Geovane Geo Sandoval
IT GRC Leader | Cybersecurity Strategist | Risk & Compliance Advisor | Driving Resilience Through Governance, Data Privacy & Audit Excellence
- Role
- Director - IT Governance, Risk & Compliance at Auctane
- Location
- Long Beach, CA, US
- LinkedIn followers
- 500 followers
About Geovane Geo Sandoval
Experienced and results-driven GRC leader with a proven track record of driving governance, risk, and compliance programs across global tech environments. I specialize in aligning IT operations with business goals and regulatory frameworks including NIST, ISO 27001, SOX, GDPR, PCI-DSS, and CMMC to build secure, compliant, and resilient organizations.Skilled in IT audit management, risk assessments, data privacy, and third-party risk, I’ve led enterprise-wide initiatives that enhance audit readiness, reduce risk exposure, and embed a culture of accountability. Passionate about automation and efficiency, I’ve streamlined GRC processes and implemented data-driven KPIs to elevate security and compliance maturity.Trusted advisor to senior leadership, translating complex risk into actionable strategy. I lead cross-functional teams and partner with stakeholders to protect digital assets and ensure operational integrity in fast-paced, cloud-driven environments. I’m equally committed to developing talent and embedding governance into the fabric of everyday business operations.Areas of Expertise include: Enterprise Risk Management & Controls IT Audit & Regulatory Compliance Data Privacy & Protection Programs Cybersecurity Frameworks & KPIs Policy development and implementationFeel free to reach out to me at: l••••••••@gmail.com.
Experience
Director - IT Governance, Risk & Compliance
May 2017 — Present · Austin, TX, US
Throughout my career, I’ve had the privilege of leading enterprise-level IT compliance and cybersecurity initiatives that safeguard critical systems and data. By crafting and enforcing resilient IT policies—spanning access control, data governance, and infrastructure integrity—I’ve helped organizations stay ahead of security threats and align with ever-evolving regulatory demands. From GDPR/CCPA to SOX and PCI-DSS, I ensure compliance isn’t just a checkbox but a strategic asset. I’ve also built and refined incident response strategies, preparing teams to respond decisively to cyberattacks, breaches, and system failures.What fuels this work is a deep commitment to building a proactive, risk-aware culture. I’ve mentored high-performing security and compliance teams, driven organization-wide education on regulatory standards, and delivered key insights to executive leadership and board members to shape risk strategy. Whether identifying hidden vulnerabilities or strengthening data protection frameworks, I’m passionate about aligning IT operations with trust, transparency, and resilience at their core.Key Accomplishments: Streamlined GRC processes, enhanced compliance monitoring, and drove automation efficiency by evaluating emerging technologies. Championed creation of Information Security department\'s intranet site, providing access to security policies, resources, and updates. Established and implemented latest IT Governance Framework, aligning systems and processes with business goals, legal requirements, and industry standards. Implemented GDPR/CCPA controls organization-wide and developed Global Information Security policies and standards based on ISO 27002, enhancing data protection and compliance. Administered SOC2 and SOC1 compliance efforts across four brands, as well as coordinated internal and external vulnerability scans and penetration tests, supporting PCI and overall security compliance efforts.
Education
California State University, Long Beach
Master of Business Administration (MBA), Management Information Systems, General
California State University-San Bernardino
Bachelor of Arts (B.A.), Finance, General
Mt. San Antonio College
Associate of Arts - AA, Liberal Arts and Sciences/Liberal Studies
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.