Acerca de Fernando
Español
Bilingüe o nativo
Italiano
Competencia profesional básica
Experiencia
- European Commission CybersecuritySenior Manager Engineerseptiembre de 2021 - Hoy (4 años y 9 meses)Italy• Definition and Quality Assessment of IT Risk governance and IT Risk Management process. The mosnt relevant directives I have reviewed are DORA and NIS2.• Definition and Implementation monitoring of the security controls, deploying risk assessments on the control systems of the nuclear power stations.• Dashboard definition to show KPI and KRI to the Commission Directorates.• Incident, vulnerabilities and threats management. Workflows implantation.• Advisory in the improvement of an Information Security Steering Plan (ISMS) based on ISO27001 and GDPR.
- AplazameCISOBANCA & SEGUROSjunio de 2020 - agosto de 2021 (1 año y 2 meses)• Definition and implantation of all the Information Security Business Unit, such as GRC, Security Architecture, Privacy and SOC.• Definition and implantation of Information Security Steering Plan (ISMS) based on ISO27001 , NIST-CSF, CIS, CoBIT, PCI-DSS and GDPR.• Definition and implantation of IT Risk governance and management model.• Implantation of a Security by Design process in all the bus8ness units in the company.• Defining security controls in the AWS infrastructure, helping DevOps Team to implement SecDevOps process.• Dashboard definition to show KPI and KRI to Steering Committee.• IT security normative updating.• Information security budget management.• Member of the Corporative Risk Committee and president of the Information Security Committee.• SOCaaS and CERTaaS setup.• Trainning and awareness plan definition• Incident, vulnerabilities and threats management. Workflows implantation.
- SegurCaixa AdeslasGRC Senior Manager and DeputyCISOenero de 2019 - mayo de 2020 (1 año y 4 meses)Madrid, Spain• Definition and implantation of IT Risk Assessment, identifying stakeholders and relation models.• Definition and implantation of IT Risk classification model.• Dashboard definition to show KPI and KRI to Steering Committee.• Coordination and integration among different technical areas (Cybersecurity, IT Contingency, IT Security Architecture) to establish Global Risk Framework.• IT security normative updating.• Information security budget management.• Member of the Corporative Risk Committee and president of the Information Security Committee.• Definition and management of a compliance assessment process to ensure the Information Security framework implementation.
Recomendaciones
Sé el primero en recomendar a Fernando
Ayuda a este freelance a destacar compartiendo tu experiencia.
Estos perfiles de freelance también coinciden con tus criterios
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Formación
- Master of Business2008Master in Business Administration (MBA)
- Telecommunication Engineer"Escuela Tecnica Superior de Ingenieria de Telecomunicacion" (ETSIT). Superior2005Telecommunication Engineer