Samantha Cowan

Trust Architecture for SaaS & AI | Building Security, Privacy & AI Governance Programs That Hold Up Under Enterprise Scrutiny

Role
Head of Information Security, Privacy and Grc at Nylas
Location
La Crosse, WI, US
LinkedIn followers
500 followers

About Samantha Cowan

Most companies don’t struggle with compliance because they lack controls.They struggle when those controls get tested.Enterprise buyers are asking different questions now — not just whether you have SOC 2 or ISO, but how your program actually operates, how evidence is generated, and how much rigor sits behind the audit itself.That’s where gaps show up. And in many cases, those gaps don’t appear until a deal is already at risk.I work with SaaS, AI, and data-driven companies to build security, privacy, and AI governance programs that hold up under real scrutiny — not just audits.Over the past decade, I’ve led governance, risk, compliance, and security programs for high-growth companies, with a track record of successful outcomes across SOC 2, ISO 27001/27701, PCI-DSS, FedRAMP, and global privacy frameworks.My focus has consistently been on building programs that:• Align with engineering workflows• Scale with the business• Support enterprise sales and customer trustI’m the founder of Lodestone Security Group, where I advise companies on how to structure compliance programs that translate into real enterprise confidence — not just certifications.This includes:• SOC 2 / ISO readiness and program design• AI governance and emerging regulatory alignment• Privacy and data protection architecture• Enterprise trust and audit strategy

Experience

  1. Head of Information Security, Privacy and Grc

    Nylas

    Aug 2022 — Present · US

    Strategic Leadership: Proactively forecasts and develops the department roadmap, aligning initiatives with broader business objectives to drive organizational growth.• Process Optimization: Innovatively streamlines business processes, significantly reducing workload and headcount requirements while simultaneously boosting operational efficiency.• Comprehensive Program Management: Assumes full responsibility for the company’s Security, Information Technology, Compliance, and Privacy Programs, ensuring robust and compliant operations.• Privacy Program Overhaul: Successfully revamped the entire company privacy program within six months of joining, demonstrating exceptional agility and expertise in privacy matters.• ISO 27701 Certification Achievement: Led the initiative to obtain ISO 27701 certification within one year of hire, achieving this significant milestone with a reduced team size.• Compliance Framework Expansion: Skillfully guided the company to compliance with additional privacy and financial frameworks, adeptly managing resources to maintain lean operations.• Vendor Management Program Implementation: Established and implemented a comprehensive vendor management program, enhancing vendor relations and oversight.• Privacy Program Advancements: Implemented key elements of the privacy program, including privacy by design and a Data Protection Impact Assessment (DPIA) process, fortifying data privacy practices.• Automation Initiatives: Continues to increase automation within standard team processes, streamlining tasks and improving team efficiency and productivity.• Audit Time Reduction: Effectively reduced the time spent in audits, optimizing resource use and minimizing disruptions to business operations.

Education

  • University of Maryland Global Campus

    Graduate Certificate, Cybersecurity Technology

    2012 — 2014

  • University of Oregon

    Political Science and Government

    2002 — 2003

  • University of Maryland Global Campus

    Master of Science (MS), Cybersecurity

    2012 — 2013

  • University of Maryland Global Campus

    Master of Business Administration (M.B.A.), Business Administration and Management, General

    2014 — 2014

  • Oregon State University

    Bachelor of Science (BS), Liberal Arts and Sciences/Liberal Studies

    2010 — 2011

  • Southern Oregon University

    Political Science and Government

    2009 — 2010

  • Lane Community College

    Political Science and Government

    2000 — 2001

  • University of Maryland Global Campus

    Graduate Certificate, Foundations of Cybersecurity

    2012 — 2014

Skills

  • Windows 7
  • Visio
  • Data Entry
  • Editing
  • Community Outreach
  • Cloud Computing
  • Intrusion Detection
  • Project Management
  • Event Planning
  • Research
  • Information Security
  • Program Management
  • Incident Response
  • Technical Support
  • Data Analysis
  • Training
  • Amazon Web Services (Aws)
  • Writing
  • Procurement
  • Policy
  • Patch Management
  • Microsoft Word
  • Troubleshooting
  • Information Technology
  • Networking
  • Continuity of Operations
  • Time Management
  • Databases
  • Program Coordination
  • Microsoft Office
  • Policies & Procedures Development
  • Public Speaking
  • Leadership
  • Access
  • Computer Security
  • Cyber-Security
  • Government
  • Information Security Management
  • Help Desk Support
  • Security

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Samantha Cowan — Head of Information Security, Privacy and Grc at Nylas in La Crosse, WI, US | Unifers