Mark E.S. Bernard, Trusted Advisor to BoD and Executive Team

CEO

Austin, Texas, United States6 yrs 11 mos experience
Most Likely To SwitchAI Enabled

Key Highlights

  • 20+ years of cybersecurity leadership experience
  • Expert in ISO/IEC 27001 and SOC 2 certifications
  • Proven track record in risk management and compliance
Stackforce AI infers this person is a Cybersecurity Leader with extensive experience in compliance and risk management across multiple industries.

Contact

Skills

Core Skills

LeadershipProgram ManagementRisk ManagementCompliance ManagementGovernanceCybersecurityInformation Security

Other Skills

Project ManagementCultural AwarenessBusiness Impact AnalysisCloud ComputingWork Breakdown Structure (WBS)Customer Relationship Management (CRM)Data ClassificationData SecurityRisk AnalysisBusiness CommunicationsInformation Security ManagementCISMCISSPChange ManagementInterpersonal Skills

About

Innovative cybersecurity professional with 20+ years of experience leading cybersecurity strategy, governance, risk management, and compliance programs across North America. Proven track record delivering ISO/IEC 27001, SOC 2, NIST CSF, and OSFI B-13 aligned solutions in financial services, AI, healthcare, and public sectors. Skilled in aligning security initiatives with business goals, managing multi-stakeholder environments, and coaching teams to success. Passionate about leveraging AI and emerging technologies to enhance security posture and drive transformation. Open to strategic leadership roles in cybersecurity, risk management, and advisory services. Experience Highlights: Led 100+ cybersecurity and compliance projects across consulting, vCISO, and program leadership roles. Developed AI governance and risk frameworks supporting innovative technology adoption and compliance. Directed ISO 27001 ISMS, SOC 2, and NIST CSF certifications, increasing client trust and revenue opportunities. Spearheaded identity & access management, vulnerability management, and business continuity initiatives.

Experience

6 yrs 11 mos
Total Experience
4 yrs
Average Tenure
6 yrs 11 mos
Current Experience

Ghgsat

Cybersecurity Program Leader, CISO, Program Architect, AI

Mar 2024Apr 2025 · 1 yr 1 mo · Quebec, Canada · Remote

  • Directed the establishment of the Cybersecurity Governance Committee and chaired meetings.
  • Orchestrated the adoption of ISO/IEC 27001 ISMS, SOC 2, CMMC certification to achieve customer requirements and new revenue opportunities.
  • Documented Policies, Procedures, and Standards, and Collected Records for certification.
  • Supervised risk management and continual improvement, resulting in enhanced client trust.
GovernanceProcess ImprovementAsset ManagementProgram ManagementRisk ManagementCultural Awareness+53

Surgical safety technologies inc.

GRC Manager, Sr. Cybersecurity Architect, CISO, AI

Dec 2022Feb 2024 · 1 yr 2 mos · Toronto, Ontario, Canada · Hybrid

  • Directed the implementation of the AI Governance, Risk, and Compliance Program.
  • Documented Policies, Procedures, and Standards, and Collected Records for certification.
GovernanceRisk ManagementLegal ComplianceInterpersonal CommunicationInterpersonal RelationshipsInterpersonal Skills+48

Tam-c solutions

Sr. Cybersecurity Advisor, vCISO, Program Architect, AI

Jul 2021Oct 2022 · 1 yr 3 mos · Philadelphia, USA · Remote

  • Orchestrated the adoption of ISO/IEC 27001 ISMS, SOC 2, CMMC certification to achieve customer requirements and new revenue opportunities
  • Documented Policies, AI Procedures, and Standards, and Collected Records for certification.
ISO 27001SOC 2CMMCCybersecurityGovernanceRisk Management+49

Fellsway group, llc

Sr. Cybersecurity Advisor, vCISO, Program Architect

Jul 2020May 2025 · 4 yrs 10 mos · United States · Remote

  • Partnered with customers to establish Incident Response and Crisis Management to meet regulatory and customer requirements.
  • Documented Policies, Procedures, and Standards, and Collected Records for certification.
  • Orchestrated the adoption of SOC 2, BCDR, ISO/IEC 27001, and ISO 22301 certifications for US Customers to meet new goals for revenue, risk management, and business continuity.
Cultural AwarenessBusiness Impact AnalysisCloud ComputingWork Breakdown Structure (WBS)Customer Relationship Management (CRM)Data Classification+28

Bernard institute for cybersecurity excellence llc

Fractional CISO, Cybersecurity, AI /ML Program Manager, and Project Manager

Jun 2019Present · 6 yrs 11 mos

  • CEO of Bernard Institute and Senior Program Manager leading multi-million dollar cybersecurity, privacy, and quantum encryption workstreams with global impact.
LeadershipProgram ManagementRisk ManagementCompliance ManagementProject Management

Syniti

Sr. Cybersecurity Architect, vCISO, Syniti. Hyannis, USA

Feb 2019Sep 2021 · 2 yrs 7 mos · Hyannis, Massachusetts, United States

  • Orchestrated the adoption of ISO/IEC 27001 ISMS in compliance with IBM and SAP requirements, leading to new revenue opportunities.
  • Documented Policies, Procedures, and Standards, and Collected Records for certification.
  • Directed the ISO/IEC 27001 ISMS program, satisfying compliance with customer requirements.
GovernanceProcess ImprovementAsset ManagementProgram ManagementRisk ManagementCultural Awareness+58

Toronto public library

Sr. Cybersecurity RFP Project Manager, Toronto Public Library, Ontario, Canada

Jul 2017Jul 2019 · 2 yrs · Greater Toronto Area, Canada · On-site

  • • Guided the entire RFP process, publishing, evaluating, and onboarding of a new IPS vendor to replace the retired IPS and enhance the new IPS with decryption capabilities to control risks.
GovernanceRisk ManagementCultural AwarenessProcurementAnnual PlanningInformation Security+18

Ntt data, inc.

Cybersecurity Program Director, Digital Cloud Services, NTT DATA Inc. NS, Canada

Aug 2016Feb 2017 · 6 mos · Halifax, Canada Area · On-site

  • • Supervised a team of 130 Cybersecurity professionals and five programs for Morgan Stanley, meeting the service delivery requirements while expanding on Fortune 50 capabilities.
GovernanceHoneypotsTime & AttendanceTeam MotivationCustomer Relationship Management (CRM)Security Information and Event Management (SIEM)+11

Virtustream

SAP HANA HEC Cybersecurity Compliance Manager, Virtustream, Washington, USA

Oct 2015Aug 2016 · 10 mos · Bethesda, Maryland, United States · Hybrid

  • Orchestrated the adoption and certification of ISO/IEC 27001 ISMS, ISO 9001, and ISO 22301.
  • Documented Policies, Procedures, and Standards, and Collected Records for certification.
  • Directed the documentation of the PMO Methodology to satisfy customer requirements.
GovernanceRisk ManagementCultural AwarenessPCI DSSBusiness Impact AnalysisCloud Computing+39

Island health - vancouver island health authority

IM/IT Cybersecurity Threat Risk Analyst, Regional Health Authority BC, Canada

Apr 2015Oct 2015 · 6 mos · Victoria, British Columbia, Canada · On-site

  • • Orchestrated the threat risk assessment of 19,000 clinicians, 130 facilities, and 30,000 assets in preparation for the migration of the legacy health information system to Cerner Millennium.
Asset ManagementRisk ManagementBusiness Impact AnalysisInformation SecurityData ClassificationRisk Analysis+10

Orange parachute

ISO 27001 ISMS Cybersecurity Specialist, Orange Parachute, Minneapolis, USA

Feb 2010Apr 2015 · 5 yrs 2 mos · Minneapolis, Minnesota, United States · Hybrid

  • Orchestrated the adoption and certification of ISO/IEC 27001 ISMS, ISO 9001, and ISO 22301.
  • Documented Policies, Procedures, and Standards, and Collected Records for certification.
GovernanceAsset ManagementRisk ManagementBusiness Impact AnalysisCloud ComputingWork Breakdown Structure (WBS)+33

Bc government and service employees union (bcgeu)

Manager, Compliance and Reporting and Director, Technology and Operations, BC Gov, BC, Canada

Sep 2008Feb 2010 · 1 yr 5 mos · Victoria, British Columbia, Canada. · On-site

  • Orchestrated the adoption and certification of ISO/IEC 27001 ISMS, and ISO 20000 /ITIL to address 80 cybersecurity audit findings made by the BC Auditor General.
  • Documented Policies, Procedures, and Standards, and Collected Records for certification.
  • Directed the NRFP process, publishing, evaluating, and onboarding of a new Oracle eBiz Suite vendor to replace the vendor, reducing operational costs by $16 million.
GovernanceProcess ImprovementAsset ManagementRisk ManagementCultural AwarenessBusiness Impact Analysis+43

Central 1 credit union

Privacy and Security Compliance Officer, Central 1 Credit Union, BC, Canada

Feb 2007Sep 2008 · 1 yr 7 mos · Vancouver, British Columbia, Canada. · Hybrid

  • Orchestrated the adoption and certification of ISO/IEC 27001 ISMS, to address 40 cybersecurity audit findings made by a client audit that led to a new $5 million contract.
  • Guided the integration of ISO/IEC 27001 ISMS into trade service and wholesale services.
  • Documented Policies, Procedures, and Standards, and Collected Records for certification.
  • Directed the privacy and security program for a $302 million annual operation.
GovernanceProcess ImprovementAsset ManagementRisk ManagementCultural AwarenessBusiness Impact Analysis+36

Advanced solutions, an hp company

Privacy and Security Compliance Officer, EDS Advanced Solutions, BC, Canada

Oct 2005Feb 2007 · 1 yr 4 mos · Victoria, British Columbia, Canada. · On-site

  • Orchestrated the privacy and security program for a $30 million annual operation.
  • Directed the strategy to migrate citizens' private data from the government to a private company.
  • Guided the privacy and security workstream during contract negotiations.
  • Documented Policies, Procedures, and Standards, and Collected Records for certification.
GovernanceAsset ManagementRisk ManagementCultural AwarenessTeam MotivationPCI DSS+44

Independent contractor

2 roles

Cybersecurity Trusted Advisor and Management Consultant

Promoted

Dec 2002Oct 2005 · 2 yrs 10 mos · International · Hybrid

  • Responsibilities: As the Senior Cybersecurity Consultant and Project Manager I am currently leading projects designed to help my clients improve the effectiveness and efficiency of their existing programs. I led the development of business plans including strategic, tactical, and annual budgeting. I develop contact lists and meet regularly with clients. I develop media contacts and press releases establishing TechSecure as the regional experts within our profession.
  • Projects:
  • Provided Mid Range Expertise for Global Red Team against US Financial businesses
  • Led SOX /SAS 70 Audit Finding Resolution for US Bank
  • Led ISO 27001 Policy, Procedure, Standards for Major US Telecom
  • Led Security Awareness Program for Major Transportation System
  • Led Business Continuity project for US Telecom
  • Led SOX and SOC 1, 2, and 3 Audits for US Financial Services company
GovernanceProcess ImprovementAsset ManagementRisk ManagementCultural AwarenessBusiness Impact Analysis+36

Cybersecurity Trusted Advisor and Management Consultant

Apr 1997Jul 2000 · 3 yrs 3 mos · International

  • Responsibilities: As the Senior Cybersecurity Consultant and Project Manager I am currently leading projects designed to help my clients improve the effectiveness and efficiency of their existing programs. During my work I meet with clients and provide expert advice on matters concerning compliance with US and Canadian legislation, EDI and IT Audit. I led projects conducting assessments such as Threat-Risk Assessments, Reassurance Assessments, GAP Analysis and assist my clients in adopting best practices to mitigate risks to information assets and systems resources.
  • Projects:
  • Led onboard EDI Trading Partners for Manufacturing and Supply Chain
  • Red Team Penetration Testing for Global Technology company
  • Led Application Audit of Banking Wealth Management Systems
  • Led Application Audit of Telecommunications Systems
  • Sprint Canada Y2K Application Audit
  • Seneca College Professor of Applied Arts 3rd year Diploma Systems Engineering Course
  • Taro Pharmaceutical - ISO 9001 re-cert following ERP/BPCS centralization and hardware upgrade
Cybersecurity

Mccain foods

Information Security Specialist

Jul 2000Dec 2002 · 2 yrs 5 mos · Florenceville, New Brunswick, Canada

  • Responsibilities: As the Information Security Specialist I led the Information Security Business Unit (ISBU). I developed strategic, tactical and annual business plans in alignment with organizational business goals and objectives. I led the ISBU during the development and implementation of a multidimensional information security program.
  • Projects:
  • Led Global Security Program and adoption of ISO 17799 in 16 countries
  • Security Policy project
  • Organization of Information Security project
  • Asset Management project
  • Human Resources project
  • Physical & Environmental Security project
  • Communications & Operations Security project
  • Access Control project
  • Information Systems, Acquisition, development and maintenance project
  • Information Security Incident Management project
  • Business Continuity Management project
  • Compliance project
GovernanceRisk ManagementBusiness Impact AnalysisWork Breakdown Structure (WBS)Annual PlanningCustomer Relationship Management (CRM)+21

Seneca college

Professor of Systems Engineering

Jun 2000Dec 2000 · 6 mos · Don Mills Campus

  • OPS350 Offered Summer 2000 Title Introduction to AS400 (IBM System "i") Connectivity by Professor Mark E.S. Bernard
  • 1. CODE: OPS350 OFFERED: SUMMER 2000 TITLE: INTRODUCTION TO AS/400 CONNECTIVITY SUBJECT DESCRIPTION:This subject will provide an introduction to the AS/400 architecture and user interface. Topics include 5250 emulation; IBMs PC support and Client Acess /400; file transfers between an AS/400 and a PC and file transfers between two AS/400s; the ability to use PC printers as AS/400 printers; storing PC data with shared folders and the integrated file system; file and database serving; CL commands; Working with Jobs; Device configuration; AS/400 security;backup and recovery; release updates and applying PTFs; and system maintenance and monitoring performance.
  • CREDIT STATUS: 1 Credit for CNS & CTY Diploma Program
  • PREREQUISITES: OPS240
  • SPECIFIC OUTCOMES: Upon successful completion of this subject, the student will be ableto:
  • Link; http://www.slideshare.net/markb677/code-ops350-offered-summer-2000-title-introduction-to-as400-connectivity-professor-mark-e-s-bernard
GovernanceProcess ImprovementAsset ManagementProgram ManagementRisk ManagementCultural Awareness+48

Hanes companies, inc

Programmer Analyst II / Application Specialist

Nov 1995Apr 1997 · 1 yr 5 mos · Mississauga, Ontario, Canada

  • Responsibilities: As the Information Technology Consultant I meet with clients and provide expert advice on matters concerning compliance with US and Canadian legislation, EDI and IT Audit. I led projects conducting assessments such as Threat-Risk Assessments, Reassurance Assessments, GAP Analysis and assist my clients in adopting best practices to mitigate risks to information assets and systems resources.
  • Projects:
  • As the Programmer Analyst II / Application Specialist I managed the development and implementation of a project integrating JBA ERP systems with EDI ANSI X12 and EDIFACT standard transactions.
  • This included the implementation of Advanced Shipment Notices (ASN) utilizing the MH10 label thermal label process and Symbol handheld scanners.
  • Leading into this project I initiated a Request for Proposal (RFP) from which I created a Capital Expense Request (CER) for senior management’s endorsement.
  • A key to the success of this project was working with Sears Canada and Wall-Mart in establishing EDI trading partner relationships.
Cybersecurity

Zurich insurance company ltd

HRIS Manager, AS400 Guru, CISO

Feb 1989Sep 1995 · 6 yrs 7 mos · Toronto, Ontario, Canada

  • Responsibilities: As the HRIS Manager I administered the systems and network supporting the in-house payroll system and Human Resource systems including planning and budgeting. I collaborated with HR Business Units, Finance Department, Internal, Corporate and External Audit teams to establish best practices while mitigating risks
  • Projects:
  • Infrastructure Upgrade and migration from S36 to AS400
  • Mergers of two largest Ins HR databases
  • Design and develop custom Applicant Tracking
  • Design and develop custom Skills Inventory
  • Canadian Savings Bonds annual program
  • Cost of Living annual program
Cybersecurity

Education

University of Toronto

Human Resources Management Certificate (Continuing Studies) — Business Communications

Jan 1991Jan 1992

Centennial College

Certificate — Advanced Programming

Jan 1997Jan 1997

International information system security certification consortium

(ISC)² CISSP Certification Now Comparable to Masters Degree Standard — Cybersecurity

Jan 2004Present

York University

Certificate in Adult Education — Instructional Skills Workshop

Jan 2003Jan 2004

University of Toronto

Business/Corporate Communications

IBM

AS /400 Guru (now IBM System ' i ')

Jan 1989Jan 1995

Salisbury High School

Grade 12 — general education

Jan 1970Jan 1982

Royal Roads University

Certificate in Adult Education — Education

Jun 2003Jul 2003

Stackforce found 100+ more professionals with Leadership & Program Management

Explore similar profiles based on matching skills and experience