Leonid Beryozkin
Information Security Governance Manager
- Role
- Information Security Grc at Blue Cross Blue Shield Association
- Location
- Chicago, IL, US
- LinkedIn followers
- 500 followers
About Leonid Beryozkin
Security & Risk leader in regulated healthcare who turns AI ambiguity into governed, measurable outcomes. I build guardrails people actually use across the full lifecycle—use-case intake, data classification, privacy/legal review, model/agent approval, deployment controls, monitoring, and audit-ready evidence mapped to NIST CSF 2.0, SOC 2, and HITRUST. Platform coverage includes OpenAI, Anthropic, and enterprise copilots/foundation models.Current focus: enterprise AI governance (zero-retention paths, prompt/response controls, evaluations with human-in-the-loop), platform risk (access, logging, secrets, BCDR), data protection/DLP that changes behavior, and supplier risk as one lane—not the whole highway. Plain talk with executives; precise detail with engineer
Experience
Information Security Grc
Blue Cross Blue Shield Association
Mar 2021 — Present · Chicago, IL, US
Governance and Compliance Manager with over 8 years of experience in leading and managing the third party risk oversight program across BCBSA, including the Enterprise Data Loss Prevention Program, the Phishing Program and training, and management metrics/reporting. Managed more than 300 vendors and educated senior management on all risks from the use of third parties. Prepared BCBSA enterprise to respond effectively to incidents, including appropriate use of simulation exercises/testing, and creation of supporting documentation.
Education
State University of New York - System
BS, Finance
1987 — 1991
Skills
- Information Security Policy
- Information Technology
- Computer Security
- Incident Management
- Cobit
- Business Continuity
- Vendor Management
- IT Risk Management
- Program Management
- Cyber Security
- Privacy Law
- Pci Dss
- Data Privacy
- Information Security
- Governance
- Vulnerability Management
- Data Security
- Disaster Recovery
- Cissp
- IT Service Management
- Enterprise Risk Management
- Application Security
- Security Awareness
- Security
- Business Continuity Planning
- Iso 27001
- Glba
- IT Management
- Operational Risk Management
- Sox
- Ffiec
- IT Audit
- IT Strategy
- Risk Management
- Penetration Testing
- Information Security Management
- Compliance
- Vulnerability Assessment
- Sas70
- Internal Controls
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.