Brenda Fantroy-Johnson
Cybersecurity Risk Management @ AT&T | CISSP, CIPP/US, CRISC
- Role
- Cybersecurity Risk Management at AT&T
- Location
- Bainbridge Island, WA, US
- LinkedIn followers
- 500 followers
About Brenda Fantroy-Johnson
With over 17 years of experience at AT & T, I specialize in managing the end-to-end cybersecurity risk management process, aligning enterprise security initiatives with the NIST and ISO frameworks. My focus lies in integrating risk management into business processes, facilitating informed decision-making for senior management, and ensuring ongoing compliance with SOX, PCI, and SPI standards. As a liaison between Privacy and GRC teams, I contribute to audit readiness and remediation efforts while fostering a culture of security awareness. Skilled in risk assessment, governance implementation, and continuous monitoring, I enable organizations to navigate complex regulatory environments effectively and safeguard critical assets.
Experience
Cybersecurity Risk Management
Jan 2008 — Present
The Risk Management process has been defined using the NIST and ISO frameworks. I am the facilitator of the Risk Management front door process, specializing in SOX, PCI and SPI. Risk liaison between Privacy and GRC teams. It is my responsibility to integrate information security into the enterprise and to link risk management to the business unit processes. This includes continuous monitoring and providing senior management with information to make informed risk based decisions.
Education
Spring Arbor University
MBA, Business
2003 — 2004
Davenport Univerisity
BAS, Computer and Information Systems
1999 — 2001
Skills
- Disaster Recovery
- Cissp
- Financial Risk
- Information Security Management
- Information Security
- Data Security
- Security Audits
- Risk Management
- Privacy
- Cipp
- Risk Assessment
- Sarbanes-Oxley Act
- Computer Security
- Data Privacy
- Audit
- Network Security
- Enterprise Risk Management
- Iso 27000
- Policy
- Cism
- Auditing
- Technical Training
- Security
- Vulnerability Assessment
- Iso 27001
- IT Audit
- Pci Dss
- Cloud Security
- Compliance
- Governance
- Vulnerability Management
- Information Technology
- Privacy Law
- Sox
- Cisa
- Cloud Computing
- Security Awareness
- Payment Card Industry Data Security Standard (Pci Dss)
- Risk
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.