Diana Esparza

Diana Esparza

About

Detail

Information Security | Expert in Cybersecurity Strategies, Risk Management, and Security Training Programs
Irvine, California, United States

Contact Diana regarding: 
work
Full-time jobs

Timeline


work
Job
school
Education
folder
Project

Résumé


Jobs verified_user 0% verified
  • Alteryx
    Information Security Third-Party Risk Management/Training & Awareness Program Owner
    Alteryx
    Jan 2022 - Current (4 years 9 months)
    Transformed Security Training and Awareness Program from Stage 2 compliance-based to Stage 3 promoting awareness and behavioral change in the SANS Security Awareness Model, achieving a comprehensive and maturity-focused approach.

    Developed a Human Risk Score Methodology for internal assessments, integrating quantitative likelihood and impact factors to quantify and address risks effectively.

    Developed and executed a comprehensive Security Training and Awareness Program, including spearheading engaging initiatives for Cybersecurity Month. The program featured curated content, videos, games, and prizes, aligning with organizational risks.

    Achieved higher completion rate in the 2023 Security Annual Training, su
  • Zions Bancorporation
    Information Technology Risk Manager
    Zions Bancorporation
    Nov 2020 - Jan 2022 (1 year 3 months)
    Contributed to the development of a robust risk culture and championed risk ownership across all organizational levels by implementing and promoting the company’s comprehensive IT Risk Management Framework, inclusive of well-defined risk tolerances.

    Conducted thorough risk assessments, delivering presentations to Senior Leadership in risk committees and councils, including the CIO. Empowered leadership with the necessary information to make informed decisions based on risk evaluations.

    Achieved an 80% reduction in end-of-life and end-of-support assets across the organization, enhancing overall security posture and compliance.

    Collaborated with critical operations teams to establish and monitor key risk indic
  • First American
    Manager, Enterprise Application Security
    First American
    Sep 2018 - Nov 2020 (2 years 3 months)
    Head of an Enterprise Application Security team with a team of 7 in the U.S and India.

    Develop, own, and lead the enterprise’s application security strategies and processes that includes:

    -Vulnerability Assessment
    -Application Security Training
    -SDLC Security Integration
  • First American
    Sr. Information (Cyber) Security Analyst
    First American
    Oct 2016 - Sep 2018 (2 years)
    Leading the Enterprise Application Security team to ensure the security of First American’s applications and data.

    Focused on maintaining awareness of the current landscape and recommend mitigations against threats.

    Communicate and educate software development staff on how to mitigate threats using vulnerability frameworks and guidance such as OWASP, SANS, CVE, and NIST.

    Administration and support of user-facing security tools in support of the vulnerability management program as well as the rollout of new security technologies and processes.

    Spearheaded and implemented a pattern-based Threat Model capability and program for the Enterprise Application Security team; including documentation and
  • First American
    Sr. eDiscovery Analyst
    First American
    Mar 2010 - Oct 2016 (6 years 8 months)
    Assist clients and their legal counsel collect, preserve, and analyze large amounts of electronic stored data for investigations and complex litigation, utilizing discovery and forensics tools.

    All applications cover all portions of the Electronic Discovery Reference Model (EDRM) and the processes used uphold the standards of the Federal Rules of Civil Procedure (FRCP).
  • First American
    Senior Administrative Assistant
    First American
    Sep 2008 - Mar 2010 (1 year 7 months)
    Administrative/Operational support to:

    Vice President, Litigation /Employment Counsel
    Vice President, Intellectual Property Counsel
    Vice President, Corporate Counsel
  • Experian
    Business Continuity Office Adminstrator
    Experian
    Jun 2007 - Nov 2007 (6 months)
    Administrative/Operational support to the Director of Business Continuity Services.

    Back-up support to the Senior Vice President, Chief Information Security Officer.
  • New Century Mortgage
    Executive Assistant
    New Century Mortgage
    Sep 2004 - Jun 2007 (2 years 10 months)
    Administrative and operational support to Vice President, Chief Security Officer and staff of eighteen that included:

    Information Security
    Business Continuity
    Fraud Investigations
    Physical Security
Education verified_user 0% verified
  • Santa Ana College
    Associate of Arts - (A.A, Social & Behavioral Science
    Santa Ana College
    TRAINING:
    Defending Web Applications Security Essentials (SANS),
    Cybersecurity and Ethical Hacking Part 1 (SaiSoft),
    Strengths Finders Coaching

    Gallup Strengths: Input, Intellection, Learner, Connectedness, Relator

    ITIL Foundation Certification in IT Service Management

    Leadership
  • Santa Ana College
    Associate of Science (A.S, Business Administration
    Santa Ana College
  • California State University Fullerton
    Bachelor of Business Administration - BBA, Management Information Systems, General
    California State University Fullerton
Projects (professional or personal) verified_user 0% verified
    Awards verified_user 0% verified
    • C
      Cheers for Peers
      Diana stepped up to sponsor an idea she submitted for the Agents of Change (AoC) and has done a great job with a challenging project. Her project has needed to shift directions a couple of times to better align with policies and our culture at First American. But she has been undaunted despite her limited experience in managing this type of project. She's done a superb job of building a team, identifying a clear outcome, collaborating with key stakeholders (like HR and Corporate Learning and Development). She's sustained a positive attitude and helped her team stay focused on the outcome versus the process. Her project is now merging with a coroprate-wide initiative which demonstrates what great insight she had in submitting her idea!
    This is a community-created genome.