W

William Brock

Operations Associate

Washington, District of Columbia, United States28 yrs 5 mos experience

Key Highlights

  • Led ISO 27001 assessments for Walmart globally.
  • Established a robust third-party vendor risk management program.
  • Developed a playbook to prevent data loss.
Stackforce AI infers this person is a Cybersecurity and Risk Management expert in enterprise environments.

Contact

Skills

Core Skills

Risk ManagementInformation SecurityCybersecurity

Other Skills

Third Party Risk ManagementRisk AssessmentVendor ManagementData PrivacyInformation Risk ManagementData Sharing AgreementsVendor Risk AssessmentsSecurity PoliciesComplianceSystem Security PlansFISMA ComplianceNIST StandardsVulnerability ManagementISO 27001 AssessmentsData Protection

About

Self-directed and driven technology professional with comprehensive accomplishments leading enterprise risk and information security management, audits, data protection, policies and procedures development, and cross-functional teams to ensure success and achieve goals. Known as an innovative thinker with strong consulting, defense contracting, aerospace, government, and retail acumen. Demonstrated success in developing and executing risk assessment strategies in complex organizational structures. Recognized for building relationships to foster collaboration essential to holistically implementing appropriate data protection strategies. Expertise includes managing technology operations for multibillion-dollar companies. Accomplishments: • Reduced risk by establishing a robust third-party vendor risk management program. • Led ISO 27001 security assessments for Walmart across 60+ global locations as a contractor with KPMG. • Manage data sharing agreements and technology standard compliance for the world’s largest supplier of athletic shoes and apparel. • Prevented data loss by developing a playbook detailing deployment paths and plans. Expertise: Information Security, Information Assurance, Vendor Management, Information Technology, Consulting, Program Management, Customer Relationship Management (CRM), Data Loss Prevention, Networking, Risk Management, Third Party Vendor Management, Cybersecurity, Amazon Web Services (AWS), AWS Security, ITIL, Risk Assessment, Platform as a Service (PAAS), Software as a Service (SaaS), Infrastructure as a Service (IaaS), KPI Dashboards, Governance Risk & Compliance (GRC), IT Governance, IT Compliance, Data Privacy, Off-shore Team Management, Security Incident Response, Archer, System Development Life Cycle, Vulnerability Assessment

Experience

28 yrs 5 mos
Total Experience
--
Average Tenure
--
Current Experience

Lowe's companies, inc.

Third Party Risk Analyst

Jan 2020Present · 6 yrs 5 mos · Charlotte, North Carolina, United States

  • Develop, drive, and lead strategy in the third party information risk management group.
  • Coordinate and lead onsite & remote vendor risk assessments and internal enterprise-wide risk
  • assessments.
  • Interview vendors and internal stakeholders to identify the existence, suitability and operating
  • effectiveness of information security controls.
  • Contribute to client relationship management, lead conference calls, onsite meetings and
  • presentations, and serving as the point of contact on client engagements.
  • Conduct risk assessment workshops and gap analysis interviews with key client stakeholders and
  • produce reports and analyses conveying findings and recommendations for remediation.
  • Assess gaps in practices and controls against relevant standards, compliance requirements and
  • business policies and develop recommendations to close identified gaps
  • Summarize risk analysis, evaluations, and recommendations in executive reports to Lowe's Business
  • Unit Leadership to facilitate risk-based decision making regarding procurement of vendor service or product
  • Track and report remediation progress and exceptions to support enterprise risk reports to
  • executive leadership
  • Additional Duties
  • Mentor and train Junior Risk Analysts, provide cloud security subject matter expertise, serve as
  • technical consultant for complex engagements
  • Develop success criteria and lead tool evaluation initiatives for new GRC tool selections
  • Maintain an understanding of current issues and technology relating to information security, data
  • privacy and information security frameworks,standards, & regulations
Third Party Risk ManagementRisk AssessmentInformation SecurityVendor ManagementData PrivacyRisk Management

Nike

Senior Analyst, Information Risk

Jan 2015Jan 2020 · 5 yrs · Portland, Oregon, United States

  • Architect strategies for the global information risk management group and direct enterprise and third-party vendor risk assessments for the world’s largest supplier of athletic shoes and apparel with $36B+ in revenue.
  • Oversee data sharing agreements, policies, procedures, and standards, collaborations with compliance and governance groups, legal counsel, and terms for legal contracts.
  • Advise business unit leaders on vendor services and product procurement by developing and submitting executive reports encompassing risk analyses, evaluations, and recommendations.
  • Improve information security controls by interviewing vendors and internal stakeholders, evaluating operational effectiveness, and implementing modifications.
  • Prevent the inadvertent exposure of sensitive data by vendors and internal stakeholders by documenting vulnerabilities and rectifying problem areas.
Information Risk ManagementData Sharing AgreementsVendor Risk AssessmentsSecurity PoliciesComplianceInformation Security+1

First tek

Information System Security Engineer

Jan 2014Jan 2015 · 1 yr · Portland, Oregon Area

  • For primary client Bonneville Power Administration designed system security plans and life cycle documents aligned with the Federal Information Security Management Act (FISMA) and National Institute of Standards and Technology (NIST) 800-53, Defense Information Systems Agency’s (DISA) Security Technical Implementation Guides (STIG), and internal executive guidance for a leading technology services provider.
  • Mitigated risk by analyzing technology operations and ensuring compliance with best practices relative to vulnerability and change management, system confidentiality, and document and data integrity.
  • Developed management summaries in Word, PowerPoint, Excel, and Visio.
System Security PlansFISMA ComplianceNIST StandardsVulnerability ManagementInformation Security

Kpmg

Consultant, Information Protection & Compliance

Jan 2012Jan 2014 · 2 yrs · Bentonville, Arkansas, United States

  • For the primary client Walmart led International Organization for Standardization (ISO) 27001/2 security assessments across 60+ locations spanning North and South America, Asia, and Europe for one of the big four accounting organizations with $29B+ in revenue.
  • Advised business unit stakeholders on risks, system architecture, and security policies.
  • Protected sensitive data by performing manual discovery of electronically protected health information (ePHI), including conducting interviews with business leaders, reviewing data repositories, designing data flow diagrams, and assessing HIPAA-related security controls.
  • Prevented data loss by developing a comprehensive playbook detailing deployment paths.
  • Averted security-related disasters by investigating and resolving system vulnerabilities, analyzing gaps, and implementing regulatory frameworks, standards, and processes.
ISO 27001 AssessmentsSecurity PoliciesData ProtectionRisk AnalysisInformation SecurityRisk Management

Northrop grumman

Cyber Security Analyst

Jan 2006Jan 2011 · 5 yrs · Orlando, Florida, United States

  • Managed system controls, including documentation for certification and accreditation, compliance with Department of Defense (DoD), federal government, and corporate requirements, and security policies and procedures for the world’s largest weapons manufacturers and military technology providers with $30B+ in revenue.
  • Oversaw the physical security program relative to visitor access, badges, the Joint Personnel Adjudication System (JPAS), intrusion detection system (IDS), and contingency plans.
  • Ensured operational readiness for external audits by executing internal information systems audits.
  • Mitigated risk by identifying compliance gaps and implementing improvement action plans and milestones.
  • Achieved departmental goals by assessing purchase requests and approving equipment upgrades.
  • Increased adherence to technical documentation requirements by developing accountability processes.
System ControlsComplianceSecurity PoliciesRisk MitigationCybersecurity

Lockheed martin

2 roles

Manager, Computer Security

Promoted

Jan 2005Jan 2006 · 1 yr

  • • Managed technology security systems, including firewalls, data protection controls, vulnerability scanning, and risk mitigation for one of the largest companies in the aerospace, defense, security, and technologies industry with $53B+ in revenue.
Technology Security SystemsRisk MitigationVulnerability ScanningCybersecurity

Senior Systems Engineer

Jan 1999Jan 2005 · 6 yrs

  • • Oversaw technical services and support, escalated issues, network assessments, security audits, and remote monitoring and management.
Technical ServicesNetwork AssessmentsSecurity Audits

Veridian

System Administrator

Jan 1997Jan 1999 · 2 yrs · McLean, Virginia, United States

  • • While at Trident Data Systems (later acquired by Veridian), installed and configured hardware, software, and networks monitored system performance and ensured security compliance for a provider of technology solutions to military and intelligence community customers.
Hardware InstallationNetwork ConfigurationSystem Performance Monitoring

Education

Darla Moore School of Business at the University of South Carolina

Bachelor of Science (BS) — Management Science

Brooklyn College

Master of Arts (MA) — Political Science

DeVry University

Master of Business Administration (MBA) — Information Security

Jan 2008Jan 2010

Stackforce found 100+ more professionals with Risk Management & Information Security

Explore similar profiles based on matching skills and experience