 mos

Director - Global Applications and Development

Jan 2017Sep 2019 · 2 yrs 8 mos

  • My role was to setup a global GRC function to manage risks and controls governing the most critical processes supported by global applications at GSK (such as the global ERP system, SAP, that supports all core operations from manufacturing to finance). My initial goal was to support the deployment of security framework across all regions and implement a “GRC by design” template to ensure risk and compliance standardization across global and BU-specific IT and Business functions.
  • I have also led the design and deployment of one of the largest global Intelligent Automation programs across all GSK Business Units (including the implementation of a global Automation Centre of Excellence and enablement of regional scalable Automation Deliver Hubs).

Ey

Senior Manager - IT Advisory Services

Jul 2013Sep 2016 · 3 yrs 2 mos · London, England, United Kingdom

Pwc

Senior Manager - Risk Advisory Services

Apr 2010Jun 2013 · 3 yrs 2 mos · London, England, United Kingdom

Ey

Manager - Technology Security and Risk Services

Sep 2006Mar 2010 · 3 yrs 6 mos · Madrid, Community of Madrid, Spain

Kpmg

Senior Consultant - IT Audit Services

Apr 2005Aug 2006 · 1 yr 4 mos · Madrid, Community of Madrid, Spain

Stackforce found 100+ more professionals with Governance, Risk, And Compliance & Grc Strategy

Explore similar profiles based on matching skills and experience