At National General Insurance, I lead privacy assessments for business processes, products, systems, vendors, and technology changes. I document privacy risks and recommend practical controls.
I administer and improve OneTrust workflows for assessments, data inventories, risk tracking, and remediation. I also manage Data Subject Rights requests from intake and identity validation through fulfillment tracking.
At Cardinal Health, I supported privacy operations and assessments, including applying ISO 27701 controls to build a privacy threat risk register using RSA Archer and coordinating mitigations with InfoSec.
Earlier, as a Microsoft SQL Database Administrator at Royal Bank of Canada, RBC, I developed PowerShell scripts for SQL Server hardening aligned with PCI and HIPAA audit requirements. I also supported audit traceability and secure handling of personal information through access logs, role-based controls, and monitoring dashboards.

