Bryan Zimmer

DevOps Manager

San Francisco, California, United States29 yrs 2 mos experience
Highly Stable

Key Highlights

  • Expert in building company-wide security programs.
  • Achieved ISO 27001 and SOC 2 compliance.
  • Led Zero Trust architecture implementation at Netflix.
Stackforce AI infers this person is a seasoned security leader in the SaaS industry with expertise in compliance and risk management.

Contact

Skills

Core Skills

Information Security ManagementSecurity PolicySecurity Architecture DesignInformation Security

Other Skills

ISO 27001SOC 2GDPR complianceVulnerability ManagementIncident ResponseSecurity EducationSecurity TrainingZero Trust ArchitectureNetwork SecuritySecurity AwarenessCloud ComputingProject ManagementComputer SecurityVulnerability AssessmentPenetration Testing

About

Security leader with proven expertise building modern company-wide security programs, with a focus on business enablement, operations, and empathy. Trusted executive and customer advisor, and partner to internal teams including Sales, Legal, and Engineering.

Experience

29 yrs 2 mos
Total Experience
3 yrs 9 mos
Average Tenure
1 yr 3 mos
Current Experience

Nvidia

Security

Mar 2025Present · 1 yr 3 mos

Gretel

Head of Security

Mar 2023Mar 2025 · 2 yrs

  • Built and led company-wide security program and team known for responsive and approachable support. Created a security-conscious company culture, with embedded security champions across the organization.
  • Achieved ISO 27001, SOC 2, and GDPR compliance. Implemented policies, procedures, and technical controls. Lead compliance efforts and yearly audits.
  • Met with major customers to discuss details of the security program and completed customer security questionnaires, enabling the business to rapidly close deals.
  • Advised business on risk and conducted reviews for Third Party Risk Management program.
  • Worked with General Counsel on customer contract reviews.
  • Conducted daily security operations including administration, monitoring, and response on all security tools. Toolset included Crowdstrike, Kandji, Google Security Command Center, Netsparker/Invicti, Github, and others.
  • Lead Vulnerability Management and Incident Response programs.
  • Delivered customized security education and outreach.
ISO 27001SOC 2GDPR complianceVulnerability ManagementIncident ResponseSecurity Education+2

Humu

Head Of Security

Apr 2018Feb 2023 · 4 yrs 10 mos

  • Created and oversaw the organization's security program, building a team across the company that obtained ISO 27001 and SOC 2 certifications. Established and maintained robust policies, processes, and technical safeguards. Directed compliance initiatives and managed recurring audit activities.
  • Engaged directly with key clients to present the security framework and handle security questionnaires, helping to accelerate the sales process.
  • Provided strategic guidance on risk matters and carried out assessments as part of the Third Party Risk Management efforts.
  • Collaborated with legal counsel to review customer agreements from a security perspective.
  • Managed day-to-day security operations, including configuration, surveillance, and incident handling across a range of security tools such as Crowdstrike, Kandji, Obsidian, Google Security Command Center, Netsparker/Invicti, and Github.
  • Led programs focused on vulnerability remediation and incident response.
  • Created and delivered tailored security training and awareness initiatives.
  • Set up and maintained physical security systems, including video surveillance and access badge infrastructure.
ISO 27001SOC 2Vulnerability ManagementIncident ResponseSecurity TrainingInformation Security Management+1

Netflix

Senior Security Engineer

Mar 2014Nov 2017 · 3 yrs 8 mos

  • Successfully moved enterprise to LISA, one of the first Zero Trust architectures outside of Google. Directly responsible for driving entire project including devising strategy, designing security architecture, coordinating multiple teams, setting timelines, communication, marketing, and evangelism.
  • Set strategic direction for global endpoint and network security. Socialized significant changes via collaboration, debate, and company-facing memos. Evaluated, implemented, and administered global endpoint and network security toolset. Products included Carbon Black, SentinelOne, Cyphort, ProtectWise, Palo Alto Networks, Elasticsearch, and Kibana.
  • Assisted in creation of vendor security review program and conducted reviews.
  • Provided risk assessment and security guidance to teams across the enterprise.
  • Conducted incident response activities including network and host forensics.
  • Generated content for security awareness training.
  • Provided guidance and feedback to Venture Capital firms and numerous security startups.
  • Served on Customer Advisory Boards for Cyphort and SentinelOne.
Zero Trust ArchitectureNetwork SecurityIncident ResponseSecurity AwarenessSecurity Architecture DesignInformation Security

Barclays global investors

Security Engineer

Jul 2007Apr 2008 · 9 mos

University of california, santa cruz

Senior Security Engineer

Apr 2006Feb 2014 · 7 yrs 10 mos

United states department of defense

Security Specialist

Feb 2002Mar 2006 · 4 yrs 1 mo

Gloryworks corporation

Network and Systems Architect

Jan 1999Jan 2002 · 3 yrs

Bethany university

Director Of Student Computing

Jul 1996Sep 2000 · 4 yrs 2 mos

Education

California State University, Monterey Bay

BS

Stackforce found 100+ more professionals with Information Security Management & Security Policy

Explore similar profiles based on matching skills and experience