Brenda Fantroy-Johnson

Cybersecurity Risk Management @ AT&T | CISSP, CIPP/US, CRISC

Role
Cybersecurity Risk Management at AT&T
Location
Bainbridge Island, WA, US
LinkedIn followers
500 followers
Information TechnologyView LinkedIn profile

About Brenda Fantroy-Johnson

With over 17 years of experience at AT & T, I specialize in managing the end-to-end cybersecurity risk management process, aligning enterprise security initiatives with the NIST and ISO frameworks. My focus lies in integrating risk management into business processes, facilitating informed decision-making for senior management, and ensuring ongoing compliance with SOX, PCI, and SPI standards. As a liaison between Privacy and GRC teams, I contribute to audit readiness and remediation efforts while fostering a culture of security awareness. Skilled in risk assessment, governance implementation, and continuous monitoring, I enable organizations to navigate complex regulatory environments effectively and safeguard critical assets.

Experience

  1. Cybersecurity Risk Management

    AT&T

    Jan 2008 — Present

    The Risk Management process has been defined using the NIST and ISO frameworks. I am the facilitator of the Risk Management front door process, specializing in SOX, PCI and SPI. Risk liaison between Privacy and GRC teams. It is my responsibility to integrate information security into the enterprise and to link risk management to the business unit processes. This includes continuous monitoring and providing senior management with information to make informed risk based decisions.

Education

  • Spring Arbor University

    MBA, Business

    2003 — 2004

  • Davenport Univerisity

    BAS, Computer and Information Systems

    1999 — 2001

Skills

  • Disaster Recovery
  • Cissp
  • Financial Risk
  • Information Security Management
  • Information Security
  • Data Security
  • Security Audits
  • Risk Management
  • Privacy
  • Cipp
  • Risk Assessment
  • Sarbanes-Oxley Act
  • Computer Security
  • Data Privacy
  • Audit
  • Network Security
  • Enterprise Risk Management
  • Iso 27000
  • Policy
  • Cism
  • Auditing
  • Technical Training
  • Security
  • Vulnerability Assessment
  • Iso 27001
  • IT Audit
  • Pci Dss
  • Cloud Security
  • Compliance
  • Governance
  • Vulnerability Management
  • Information Technology
  • Privacy Law
  • Sox
  • Cisa
  • Cloud Computing
  • Security Awareness
  • Payment Card Industry Data Security Standard (Pci Dss)
  • Risk

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Brenda Fantroy-Johnson — Cybersecurity Risk Management at AT&T in Bainbridge Island, WA, US | Unifers