Norman Levine
@normanlevine
Cyber risk and privacy executive delivering TPRM, GRC automation, and privacy-by-design results.
What I'm looking for
I am a cyber risk and privacy executive with over 20 years leading enterprise TPRM, GRC automation, and privacy-by-design programs for Fortune 500 companies and professional services clients. I serve as a trusted advisor to executives, boards, and investors and have delivered measurable outcomes such as shorter vendor assessment cycles and improved remediation closure.
As Founder and Principal Consultant at Cyber Risk Partners, I act as a fractional CRO and vCISO, modernizing third-party risk management, automating GRC workflows in RSA Archer and ServiceNow, and strengthening cyber insurance readiness. Previously I led enterprise TPRM and privacy initiatives at Omnicom, Cigna, Stanley Black & Decker, HBO, and KPMG, managing multi-billion-dollar vendor portfolios and global programs.
I hold practical experience across audit readiness (SOC 2, ISO 27001, NIST), regulatory compliance (HIPAA, GDPR, CCPA/CPRA, DORA), and AI governance development. I am open to remote contract and consulting engagements and focus on driving measurable risk reduction, improved audit posture, and cross-functional alignment among Legal, Procurement, and Compliance.
Experience
Work history, roles, and key accomplishments
Founder & Principal Consultant
Cyber Risk Partners LLC
Jan 2024 - Present (2 years)
Serve as fractional CRO and vCISO for mid-market and PE-backed organizations, modernizing TPRM and privacy programs and automating GRC workflows to improve evidence traceability and audit readiness.
Senior Manager, Cyber Risk Management
Omnicom Group
Jan 2022 - Jan 2024 (2 years)
Led enterprise TPRM and privacy initiatives across operating agencies, standardizing third-party risk processes and delivering program metrics and reports to enterprise risk committees.
Senior Lead, TPRM & Privacy
Cigna Healthcare
Jan 2019 - Jan 2022 (3 years)
Managed a $10B vendor portfolio supporting HIPAA-regulated operations, centralized risk registers in Archer and expanded SIG due diligence to raise attestation completion to 98%.
Managed due diligence for a $14B portfolio and continuous monitoring of 900+ vendors, initiated GDPR readiness and automated vendor tiering to reduce manual effort ~25%.
Manager, IT Compliance & Audit
Home Box Office
Jan 2006 - Jan 2013 (7 years)
Managed SOX, PCI, and privacy compliance programs, enhanced disaster recovery and business continuity testing, and coordinated IT audit and remediation activities.
Led IT separation and privacy controls during a major divestiture and conducted enterprise IT and privacy audits for financial services and healthcare clients under SOX and HIPAA.
Education
Degrees, certifications, and relevant coursework
null
Bachelor of Science, Business Administration
B.S. in Business Administration (institution and dates not provided).
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Website
cyberriskpartnersllc.comJob categories
Interested in hiring Norman?
You can contact Norman and 90k+ other talented remote workers on Himalayas.
Message NormanFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
