At Wise, I own third-party assurance methodology, control libraries, and risk-tiering for 150+ vendors across 30+ markets, reducing assessment cycle time from 25 to 14 days while achieving 100% tier-1 supplier coverage. Previously at Johnson & Johnson, I led global security contract governance across 900+ supplier contracts annually and set the security risk position for 200+ applications across 12 Latin American countries.
I've built and led security, GRC, and audit teams of up to 22 people across global regulated environments, including healthcare, fintech, assurance, and technology. My work spans ISO 27001, SOC 2, NIST, SOx, GDPR, DORA, HIPAA, security contracting, audit leadership, and executive risk decisions.
