Himalayas logo
PS
Open to opportunities

Paul Smith

@paulsmith1

Experienced audit, risk and information security leader driving GRC and compliance.

United States
Message

What I'm looking for

I seek senior GRC or information security roles where I can lead risk, audit and third-party programs, implement pragmatic controls, and partner cross-functionally to strengthen compliance and privacy.

I am a seasoned audit, risk management and information security professional with deep experience designing and running GRC, third-party risk and internal controls programs for large enterprises. My background spans SOX, NIST, ISO, PCI, privacy, and implementing tools such as RSA Archer and ServiceNow to operationalize risk and compliance.

Throughout my career I have led internal audit organizations, built ERM and audit programs from the ground up, coordinated IT SOX efforts, and managed third-party risk assessments and remediation across complex global environments. I have delivered measurable process improvements, implemented security frameworks, and coordinated cross-functional stakeholders to reduce risk and ensure regulatory compliance.

I hold multiple professional certifications (CPA, CISA, CISSP, CISM, CFE, CRISC, PMP, PCIP, ISA) and certifications in privacy and GRC tooling, and I bring a pragmatic, business-aligned approach to security and compliance that emphasizes practical controls, remediation ownership, and measurable outcomes.

Experience

Work history, roles, and key accomplishments

Toyota Motor North America logoTA
Current

Cyber Security Engineer

Toyota Motor North America

Jul 2022 - Present (3 years 3 months)

Lead third-party cyber risk assessments and remediation activities, reviewed supplier contract security/privacy requirements, and implemented risk-based security controls to improve compliance and reduce vendor-related security exposure.

Citi logoCI

Governance Risk & Compliance Officer

Sep 2015 - Feb 2017 (1 year 5 months)

Led GRC oversight for consumer businesses, directed issue tracking and remediation, and provided PCI and information security governance during major card program transitions to maintain regulatory compliance and reduce control gaps.

Education

Degrees, certifications, and relevant coursework

Pace University, Lubin School of Business logoPB

Pace University, Lubin School of Business

Bachelor of Business Administration, Accounting

Completed a Bachelor of Business Administration with a major in Accounting and a minor in Finance at Pace University's Lubin School of Business.

Southern Methodist University logoSU

Southern Methodist University

Master's (Information Assurance), Information Assurance

Completed graduate-level studies in Information Assurance resulting in a master's-level certification from Southern Methodist University.

Harvard University logoHU

Harvard University

Certificate, Data Privacy and Technology

Completed a Data Privacy and Technology certification program at Harvard University.

Tech stack

Software and tools used professionally

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Paul Smith - Cyber Security Engineer - Toyota Motor North America | Himalayas