Helen Nhan McCaffrey

CEO

San Francisco, California, United States11 yrs experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Proven expertise in cybersecurity and program management.
  • Led content assurance initiatives at TikTok.
  • Strong background in vulnerability management and risk assessment.
Stackforce AI infers this person is a Cybersecurity and Information Technology professional with expertise in vulnerability management and program execution.

Contact

Skills

Core Skills

SecurityProgram ManagementCybersecurityProject ManagementInformation SecurityVulnerability ManagementInformation Technology

Other Skills

General IT ControlsManagementComplianceGovernanceContent AssuranceAlgorithm AssurancePortfolio managementCyber ResiliencyIncident ResponseIdentity and Access ManagementInformation Security Risk ManagementProgram DesignOperationsSystem Vulnerability ScanningDatabase Vulnerability Scanning

About

"Put your heart, mind, and soul into even your smallest acts. This is the secret of success." (Swami Sivananda) "Let your eyes look straight ahead; fix your gaze directly before you. Give careful thought to the paths for your feet and remain steadfast in all your ways." (Proverbs 4:25-26) I enjoy exemplifying my diligent work ethic by aiming to exceed expectations and in pushing myself to always learn. I constantly seek ways in which I can maximize on value creation and I enjoy working in team settings. I thoroughly take joy in being challenged because I know that is where growth happens.

Experience

11 yrs
Total Experience
1 yr 9 mos
Average Tenure
1 yr 10 mos
Current Experience

Tiktok

Content and Algorithm Security Lead

Aug 2024Present · 1 yr 10 mos · San Francisco Bay Area

  • EU Digital Services Act
  • General IT Controls (access controls, change management, system monitoring) across 23 Articles
  • Management of Recommender Articles 27 & 38
  • Code of Conduct - Hate Speech
  • Code of Conduct - Disinformation
  • UK Online Safety Act
  • Recommender testing safety metrics
  • Content Assurance
  • Content Assurance teams work to establish controls, assess processes, and secure systems to prevent inauthentic and unauthorized influence on TikTok content. The Content Assurance team provides oversight and technical enforcement of controls on content-impacting tools and processes to ensure security and compliance. Our goal is to ensure the TikTok platform remains free from manipulation, especially implementing safeguards on our content algorithm, and promotion tools.
  • Governance (Operating Model, RACI, Program Management, Guidelines and Policies, Exceptions, and Escalations)
  • Compliance (Framework development and controls evaluation and remediation)
  • Learning and Development (E-learning development and roll out)
  • Promotion Compliance (Operations, Quality Assurance and Escalations, LLM automation and scaling)
  • Critical System Security (Access, Insider Risk, Penetration Tests, Vulnerability Management)
  • Algorithm Assurance (Training data, ML Models, Recommendation rules, Algo output analysis)
  • Content Investigations (elections and branding)
  • USDS partnership and build
  • Pillar Business Operations
  • Procurement (proposal review, Statement of Work review, supplier performance, sourcing and vendor selection, purchase requisition and purchase order, contractor onboarding, vendor management
  • Finance (pillar budget planning and management, cost optimization)
  • Headcount Management (Resource planning and management, job application creation, interview and candidate selection, onboarding)
  • Team wiki maintenance, capabilities catalogue, offsite planning, OKR and operating model
General IT ControlsManagementComplianceGovernanceContent AssuranceAlgorithm Assurance+2

Ey

3 roles

Cybersecurity Manager

Promoted

Jan 2023Jul 2024 · 1 yr 6 mos

  • Global Security Organization - Content Assurance - Technical Program Manager
  • Content Assurance Program Build
  • Global Security Organization - Security Execution and Performance - Technical Program Manager
  • Portfolio management of ~10 security projects
  • Security Execution and Performance program build (Business Operations, Program Management, Metrics and Reporting)
  • Business Operations standardization (Finance Management, Procurement, Staffing and Operations, and Security On-call Bot)
  • Security Tech industry review
  • Information Security Office, Chief Information Risk Officer (CIRO) Program Management
  • Assist CIRO and ISO team with company divestiture.
  • Cyber Resiliency and Risk (GRC, Disaster Recovery, Crisis Management, Business Continuity)
  • Security Operations (Incident Response, Vulnerability Management, Security Incident and Event Monitoring)
  • Identity and Access Management
  • Information Protection (Data Loss Prevention, Data Discovery)
  • Human Risk (Security Awareness and Phishing)
  • EY internal teams:
  • Executive Women's Forum - EY Representative (November 2023)
  • Cyber Program Transformation - Community Leader (July 2023 - July 2024) - Onboarding, People Engagement, SharePoint
  • Cyber Program Transformation - SharePoint Team Lead (Aug 2022 - July 2023)
  • City of Refuge - Business and Cyber representative/mentor (May 2022 - July 2024)
  • EY Americas - CyberHub Core Team Lead (Apr 2020 - February 2023)
Portfolio managementProgram ManagementCyber ResiliencyIncident ResponseIdentity and Access ManagementCybersecurity

Senior Cybersecurity Consultant

Oct 2020Jan 2023 · 2 yrs 3 mos

  • Information Security Risk Management, Program Management
  • Assisted with Application Security, SOX, Supply Chain OT, Records Information Management, eDiscovery project plan execution
  • Vulnerability Management, Project Management
  • Vulnerability Management, Gold Image Scanning
  • Vulnerability Management, Secure Configuration Baselines
  • EY internal teams:
  • Cyber Program Transformation - SharePoint Team Lead (August 2022 - July 2023)
  • City of Refuge - Business and Cyber representative (May 2022 - Present)
  • EY Americas - CyberHub Core Team Lead (April 2020 - February 2023)
  • Atlanta Cyber Circles Coordinator (October 2018 - December 2022)
  • Cyber Managed Service Vulnerability Management - Operations development (December 2020 - March 2022)
Vulnerability ManagementProject ManagementInformation Security Risk ManagementCybersecurity

Cybersecurity Consultant

Aug 2018Oct 2020 · 2 yrs 2 mos

  • Threat Exposure Management Team
  • Vulnerability Management, Program Design:
  • Assisted with the Global Vulnerability Management governance for one of the biggest producers of premium cars in the world
  • Assisted with updates to the Operating Model, Procedural Guidelines, RACI, Standard, Policy, Process Flow, Vulnerability Risk Ranking Standard and Remediation Timelines, and the Working Group Charter
  • Vulnerability Management, Qualys optimization
  • Vulnerability Management, Operations:
  • Improved the vulnerability posture for one of the world’s biggest manufacturer of commercial vehicles, working alongside 10+ different Markets globally
  • Provided concise vulnerability reports and conducted an in-depth analysis of the Market’s vulnerability posture by providing thorough recommendations on how to reduce the vulnerability count and the overall risk exposure
  • Vulnerability Management, Secure Baseline Standards:
  • Assisted with providing custom baseline policies for one of the top largest cable providers in the nation.
  • Configured policies for in-scope operating systems and technologies from the industry of leading benchmarks (i.e., CS level 1, NIST, etc.)
  • EY internal teams/projects:
  • TEM Intern Program Lead (May 2020 - August 2020)
  • EY Americas - CyberHub SharePointOnline team (Apr 2020 - February 2023)
  • Next Generation Security Operations - EY Buddy (Mar 2020 - August 2020)
  • TEM Knowledge Management Lead (May 2019 - August 2020)
  • Atlanta Counseling Family Onboarding Champion (Oct 2018 - August 2020)
  • EY Connect Day Volunteer Lead (2018)
Vulnerability ManagementProgram DesignOperationsCybersecurityProgram Management

Anthem, inc.

Information Security Analyst Intern

Jan 2018Aug 2018 · 7 mos · Greater Atlanta Area

  • Used innovative approaches that leveraged state of the art technologies and methodologies to evaluate and mitigate risk and vulnerabilities.
  • Vulnerability Management Team - System Vulnerability Scanning:
  • Utilized Qualys tool to scan pre-production servers (Intel, Linux, and Unix) from IBM
  • Generated reports as a form of case management for the Vulnerability Management team
  • Sent notice of certification, notice of conditional certification, and notice of remediation of servers in accordance to the service level agreements
  • Provided timely detection, identification, and alerting of vulnerabilities
  • Collaborated with System Admin to discuss security incidents
  • Tasks included: Daily Qualys check, Qualys Ticket Moves, and updating IPs for authentication scans
  • Vulnerability Management Team - Database Vulnerability Scanning:
  • Utilized Guardium to scan pre-production Oracle, DB2, Sybase, and SQL databases.
  • Completed database whitelist requests, data source decommissions and updates, Guardium clean up, updated password change scan group
  • Sent notice of certification, notice of conditional certification, and notice of remediation of databases in accordance to the service level agreements.
  • InfoSec Policy Management Team - Permanent Exception Project Resources Team:
  • Assisted in the management of security exceptions within Anthem to ensure compliance by following up with exception owners to assess the exception's necessity
  • Closed security exceptions
  • Assisted with walk through on how to refile the security exceptions
  • Anthem Newsletter Team:
  • Created, edited, and published news articles for the Anthem IT News Team through SharePoint, Word, PowerPoint, and Publisher
Vulnerability ManagementSystem Vulnerability ScanningDatabase Vulnerability ScanningInformation Security

georgia pacific

Information Technology Co-op

Feb 2017Jan 2018 · 11 mos · Atlanta, Georgia

  • Nominated for the ACT Tax Technology Award by Manager
  • Collaborated among a small technical team to discuss execution of projects in order to provide technical solutions for the GP Tax department
  • Combined analytical and problem solving skills to successfully operate the Varonis software which oversees employee's cyber behaviors over the past 20 years.
  • Strengthened and improved the cyber security of critical files and documents within a massive file server by overseeing access controls
  • Monitored permissions allowed on high priority folders and generating appropriate reports in a timely manner
  • Administered and revamped the companies GP Tax SharePoint website to enhance the user interface
Technical SolutionsCyber SecurityInformation TechnologyCybersecurity

Apple

Technical Advisor

Aug 2016Jan 2017 · 5 mos

  • Analyzed various troubleshooting procedures that involved software, hardware, environmental, and educational opportunities for iOS products
  • Applied critical thinking skills to efficiently probe with customers to understand and solve the problems while simultaneously guaranteeing customer satisfaction with friendly interpersonal communication
  • Utilized virtual guides, iCloud support applications, and knowledge based articles to assist in gaining proficiency and expertise
  • Worked from a virtual environment at home independently with minimal managerial supervision while ensuring that goals are met for the month and quarter
  • Assisted customers in the utilization, installation, and maintenance of their iOS devices and applications

Mf sushi

Server

Aug 2015Jan 2018 · 2 yrs 5 mos · Atlanta, Georgia

  • Worked in a fast paced environment while guaranteeing guest satisfaction with up to 6+ tables at one time; lead server in sales
  • Navigated the guests through the diverse menu which includes approximately 75+ menu items as well as a large alcoholic menu

Seasons 52 restaurant

Server

Oct 2012Mar 2015 · 2 yrs 5 mos · Atlanta, Georgia

  • Adapted to a new menu with every season while having knowledge of over 52 wines by the glass
  • Received “Freshness Pin” from General Manager as an award for excellence

Education

Georgia State University

Bachelor's degree — Computer Information Systems

Jan 2012Jan 2018

Stackforce found 100+ more professionals with Security & Program Management

Explore similar profiles based on matching skills and experience