Diana Riley
Cybersecurity Executive | Head of GRC & Risk Strategy | Deputy CISO | CISSP-ISSAP | NYDFS | ISO 27001 | CIPP/E
- Role
- Head of Cyber Governance, Risk & Compliance at MassMutual
- Location
- Boston, MA, US
- LinkedIn followers
- 500 followers
About Diana Riley
Driven by a deep commitment to building a culture of security and accountability that protects the enterprise and everyone it touches.I’m an enterprise information security and data privacy leader with extensive progressive experience strengthening cyber resilience across global institutions. My work centers on building mature Governance, Risk & Compliance programs, elevating security accountability, and operationalizing controls that stand up to regulatory scrutiny and evolving threats.I’m known for blending strategic vision with practical execution, bringing transparency to cyber risk, modernizing governance frameworks, and developing high-performing teams across GRC, third-party risk, security awareness, and privacy. Whether partnering with boards, regulators, executive leadership, or global engineering teams, I help organizations make informed decisions that reduce risk without slowing the business.My leadership style is grounded in social intelligence and clarity: aligning people, process, and technology to create secure, resilient, and aware organizations. I thrive in environments where the mandate is to modernize, simplify, and uplift security capabilities while developing the leaders who will carry that momentum forward.Areas of Focus: Cybersecurity Governance & Risk Oversight Enterprise GRC Strategy & Program Maturity Third-Party & Supply Chain Risk Management Data Privacy & Protection (CIPP/E | CIPM | CIPT) Regulatory Compliance (GLBA, NYDFS, SEC, GDPR, ISO 27001, NIST CSF) Security Awareness & Human Risk Management & Training Audit & Regulatory Engagement Executive & Board-Level Risk ReportingI welcome opportunities to connect with peers, collaborators, and organizations.
Experience
Head of Cyber Governance, Risk & Compliance
Nov 2024 — Present · Boston, MA, US
Leading enterprise GRC, Third-Party Risk, and Security Awareness programs with oversight of 3 directors and 18 person team. Advise executive leadership and board on cyber risk, resilience, and program maturity. Directed vendor risk assessments, security governance frameworks, and continuous monitoring across MassMutual\'s critical technology partnership.Key achievements: Designed a third-party cyber risk strategy aligned with NYDFS, GLBA, ISO 27001, improving vendor accountability. Built a cybersecurity governance framework based on NIST CSF/ISO 27001, enabling real-time cyber risk reporting. Reduced audit preparation time by 40% by implementing a centralized GRC platform. Launched a company-wide security awareness program achieving 100% compliance and measurable risk reduction. Strengthened cross-functional alignment with Legal, Privacy, and Procurement, embedding controls across workflows.
Education
UMass Boston
Bachelor of Arts, English Literature
1993 — 1997
Northeastern University
Masters, Professional Studies in Informatics – Concentration: Information Security Management
2005 — 2007
Skills
- Build Trust Advisory Relationships with Cross-Functional Management to Strateg
- Solaris
- Security
- Unix
- Information Security
- System Deployment
- Servers
- Troubleshooting
- Software Development
- Computer Security
- Responsible for IT Security at a Mid-Sized Company (~500 Staff)
- Software Documentation
- Disaster Recovery
- Expert on Current Security Tools and Technologies, Knowledge of Various Operat
- Network Security
- Drive Corporate Security Compliance and Cultivate IT Security Awareness Via Tr
- Provide Leadership to the Organization IT Security Programs, Including Develop
- Perl
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.