Wendy Athanas

AVP, IT Risk Management, Sammons Financial Group Member Companies, CRISC, CISM, CISA, CDPSE

Role
AVP, IT Risk and Compliance, Crisc, Cism, Cisa, Cdpse at Sammons Financial Group Companies
Location
Clayton, NC, US
LinkedIn followers
500 followers
Information TechnologyView LinkedIn profile

About Wendy Athanas

AVP, IT Risk Manager with expertise in leading IT professionals to assess and manage security and risk within complex IT environments. Skilled in IT/Business alignment, IT security policy development and implementation, Business Impact Analysis, Risk Assessments, Vendor Risk Assessments, Gap Analysis, Regulatory Compliance and Project Management. Key core qualifications include: Information Risk Management, Vendor Risk Management, Risk Assessments (ISO 27002, NIST Cybersecurity Framework, High-Level Risk Assessments, Detailed Assessments), Disaster Recovery/Business Continuity Planning, Project Management, Process Improvement, Security Policy Development, Regulatory Compliance, IT Management, IT Controls, Gap Analysis and Remediation, Managing Large Budgets ($21M), Strategic Planning, Security Awareness, Security/Risk Maturity Models

Experience

  1. AVP, IT Risk and Compliance, Crisc, Cism, Cisa, Cdpse

    Sammons Financial Group Companies

    Jun 2017 — Present · San Antonio, TX, US

    Responsible for the overall IT Risk and Compliance program, including-Developing, implementing, and maintaining IT risk management methodologies -Conducting regular Company information security risk assessments -Working collaboratively with Enterprise Risk Management, Internal Audit, Legal and Compliance to appropriately manage information risk in alignment with established risk, legal and compliance risk tolerances and methodologies -Developing and implementing IT risk and security policies -Monitoring information risks, mitigation and remediation efforts -Understanding and monitoring the regulatory environment, and ensuring compliance with applicable regulations -Working with IT and entire staff to ensure their compliance with IT and risk security policies -Overseeing the Identity and Access Management program -Developing and implementing a security awareness program -Developing and implementing an IT controls framework -Working with IT to assist them selecting appropriate control activities; measuring and monitoring those control activities -Coordinating IT activities in response to Internal Audit requirements -Providing oversight of audit, regulatory and risk management activities across IT functional areas -Coordinating the IT component of both internal and external audits, federal and statement examinations related to information security -Ensuring compliance with Model Audit Rule controls -Providing IT risk consulting -Directing IT Risk and Compliance team activities -Continuously monitoring the risk function, identifying, developing and implementing process improvements

Education

  • Metropolitan State University of Denver

    Technical Communication

    2006 — 2010

  • ISACA

    CISM, Certified Information Security Manager

    2011 — 2011

  • ISACA

    CRISC, Certified in Risk and Information Systems Control

    2021 — 2021

  • ISACA

    CDPSE, Certified Data Privacy Solutions Engineer

    2020 — 2020

  • ISACA

    CISA, Certified Information Security Auditor

    2008 — 2008

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Wendy Athanas — AVP, IT Risk and Compliance, Crisc, Cism, Cisa, Cdpse at Sammons Financial Group Companies in Clayton, NC, US | Unifers