John Abraham
Director of Information Security – GRC | Safeguarding organization\'s informational assets through strategic risk management and cyber defense tactics while fostering a culture of security awareness.
- Role
- Director Information Security Governance, Risk, and Compliance (Grc) at Trane Technologies
- Location
- Charlotte, NC, US
- LinkedIn followers
- 500 followers
About John Abraham
I am a strategic professional with years of experience creating security awareness…
Experience
Director Information Security Governance, Risk, and Compliance (Grc)
May 2024 — Present · Davidson County, NC, US
Established and operationalized a Governance, Risk, and Compliance (GRC) function aligned with the enterprise\'s strategic vision. Report directly to the VP of Cybersecurity & Infrastructure and collaborate with executive leadership. Report directly to the VP of Cybersecurity & Infrastructure and serve as a strategic partner to executive leadership. Responsibilities include policy and standards development, third-party risk management, business continuity, disaster recovery, training & awareness, and compliance via a NIST CSF-aligned Cybersecurity Compliance Assessment Program (CCAP). Utilize technical expertise across modern and legacy systems to identify, evaluate, and report security risks, and drive risk-mitigation strategies with business and IT stakeholders. Implemented a modern GRC platform for centralized workflow as well as being the single source of truth for policies, risk management, compliance standards, third-party risk, and BC/DR management — improving visibility, consistency, and accountability across the enterprise. Implemented a risk-driven approach to cybersecurity governance, including the launch of a continuous maturity program and a suite of KPIs/KRIs to measure control effectiveness and program performance. Strengthened third-party risk and access management practices by enhancing vendor control validation processes, data protection oversight, and network access review rigor. Directed the global business continuity and disaster recovery strategic and tactical approach, integrating it with broader enterprise risk and operational resilience efforts. Designed and executed a robust cybersecurity compliance program, aligning policies and standards with NIST controls, and developed a comprehensive compliance assessment process based on these controls. Serve as a strategic security risk advisor, collaborating with business units to mitigate key IT risks and align new IT initiatives with business goals
Education
Buffalo State University
Bachelor’s Degree, Computer Information Systems
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.