Linda K.
Cloud Security, Risk, Privacy | CIPP/E, PCI ISA
- Role
- Information Security Saas Assurance and Risk at Block
- Location
- Portland, OR, US
- LinkedIn followers
- 500 followers
About Linda K.
Security and Privacy SME specializing in building and growing services, lines of business, and right-sized programs. Over 15 years of working in the Information Security, Privacy, and GRC arenas. I’ve helped organizations build programs from the ground up, align their security architecture and dataflows to best practices, conduct risk assessments and prioritize implementation plans, achieve security certifications, understand how to navigate customer vendor security processes, and more.I\'ve worked in-house on both the product and enterprise sides, building risk programs, security-focused privacy and data governance programs, and advisory lines of business, many of which had visibility at the board and C-suite levels. Independent self-starter, adaptable to changing needs, strategic about long-term impacts. Fluent in helping organizations navigate FedRAMP, NIST, ISO 27001/27017/27018, SOC 2, GDPR/CCPA, PCI, HIPAA HITRUST, and TISAX standards.
Experience
Information Security Saas Assurance and Risk
Apr 2023 — Present
Execute on a top-down approach to reduce risk holistically across the Block enterprise, conducting security reviews and risk-based assurance activities for 3,300+ applications, and determining risk management strategies for application, data, and vendor use aligned to their classification/profile.Remove silos and establish a cross-functional solution as the product manager for an AI-driven, homegrown continuous monitoring tool that centralizes infosec requirements from international/federal regulations, certifications such as PCI and SOC 2, and partner teams. Liaise with privacy, legal, GenAI, product security, third party risk management, corporate security, GRC, threat intelligence, communications, and other teams to ensure alignment with risk activities and promote safe use of data and third party applications.Manage audit inquiries and represent key program activities to auditors; the results of these activities are reported to the board with C-suite visibility.Focus analysis on high priority security risks and make decisions based on what would make the largest impact on security out of limited resources.Work with product and other internal teams to advise on security requirements early in the process for large development initiatives (security by design).Evaluate third party security risk and data safety across the enterprise as the owner of a critical security workstream, continually adapting to industry changes such as the use of generative AI, reports of enhanced threat vectors, large-scale breaches, etc.Ensure effective security communications for key program initiatives and developing requirements, conduct continuous training and education outreach, overhaul of assets to engender continued legitimacy of program developments.Conduct security research to enable data-driven decision making.Provide risk analysis and security assurance training to other internal teams.
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.