David Topelberg

Senior Cybersecurity & Risk Leader | CISSP | Pharma / Life Sciences / Manufacturing | ISO 27001 | GxP | OT & Cloud Security | AI Security & Governance | Board-Facing | CISO-Track

Role
Senior Manager, IT Risk & Compliance (Director-level Cybersecurity Board-facing Ai Governance) at PennEngineering®
Location
Philadelphia, PA, US
LinkedIn followers
500 followers

About David Topelberg

I am a board-facing cybersecurity and risk leader with 18+ years of global experience across manufacturing, pharmaceutical, and regulated industries.I have built and scaled ISO 27001-certified programs, led enterprise-wide modernization across IT, OT, and cloud, and advised executive leadership on cyber risk, resilience, and innovation strategy. My approach is rooted in systems thinking: translating complex threats into board-relevant priorities and secure-by-design transformation.My expertise spans governance and compliance frameworks (ISO 27001, NIST, GDPR, HIPAA, TISAX), incident response, third-party risk, OT security, and AI security governance. I currently lead enterprise efforts to assess AI-related risks, evaluate secure integration paths, and align future adoption with regulatory and compliance frameworks.I have a proven track record of building and leading global teams, enhancing security capacity, and driving cultural change across enterprises. I am succession-ready for executive leadership, aligning cybersecurity with business growth, enterprise resilience, and AI-driven transformation.

Experience

  1. Senior Manager, IT Risk & Compliance (Director-level Cybersecurity Board-facing Ai Governance)

    PennEngineering®

    Jan 2025 — Present · Doylestown, PA, US

    Promoted after leading global cybersecurity transformation, board-facing visibility, and cross-regional compliance initiatives across North America, Europe, and Asia. Partners with senior leadership to align security strategy with executive priorities and enterprise growth.Strategy, Compliance & AI Risk OversightLed ISO 27001:2022 certification for U.S. operations and developed a global roadmap for ISO, TISAX, and regional compliance. Established Key Risk Indicator dashboards and launched Security Council meetings for executive-level threat visibility. Currently leadin efforts to assess AI-related risks, evaluate secure integration paths, and align future AI adoption with enterprise security and compliance frameworks.Threat Operations, Automation & ResilienceExpanded EDR/XDR platform to include Cloud, VM, and legacy OS coverage. Enhanced SIEM/MDR effectiveness via enriched data ingestion and event correlation. Integrated SOAR-based phishing remediation, cutting mitigation time by 50%. Formalized incident response and disaster recovery playbooks, improving RTO and readiness through live simulations.Team Growth, Culture & Third-Party RiskDoubled security team size, scaling coverage across IR, detection, and vulnerability response. Drove a 100% YoY increase in third-party audit responsiveness. Advanced global security culture through targeted awareness efforts—halving phishing test failure rates and achieving full compliance training enterprise-wide.

Education

  • UNM Anderson School of Management

    Bachelor's degree, Business Administration / Business Computer Systems

  • Boston University

    CIO Pocket MBA Certificate

  • Vrije Universiteit Amsterdam (VU Amsterdam)

    Economics

Skills

  • Microsoft Sql Server
  • Cross-Functional Team Leadership
  • Sdlc
  • Magic Bullet
  • Crm
  • Requirements Analysis
  • Cloud Computing
  • Project Planning
  • Management
  • Enterprise Software
  • Enterprise Architecture
  • Software License Agreements
  • Saas
  • Leadership
  • Vmware
  • Process Improvement
  • Data Center
  • Vendor Management
  • Contract Negotiation
  • Salesforce.com
  • IT Management
  • Program Management
  • Integration
  • Project Portfolio Management
  • Project Management
  • IT Strategy
  • Business Process
  • Hostage Negotiator
  • Risk Management
  • Threat Management
  • Information Security
  • Change Management
  • Business Intelligence
  • Cyber-Security
  • Business Analysis
  • Business Process Improvement
  • Strategy

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

David Topelberg — Senior Manager, IT Risk & Compliance (Director-level Cybersecurity Board-facing Ai Governance) at PennEngineering® in Philadelphia, PA, US | Unifers