Jonathan S.
Director, Enterprise Cybersecurity Governance & Risk | Dual Scope: Aptiv + Wind River | Global GRC, TPRM & Resilience Leader | Board & Audit Committee Reporting
- Role
- Head of Cybersecurity Grc, Tprm, Resilience & Training (Director) Dual Scope Aptiv & Wind River at Aptiv
- Location
- Boston, MA, US
- LinkedIn followers
- 500 followers
About Jonathan S.
Strategic cybersecurity executive with 12+ years leading global GRC, third-party risk, and resilience programs across tech, finance, manufacturing, and defense. Proven ability to scale enterprise controls, align security with business goals, and operationalize frameworks like NIST 800-171, ISO 27001, SOX, CMMC, and SOC 2. Trusted by CISOs, CIOs, and legal teams to deliver security, compliance, and risk outcomes in complex enterprise and M&A environments.
Experience
Head of Cybersecurity Grc, Tprm, Resilience & Training (Director) Dual Scope Aptiv & Wind River
Feb 2022 — Present · Boston, MA, US
Lead enterprise IT cybersecurity risk management across Aptiv employees), Wind River, and multiple wholly owned subsidiaries. Oversee cybersecurity governance, compliance, third-party risk, and resilience across multiple legal entities. Report directly to the Global CISO and senior IT leadership.• Lead 4 cybersecurity departments: GRC, TPRM, Resilience, and Security Awareness & Training.• Provide oversight and alignment across global entities and regions.• Own implementation of cybersecurity frameworks (NIST 800-171, ISO 27001, SOX, CMMC, TISAX) across IT, Legal, HR, and Engineering.• Manage enterprise risk register, SSP, POA & Ms, and board-level KPIs.• Coordinate and lead SOX, ISO 27001, NIST, TISAX, and internal audit walkthroughs.• Support U.S. government contracts and commercial audits across Aptiv and Wind River.• Conduct M&A due diligence, pre-acquisition risk assessments, and post-merger alignment.• Oversee TISAX certification and Transitional Service Agreement (TSA) compliance for Aptiv’s EDS spin-off.• Deliver CISO and Board dashboards, risk heatmaps, and remediation tracking.• Direct third-party risk program using BitSight and AuditBoard; assess thousands of vendors.• Lead customer contract security reviews, pre-sales assessments, and vendor compliance monitoring.• Drive disaster recovery and business continuity planning, including testing for 30+ critical systems.• Maintain cybersecurity policies, control narratives, and documentation libraries.• Led enterprise rollout of AuditBoard for IT GRC/TPRM workflows.• Migrated phishing platform from Proofpoint to KnowBe4; oversee global phishing simulations and awareness campaigns for employees.
Education
Northeastern University
Master of Science, Information Assurance
Bentley University
Bachelor of Science, Accountancy
Skills
- Computers
- Website Development
- Smartdraw
- Analysis
- Ftk
- Encase
- Information Technology
- Web Design
- Python
- Apple Safari
- Powerpoint
- Microsoft Excel
- SEO
- IT Audit
- Hubspot
- Computer Hardware
- Software Installation
- Marketing
- Wordpress
- Blackberry
- Microsoft Office
- Microsoft Publisher
- Information Assurance
- Apple Os
- Iphone
- Visio
- Windows 7
- Software Implementation
- Auditing
- Internal Audit
- Android
- Internal Controls
- Microsoft Exchange
- Blackberry Os
- Networking
- Iphone Support
- Accounting
- Computer Repair
- Microsoft Word
- Team Leadership
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.