Skip to main content
Carisa BrockmanCB
Looking for a job

Carisa Brockman

@carisabrockman

Cybersecurity and GRC leader with 20+ years in enterprise risk, privacy, and AI governance. Seeking Director/Head roles in industry or advisory.

United States
Message

At LevelBlue, I directed the Cybersecurity GRC consulting practice, expanding its service portfolio and delivery across multiple industry verticals while driving approximately 10% year-over-year growth. I also advised C-suite executives and boards on cybersecurity, privacy, regulatory compliance, and AI governance.

At AT&T Cybersecurity, I led enterprise cybersecurity, privacy, governance, risk, and compliance engagements for Fortune 500 companies, regulated organizations, and government agencies. I developed security governance programs and established risk-based third-party risk management programs.

Earlier, I led security, privacy, and GRC engagements at VeriSign and performed cybersecurity and privacy assessments at Guardent. Across my career, I’ve built advisory services including HITRUST, HIPAA, SOC 2, ISO/IEC 27001, CMMC, TPRM, privacy, and AI governance.

Experience

Work history, roles, and key accomplishments

LE

Director, Consulting — GRC Practice

LevelBlue

Jan 2024 - Dec 2026 (2 years 11 months)

Directed the Cybersecurity GRC consulting practice, setting strategy, expanding the service portfolio, and overseeing delivery and financial performance, driving approximately 10% year-over-year practice growth. Advised C-suite executives and boards on cybersecurity strategy, enterprise risk, privacy, regulatory compliance, and AI governance.

AC

Associate Director, Consulting — GRC Practice

AT&T Cybersecurity

Jan 2009 - Dec 2024 (15 years 11 months)

Led enterprise cybersecurity, privacy, governance, risk, compliance, and strategic program management engagements for Fortune 500 companies, regulated organizations, and government agencies over a 15-year tenure. Developed enterprise security governance programs and established risk-based TPRM programs.

VE

Lead Consultant, Security and Privacy

VeriSign

Jan 2004 - Dec 2006 (2 years 11 months)

Led security and privacy assessments using NIST, ISO, CIS, and other standards, translating control gaps and audit findings into risk-ranked remediation plans. Facilitated stakeholder interviews, evidence review, control testing, gap analysis, and executive risk presentations.

GU

Senior Consultant, Security and Privacy

Guardent

Jan 2000 - Dec 2004 (4 years 11 months)

Performed cybersecurity and privacy assessments, evidence collection, control testing, and compliance gap analysis against industry standards and regulatory requirements. Developed findings, recommendations, and remediation roadmaps that improved clients' security posture and audit preparedness.

MS

Information Technology Specialist

Minnesota Department of Human Services

Jan 1998 - Dec 2000 (2 years 11 months)

Partnered with the CIO to build the Strategic Information Resource Management Plan and IT Project Management Office; analyzed HIPAA requirements for statewide compliance planning.

SD

Substitute Teacher

St. Paul Public School District

Jan 1997 - Dec 1998 (1 year 11 months)

Served as a substitute teacher in the St. Paul Public School District.

Education

Degrees, certifications, and relevant coursework

UC

University of Minnesota–Twin Cities

Bachelor of Arts, History

Bachelor of Arts in History from the University of Minnesota–Twin Cities, completed in 1995.

Tech stack

Software and tools used professionally

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan