Wendy Athanas
AVP, IT Risk and Compliance, Crisc, Cism, Cisa, Cdpse @Sammons Financial Group Companies
Signup · Get unlimited contacts
WORK HISTORY
AVP, IT Risk and Compliance, Crisc, Cism, Cisa, Cdpse @Sammons Financial Group Companies
San Antonio, TX, US
Responsible for the overall IT Risk and Compliance program, including-Developing, implementing, and maintaining IT risk management methodologies -Conducting regular Company information security risk assessments -Working collaboratively with Enterprise Risk Management, Internal Audit, Legal and Compliance to appropriately manage information risk in alignment with established risk, legal and compliance risk tolerances and methodologies -Developing and implementing IT risk and security policies -Monitoring information risks, mitigation and remediation efforts -Understanding and monitoring the regulatory environment, and ensuring compliance with applicable regulations -Working with IT and entire staff to ensure their compliance with IT and risk security policies -Overseeing the Identity and Access Management program -Developing and implementing a security awareness program -Developing and implementing an IT controls framework -Working with IT to assist them selecting appropriate control activities; measuring and monitoring those control activities -Coordinating IT activities in response to Internal Audit requirements -Providing oversight of audit, regulatory and risk management activities across IT functional areas -Coordinating the IT component of both internal and external audits, federal and statement examinations related to information security -Ensuring compliance with Model Audit Rule controls -Providing IT risk consulting -Directing IT Risk and Compliance team activities -Continuously monitoring the risk function, identifying, developing and implementing process improvements
EDUCATION
Metropolitan State University of Denver
Technical Communication
ISACA
CISM, Certified Information Security Manager
ISACA
CRISC, Certified in Risk and Information Systems Control
ISACA
CDPSE, Certified Data Privacy Solutions Engineer
ISACA
CISA, Certified Information Security Auditor
ABOUT WENDY ATHANAS
AVP, IT Risk Manager with expertise in leading IT professionals to assess and manage security and risk within complex IT environments. Skilled in IT/Business alignment, IT security policy development and implementation, Business Impact Analysis, Risk Assessments, Vendor Risk Assessments, Gap Analysis, Regulatory Compliance and Project Management. Key core qualifications include: Information Risk Management, Vendor Risk Management, Risk Assessments (ISO 27002, NIST Cybersecurity Framework, High-Level Risk Assessments, Detailed Assessments), Disaster Recovery/Business Continuity Planning, Project Management, Process Improvement, Security Policy Development, Regulatory Compliance, IT Management, IT Controls, Gap Analysis and Remediation, Managing Large Budgets ($21M), Strategic Planning, Security Awareness, Security/Risk Maturity Models
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.