Tom Scarinci
Senior Director of Information Security, Risk and Compliance @Veho
Signup · Get unlimited contacts
WORK HISTORY
Senior Director of Information Security, Risk and Compliance @Veho
Successfully led company through the ISO27001:2013 certification process, including coordination with internal stakeholders and auditors, built the ISMS, created, implemented and evidenced controls. ·Met with prospective and current clients to articulate Veho security practices. ·Engaged in client deal processes to review security addendums and ensure reasonableness and compliance with contracts. ·Implemented the first Information Security Training and Awareness program. 90% of employees completed the required training within 90 days of enrollment in 2023. ·Established strategy and road mapped operational goals and milestones for the InfoSec program including functions of GRC, Audit, IAM, and SecOps. ·Partnered with Product and Engineering leadership for the development, planning, and execution of major security initiatives. ·Created and maintained the Risk Register, as well as the associated Risk Treatment plans, then translated these technical risks to a wide audience of stakeholders, including senior leadership. ·Oversaw a team of Information Security professionals to provide coaching, administer performance reviews, and set short and long term goals and objectives at an individual and team level. ·Developed and maintained Information Security Policies including Acceptable Use, Data Retention, Change Management, and System Access. ·Established and led the Vendor Risk Management program to ensure adequate security practices of our third-party service providers. ·Led initial Business Impact Assessment and then developed and implemented the Business Continuity and Disaster Recovery Plan. ·Developed and defined data governance policies, standards, and controls to secure, protect and defend from threats and attacks. ·Developed and maintained Incident Response Plan and ensured plan was documented, communicated, tested, and validated. ·Analyzed the costs, value, and risks of cybersecurity activities to create a budget and make recommendations based on that budget.
EDUCATION
Seton Hall University School of Law
Certificate in Privacy Law and Cyber Security
University of Delaware
Accounting, Management Information Systems
University of Delaware - Lerner College of Business and Economics
Master's degree, Accounting
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.