At Elsevier, I own cyber risk quantification, building FAIR-based loss-exposure models in SafeOne and translating technical scenarios into financial terms for senior leaders.
I've reduced average annual loss exposure on critical assets by approximately $4M through quantified control-maturity recommendations. I also rebuilt the cyber risk register and assessment methodology, cutting assessment time by 70%.
I've rewritten risk management standards and procedures, authored SOPs for exception and issue management, and built an auditable policy-exception workflow in Optro. I lead GRC, compliance, and third-party-risk tooling evaluations across SafeOne, RiskLens, Archer, OneTrust, and Black Kite.
I bring FAIR-based risk modeling, practical governance, and clear executive communication to enterprise cyber risk programs.
