Hoshedar Mana

Hoshedar Mana

About

Detail

VP, Head of Information Security Office (ISO) and AI Governance
Chicago, Illinois, United States

Timeline


work
Job

Résumé


Jobs verified_user 0% verified
  • Motive
    VP, Head of Information Security Office (ISO) and AI Governance
    Motive
    Sep 2021 - Current (5 years 1 month)
    Implement an ISO function by developing & enforcing security policies, standing up a pragmatic GRC program (control framework ownership, risk register governance, policy/standard-to-control mapping, third-party risk management, audit/cert readiness, continuous control monitoring, and evidence automation), monitoring compliance, preserving data privacy, managing a co-sourced Incident Response Team, overseeing ID & Access Management, maintaining security architecture & overall posture, developing digital forensics capabilities, formalizing a Product Security practice and contributing towards the development of a Disaster Recovery Plan. Additionally, manage AI governance by establishing frameworks, policies, and oversight mechanisms to ensure
  • Deem Inc
    Chief Information Security Officer
    Deem Inc
    Sep 2017 - Jul 2021 (3 years 11 months)
    A progressive modern mobile, SaaS based cloud business travel solution that allows employees to quickly shop for, book, and manage their travel in a secure and compliant manner. Responsible for leading Cyber Security - Zero Trust Architecture approach, Governance and Compliance program in addition Data protection, Cloud Security and Operational Risk Management practices

    Key Achievements

    - Drive innovation and the speed of development to get products to market, while being effective at securing the business in the design, management, and compliance of all software, platform and operations

    - Direct cross functional Resiliency, Threat Assessments including Incident Detection / Response and Vulnerability Managem
  • Movius
    Chief Information Security Officer
    Movius
    Sep 2017 - Aug 2019 (2 years)
    Established and led the Information Security practice from grounds-up

    Key Achievements

    - Formulate and drove a Security Strategies in line with business objectives, overall threat landscape and acceptable risk posture

    - Developed and maintain a Privacy, Data Protection and Cyber Security Program that integrates requirements across various compliance mandates, including PCI DSS, HIPAA, HITRUST, NIST, SOC 2/SSAE-18 & ISO frameworks

    - Ensure the security frameworks were compliant with applicable laws & contractual obligations. This involves maintaining current knowledge of changing regulations, identifying appropriate implementation plans and ensuring that requirements are being met

    - Dro
  • AIG
    Head of Information Security, Privacy Compliance & Adherence - Global Share Services
    AIG
    Sep 2015 - Jun 2017 (1 year 10 months)
    Managed a global Information Security & Privacy, Enterprise/Operational Risk Management & Compliance practice in AIG’s eight Shared Service Centers across Asia, Europe and Americas.

    Key Achievements

    - Implemented a robust Governance & Information Security framework including re-alignment of each discrete security discipline such as Incident Management, Threat & Vulnerability Management, Monitoring, logging and analysis with accepted best practices.

    - Key point of contact for Information Security Incidents, oversee development of response plans. Responsible for coordinating compliance assessment which includes internal audits, US and EU regulators and FFIEC assessments

    - Worked effectively with C
  • Oracle
    Sr. Director - Security and Privacy Practices
    Oracle
    Oct 2011 - Sep 2015 (4 years)
    A global software giant that develops and sells database software and technology, cloud engineered systems and enterprise software products and solutions. Performed independent assessments and advisory services across the organization

    Key Achievements

    - Assessed Oracle’s global privacy & security practice which focused on global product development activities, technology deployments and future aspirations of the company

    - Assisted the key stakeholders in the establishment of sustained organization-wide security technology standards, process improvements, governance processes and performance metrics to ensure that people, process and technology mitigate persistent threats and meet reliability standards adopt
  • Avon Products Inc
    Senior Leader - Information Security
    Avon Products Inc
    Apr 2007 - Sep 2011 (4 years 6 months)
    It is one of the largest beauty company with more than 6 millions sales representatives and the second largest direct-selling enterprise globally. Minimized risk exposure by starting a strong IT Security and operational assessment practice and reviewing all aspects of infrastructure supporting internal operations that connects and enables the business to representatives including E-commerce payments

    Key Achievements

    - Assessed the strategic direction of IT and privacy legal orgs. to reflect and support the business strategies and underlying laws

    - Developed a trusted advisor relationship with members of the legal, technology and operations community which resulted in an effective program of coverage, integr
  • Pfizer
    Security Assessment Executive
    Pfizer
    Feb 2006 - Apr 2007 (1 year 3 months)
    One of the world’s largest Pharmaceutical company that develops and produces medicines and vaccines for a wide range of medical disciplines. Reenergized the traditional assessment practice by introducing an integrated assessment approach within Pfizer’s global practice. The outcome of this approach was duly complemented and acknowledged by the business leaders as a value-added function

    Key Achievements

    - Developed testing methodology to assess SAP/Oracle ERP configurations and enhanced the effectiveness of testing system controls. Performed Data Privacy & Identity Access Management review and identified critical gaps/exposure for immediate action

    - Worked with the compliance teams on planning, execution and
  • Ernst  Young
    Senior Manager - Technology and Security Risk Services (TSRS)
    Ernst Young
    Jan 1998 - Jan 2006 (8 years 1 month)
    Extensive professional experience at different management levels (Asia, Middle East, Africa and US) in assurance, security and privacy consulting, risk management, corporate governance, including implementing, supporting, and enhancing enterprise applications

    Key Achievements

    - Served various clients as engagement lead in various sectors - manufacturing, pharmaceuticals, consumer health, information technology, service oriented & financial services

    - Directed, trained & managed multiple engagement teams in performing, operational and technology assessments including sensitive investigations, SOX consulting for non-resident US companies in Asia & Africa, Quality Assurance initiatives, infrastructure, securi
Education verified_user 0% verified
  • Karachi University
    Bachelor of Business Administration - BBA
    Karachi University
  • IAPP  International Association of Privacy Professionals
    CIPT, Advanced Privacy Studies
    IAPP International Association of Privacy Professionals
  • P
    Fellow - Public Finance Accountants, Finance and Financial Management Services
    PIPFA
  • Isaca
    CISA, Specialize in Information Systems Audit and Controls
    Isaca
This is a community-created genome.