Jacques Lucas
Director of Grc CISO @Avertium
Signup · Get unlimited contacts
WORK HISTORY
Director of Grc CISO @Avertium
As Director of GRC, I am responsible for creating and delivering governance, risk, and compliance programs. These programs help both enterprises and clients grow securely while meeting regulatory, contractual, and customer requirements. I collaborate closely with executive leaders and client stakeholders. Together, we simplify complex compliance and risk mandates into actionable, business-focused strategies.I manage the overall GRC strategy and operations. This includes developing policy and control frameworks, leading enterprise risk management efforts, and preparing for audits such as HITRUST, HIPAA, ISO 27001, SOC 2, and PCI DSS. I also oversee client consulting projects. These projects deliver GRC assessments, support compliance readiness, and provide remediation services that go beyond simple checklist compliance. I lead a cross-functional team to align compliance initiatives with business objectives. This approach streamlines audit processes and improves stakeholder satisfaction.
EDUCATION
University of Miami Herbert Business School
BBA, Computer Information Systems
Florida International University - College of Business
Master of Science - MS, Management Information Systems, General
Florida International University - College of Business
MS, Management Information Systems
ABOUT JACQUES LUCAS
I’ve spent over 25 years at the intersection of IT operations, cybersecurity, and regulatory compliance, helping organizations protect what matters most while enabling them to grow and innovate.My journey has taken me from hands-on technical roles into executive leadership, where I now serve as both Managing Principal and Chief Information Security Officer at Avertium. In these roles, I’ve had the privilege of leading talented teams, delivering complex solutions, and building security programs that not only meet compliance requirements (PCI DSS, ISO SOX ITGC, SOC 2, GDPR, CCPA, POPIA, GLBA, HIPAA, FTC) but also align tightly with business objectives.Along the way, I’ve driven initiatives in risk management, business continuity, penetration testing, digital forensics, and social engineering defense. My certifications—CISSP, CISA, CDPSE, PCIP, and QSA—underscore my commitment to professional excellence, but what drives me most is the opportunity to mentor, collaborate, and create environments where teams thrive.At my core, I believe security is a business enabler. By fostering innovation, collaboration, and integrity, I help organizations turn security into a competitive advantage, not just a compliance checkbox.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.