Tony Poon
Principle Engineer, Information Security Officer @Fibrogen, Inc
Signup · Get unlimited contacts
WORK HISTORY
Principle Engineer, Information Security Officer @Fibrogen, Inc
San Francisco, CA, US
Managed Cyber Security Program, Information Security Risk Management, Threat and Vulnerability Management (TVM) program, and InfoSec daily operations and projects.Notable Accomplishments:Built an Information Security program with policies, procedures, and standards.Information Security Policy, Information Classification Policy, Data Retention Policy, Acceptable Use Policy, Incident Response Policy, Email Policy, Encryption PolicyImplemented identity protection-Single Sign-On (SSO) and multiple Factor Authentication (MFA).Applied email protection-DMARC, SPAM/Phishing, and Business Email Compromise (BEC) protecion.Implemented network access protection - VPN, VLAN, Geo restriction, segmentation, endpoint protection - MDM, EDR, DR/BCP, vulnerability scanning, patching, and CM.Oversaw data and Intellectual Property protection - DLP, MDM, geo-restriction, RBAC, OTP, classification, and insurance.Conducted risk assessment, penetration testing, and internal audit.Prepared ISO/27001 certification.
EDUCATION
SANS - GIAC
GCIH, GIAC Certified Incident Handler
ISACA - Information Systems Audit & Control Association
CISM, Certified Information Security Manager
ISACA - Information Systems Audit & Control Association
CGEIT, Certified in the Governance of Enterprise IT
SANS - GIAC
GAWN, GIAC Accessing & Securing Wireless Networks
ISACA - Information Systems Audit & Control Association
CISA, Certified Information Systems Auditor
Microsoft
MCSE, Microsoft Certified Systems Engineer
Novell Netware
MCNE, Master Degree, Certified Network Engineer
ISC2 - CISSP
CISSP, Certification for Information System Security Professional
SANS - GIAC
GSNA, GIAC Systems & Network Auditor
Cisco
CCNA, Cisco Certified Network Associate
ISC2 - CCSP
CCSP, Certified Cloud Security Professional
SKILLS
ABOUT TONY POON
Passionate, dedicated, and results-driven Cyber Risk Professional with over 10 years of extensive experience in assessing, analyzing, and mitigating cyber risks within diverse organizational landscapes. Adept at implementing strategic risk management frameworks, optimizing security measures, and fostering a culture of cyber resilience. Proven ability to collaborate with cross-functional teams, align security strategies with business objectives, and develop innovative solutions to protect critical assets. Seeking to leverage my expertise and contribute to an organization\'s cyber risk management initiatives for enhanced security and sustained operational excellence.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.