Kim Thomas
Principal - Enterprise Information Security & Resilience @ Optum | UHGCISA || CISM || PMP || ITIL || ISO270001 || BS25999 || CEH || PCI || AZ900 || IBM Agile || BCP & DRP || IS Audits
- Role
- Principal - Enterprise Information Security (Governance, Vulnerability Management & Remediation) at Optum
- Location
- Hyderabad, TG, IN
- LinkedIn followers
- 500 followers
About Kim Thomas
With over two decades of leadership experience across India, Mexico, and the USA, I have driven large scale programs in information security governance, compliance, risk management, and information assurance for global enterprises.I specialize in building and leading security strategies that align with business objectives covering solution design, implementation, and operational excellence. My focus has consistently been on transforming security frameworks into business enablers that strengthen trust, resilience, and compliance readiness.Throughout my journey, I have led critical initiatives including vulnerability and risk management, incident response, change management, corporate audits (internal & external), third-party vendor risk assessments (domestic & international), and forensic investigations on software piracy. I have also spearheaded enterprise-wide security awareness programs, driving a culture of accountability and security mindfulness.Passionate about continuous learning and innovation, I aim to bridge technology, governance, and leadership to build secure, high performing organizations prepared for the future with AI assistance.Specialties & Leadership Expertise- Strategic Information Security Governance and Enterprise Risk Leadership- Regulatory Compliance & IT Audit Management (Internal and External)- Vendor Risk Governance and Third-Party Security Assessments- End-to-End Vulnerability & Incident Management Programs- Business Continuity Planning (BCP) & Disaster Recovery (DR) Strategy and Execution- Cybersecurity Program Development and Maturity Improvement- Data Protection, Privacy, and Information Assurance Frameworks- Fraud Investigation, Forensics, and Prevention Controls- Cyber Threat Intelligence and Risk Mitigation Strategy- Application Security Oversight and Secure SDLC Governance- Global IT Audits & Compliance Alignment (ISO 27001, GDPR, HIPAA, SOC 2, etc.)- Gap Analysis and Continuous Process Improvement- ISMS Policy, Process, and Control Documentation- Quality Assurance and Operational Excellence in Security DeliveryCertifications- Certified in CISA from ISACA- Certified in CISM from ISACA- Certified in ITIL Foundation Certified (V4) from People Cert - Certified Lead Implementation ISO 27001 from BSI- Certified Ethical Hacker (CEH V4) from EC Council- Certified in Business Continuity Management (ISO22301) from BSI- Certified in PCI-DSS from SISATrainings- Completed CISSP Bootcamp Program from ADEPT Technologies- Completed Project Management Training (PMP) from PMI
Experience
Principal - Enterprise Information Security (Governance, Vulnerability Management & Remediation)
Mar 2023 — Present · Hyderabad, IN
Drive vulnerability management for #Optum /#UHG by collaborating with a team of knowledgeable security experts from around the globe.Use a variety of tools, review all vulnerability scan reports, and share findings to the heads of the appropriate functions and make them aware of the security flaws. Work together to develop a plan for remediation.Accountable for efficient governance, creating a strategy to address critical and high-risk vulnerabilities, and acting as a subject matter expert to offer important feedback. Examine all active and acceptable remediation strategies for all vulnerabilities, both current and past. With the help of BISO/SISO, application owners, data owners, system administrators, the cloud team, and others, discuss and review the plan. Check to see if the remediation plans are carried out in accordance with eGRC standards.Coordination, review, and identification of any potential vulnerability gaps that can give rise to audit issues are necessary. Work proactively with functional leaders to see that issues are resolved quickly and in accordance with SLAs.Respond to pertinent requests for investigation of potential reporting issues and consult for prompt resolution made by stakeholders or stakeholders\' representatives.Deliver to function leaders or SLOs with any necessary data, reports, and presentations on the state of remediation activities, as well as any gaps or possible problems.
Education
Anna University Chennai
B.Sc - Bio-Technology
2000 — 2003
National Institute of Information Technology
Computer Software
2000 — 2003
Skills
- Social Services
- Young Adults
- Mental Health
- Individual Counselling
- Child Welfare
- Psychotherapy
- Case Management
- Adolescents
- Public Speaking
- Crisis Intervention
- Group Therapy
- Interventions
- Cbt
- Mental Health Counseling
- Family Therapy
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.