Giselle Oviedo Valdez
Manager @Kunak
Signup · Get unlimited contacts
WORK HISTORY
Manager @Kunak
Miami, FL, US
A Peruvian company with a branch in Miami, where I lead cybersecurity projects in Miami, Puerto Rico, and Peru. I am responsible for delivering Virtual CISO (vCISO) services, conducting cybersecurity maturity assessments based on the NIST Cybersecurity Framework (NIST CSF), and leading the implementation and certification of Information Security Management Systems (ISMS).
EDUCATION
Isiltech
Gestión de Proyectos PMP
Elementi
Curso CCSK - Cloud Security Knowledge
PMC - EXIN
Curso, Gestión de Continuidad de Negocio
Universidad ESAN
PAE en implementación de un SGSI, Computer and Information Systems Security/Information Assurance
IGP Peru training
Risk Quantification - FAIR, Seguridad informática y de sistemas
Universidad de San Martín de Porres
Bachiller, Ingenieria de sistemas
Universidad del Pacífico (PE)
Diplomado en Gestion de Riesgos Financieros
Universitat de Barcelona
Master in cybersecurity, Seguridad informática y ciberseguridad
Universidad ESAN
BPM - Business process management, Business process management
ABOUT GISELLE OVIEDO VALDEZ
Cybersecurity specialist with nearly 15 years of experience in information technology audit, information security, cybersecurity risk management, and regulatory compliance across the finance, insurance, retail, card processing industries and others.Professional Highlights- Design, implementation, and maintenance of Information Security Management Systems (ISMS) aligned with ISO/IEC 27001- Cybersecurity risk analysis and promotion of a strong risk culture- Cyber risk assessment for new technology projects (on-premises and cloud-based) in both traditional and agile environments- Design and deployment of security awareness strategies focused on behavioral change. I developed a user risk model that improved the organization’s cybersecurity culture by 85%, raising it from the 15th percentile at the start of my role- Design of security and cybersecurity capability maturity models based on ISO 27001 and NIST. Through this model, I helped strengthen organizational capabilities from Level 2 (Repeatable) to Level 4 (Managed)- Cyber risk quantification using the FAIR methodology for scenarios such as information leakage and service unavailability due to cyberattacks- Support in the design, implementation, and testing of IT controls for internal and external audits- Experience with Service Organization Control (SOC) reporting, including SAS 70, SSAE 16, and SOC reports.I have strong knowledge and hands-on experience with regulatory requirements and standards, including ISO 27001, ISO 27005, ISO NIST, Sarbanes-Oxley (SOX 404), HIPAA, and PCI DSS.Additionally, throughout my career I have actively facilitated high-level discussions and regularly participated in meetings with Boards of Directors, Audit Committees, and Security and Risk Committees, translating technical risk into clear business language.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.