Played a pivotal role in guiding the organization through regulatory audits, ensuring full compliance with industry standards including GDPR, ISO 27001, PCI-DSS, and SOC2 Type 2 audits. Achieved nearly a 50% reduction in external auditing costs while enhancing and broadening the scope of the process. Conducted comprehensive risk assessments and audits to identify vulnerabilities and mitigate potential threats, resulting in a estimated 15% reduction in security incidents. Collaborated cross-functionally with IT teams to enhance security protocols and deploy advanced monitoring tools, bolstering the company's defense against cyber threats. Proactively provided training and awareness programs to staff members, fostering a culture of security and business continuity consciousness and promoting best practices across the organization.
Delivering audits on ISO 27001 - Information Security, ISO 22301 - Business Continuity, BV Data Protection Scheme (GDPR), ISO 37001 – Anti-Bribery, ISO 55001 – Asset Management, ISO 20000 – IT Service Management, PCI-DSS and ISO 9001 Quality Management Systems.
Creating a mobile app to bring thousands of members closer, retrieve medical study results, and provide emergency contacts while ensuring Data Privacy was maintained.
Achieved 112-man hours/month (70%) savings on energy rating assessments preparation by back-office through automation of information extraction from building models, freeing assessors from a manual and error-prone process.
Helped clients design privacy and information security-oriented infrastructure (hybrid, public and private).
1,200% increased sales of Transport Management Solution through bespoken mobile application with full end to end integration, allowing them to offer online paperless process for delivery/transport tracking and cost management. Developed and supported the implementation of IT strategy and processes for multiple organisations, including disaster recovery strategies, resulting in improved SLAs to best practice levels. Worked with major telecoms: SAPO, the biggest Internet Service Provider for Portugal as a project mentor and Vodafone Portugal on router testing.
Performed Gap Analysis and Internal Audits to help small and medium enterprises fully and properly manage their information security and data protection risks towards an ISO 27001 certification. Defined customer-facing interfaces and improved internal processes to support strategic business relations.
Defined and implemented ISO 27001 oriented policies and controls and made progress towards ISO certification. Enabled cost reductions that allowed competitive bids that won the company long term clients like Mercedes-Benz and Mitsubishi by automating the motor vehicles registration process in Portugal. Defined the IT systems and strategy for the company, managed the IT Support team continuously improving service levels and always guaranteeing the ability to recover from disasters. Improved communication inside the company with an intranet portal including document management systems to support the Quality and Information Security System Management Systems (ISO 9001 and ISO 27001).
Discover other experts with similar qualifications and experience