Shane York
Director of Security Governance, Risk, and Compliance @Scout Motors Inc.
Signup · Get unlimited contacts
WORK HISTORY
Director of Security Governance, Risk, and Compliance @Scout Motors Inc.
IN, US
EDUCATION
George Mason University – Costello College of Business
Master of Science (M.S.), in Management of Secure Information Systems, Cybersecurity
Baruch College
Bachelor of Arts (B.A.), Political Science, Japanese
SKILLS
ABOUT SHANE YORK
I am an information security, governance, risk, and compliance leader with more than 17 years of experience helping organizations assess, implement, and mature their information security governance, risk, and compliance functions and programs. I consider myself a “hands-on” leader and am very comfortable digging into the fine aspects and functions of each of the GRC pillars and how they relate to each other. I have extensive experience with most domestic and international security frameworks and standards (NIST Special Publications, NIST CSF, PCI, ISO series, HITRUST, SOC, HIPPA, C5, CS Mark Gold, etc.) to include the implementation, assessment, and reporting/remediation functions of each. I have built and managed information security risk programs at multiple companies, to include risk analysis models, risk registers, risk assessments, and risk reporting functions. I have spent years developing control mappings and common control framework programs to build efficiencies on the control implementation/management side, along with streamlining evidence collection and external audits. I am very comfortable working with disparate teams in varied geographic locations to drive security functions to be in alignment with organizational goals and strategies. Lastly, I have a deep passion for the GRC space and truly believe that with security controls accurately defined, implemented, periodically assessed, and remediated, the risk exposure of an organization can be significantly decreased, allowing resources to be more effectively applied to other more targeted and persistent attacks. Personality Type (Gallup StrengthsFinder): Learner, Responsibility, Analytical, Achiever, and IntellectionCertificationsInformation Systems Security Management Professional (ISSMP)Certified Information Systems Security Professional (CISSP)Certified Information Systems Auditor (CISA)Certified in Risk and Information Systems Controls (CRISC) Certified ISO/IEC 27001 MasterCertified ISO/IEC 27001 Lead Implementer (ISO27XLI)Certified ISO/IEC 27001 Lead Auditor (ISO27XLA)Certified ISO/IEC 27001 Risk Manager (ISO27KRM)Certified ISO/IEC 22301 Lead Auditor (ISO22301LA)Certified CompTIA A+ TechnicianCertified CompTIA Network+ TechnicianSpecialties: Cyber Security Controls, IT Governance & Risk, Cyber Law
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.