Surya Sagar Vaddiparti
Information Security Officer (Iso) @City of Portland, Maine
Signup · Get unlimited contacts
WORK HISTORY
Information Security Officer (Iso) @City of Portland, Maine
Portland, ME, US
I oversee the city’s cybersecurity programs, ensuring compliance with NIST standards, HIPAA, PCI-DSS, and CJIS while protecting critical assets. My responsibilities include developing and maintaining security policies, standards, and procedures, conducting third-party risk assessments, and managing security audits. I design and enforce role-based access controls through Active Directory and leverage SIEM and EDR tools to enhance threat detection and response capabilities. Additionally, I implement vulnerability management strategies, establish data loss prevention protocols, and lead security awareness programs to strengthen the city’s overall security posture. By optimizing the cybersecurity budget, I ensure resource efficiency and foster organizational resilience.
EDUCATION
The Sun School
Primary to Lower Secondary Education, Class 1 to 10
Northeastern University
Master of Science - MS, Cybersecurity
Amrita Vishwa Vidyapeetham
Bachelor of Technology - BTech, Computer Science and engineering
Sri Chaitanya College of Education
Higher Secondary Education, Mathematics, Physics, Chemistry - MPC
ABOUT SURYA SAGAR VADDIPARTI
Cybersecurity professional with a passion for bridging technical expertise and real-world impact. With experience across government, enterprise, and SaaS environments, I’ve led initiatives that reduce risk, strengthen defenses, and align security with business goals.As the Information Security Officer for the City of Portland, I drive strategic initiatives—from policy development and incident response to third-party risk assessments and alignment with NIST, PCI-DSS, HIPAA, and CJIS. My work has reduced critical vulnerabilities by over 60%, cut phishing success rates by 80%, and enabled scalable onboarding and access management.At Oracle, I delivered cloud security solutions for enterprise clients, automated IAM processes, and completed 50+ risk assessments aligned with ISO 27001 and NIST SP 800. I’ve also contributed to GRC transformation at BitSight by streamlining vendor risk workflows and automating audit preparation.I like building things that make security better—whether it’s scripting automations, analyzing how systems behave, or exploring new ideas out of curiosity. My approach is hands-on and engineering-driven, focused on understanding how things work and how to improve them.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.