Summary
Overview
Work History
Education
Skills
Accomplishments
Timeline
Generic

Lenny Mansilla

Hollywood,FL

Summary

Cybersecurity executive with 25 years of experience in establishing and implementing large global information security programs. Expertise encompassing the entire spectrum of cybersecurity domains including GRC, Product Security, Security Testing, Security Operations, Incident Response, Compliance, IT Auditing, Vulnerability Management, Threat & Intelligence Management, Attack Surface Management, Cloud Security as well as others. Proven track record of building global cybersecurity programs from inception & elevating existing initiatives to advanced maturity levels for organizations of all sizes from start-up to Fortune 200 companies. Strategic thinker & innovative problem-solving prowess thriving in fast-paced & dynamic environments. Fully bilingual, in English & Spanish.

Overview

21
21
years of professional experience

Work History

Chief Information Security Officer (CISO)

Netsurion
11.2014 - 06.2024
  • Provide strategic direction for Netsurion's Managed XDR solution responsible for alerting & detections as well as investigations into customer breaches.
  • Serve as expert advisor to C-suite & company leadership on cybersecurity across areas like cybersecurity strategy, risks, & delivery of key objectives.
  • Oversee successful completion of organization wide security audits / certifications including HIPAA / HITRUST, SOC 2 Type II, ISO 27001, ISO 20000, PCI DSS, Privacy Shield (GDPR), identifying & remediating critical vulnerabilities, leading to improvement in overall security posture.
  • Created a cyber threat intelligence team to curate content for organization's threat intelligence platform with indicators of compromise from variety of feeds as well as those discovered by CTI team while threat hunting through system telemetry.
  • Developed cybersecurity roadmap that reflects long-term thinking, appropriately identifies/prioritizes risks & opportunities, & implementing security controls & technologies that raise bar for cybersecurity.
  • Developed & implemented information security policies & procedures to ensure safety & security of confidential data.
  • Managed security operations including vulnerability management, risk management, & incident response.
  • Provided technical security guidance to internal teams on security best practices & solutions.
  • Implemented comprehensive cybersecurity strategy resulting in 75% reduction in security incidents & 70% decrease in mean time to detect (MTTD) incidents.
  • Monitor external feeds for emerging threats & advised stakeholders on appropriate courses of action. Liaised with external agencies, such as law enforcement as necessary to ensure that client maintains strong security posture.
  • Designed & implemented automated tool-based vulnerability management framework that continuously monitors & detects cybersecurity threats & vulnerabilities.
  • Performed evaluations & selections of IT security tools & successfully implemented IT security systems to protect availability, integrity, & confidentiality of critical business information & information systems.
  • Developed & executed employee security awareness program, increasing staff adherence to security policies by 90% & reducing likelihood of successful phishing attacks by 95%.
  • Ensure that disaster recovery plans & procedures for business-critical services satisfy client security standards & support recovery following occurrence of security event.

SVP, Operations

Netsurion
11.2019 - 06.2024
  • Responsible for architecting presales deployments of Netsurion's Managed XDR solution as well as implementation, transition to security operations post sales. Spearheaded initiatives related to security incident investigations, customer retention renewals & customer churn management through customer success team spearheading.

Director of Business Security Enablement

EMC Corporation
04.2011 - 11.2014
  • Architected, developed & led global team of business security managers imbedded within various business verticals at EMC such as Engineering, Global Services, Manufacturing, Marketing, Sales, Legal, Finance, etc. Business Security Enablement Team acted as liaison between various business functions & Global Security Organization. Developed executive level Governance, Risk & Compliance (eGRC) steering committee responsible for addressing information security risks throughout organization.

Senior Manager Risk & Compliance

EMC Corporation
04.2007 - 04.2011
  • Act as primary liaison to customers & prospective customers on information security diligence processes & audits. Oversee risk & compliance efforts for RSA Security's Software as a Service (SaaS) & EMC's Cloud Infrastructure Group (CIG). Assess current information security controls, policies & procedures in operations, R&D & third-party services. Prepared & managed RSA Hosted Operations & Cloud Infrastructure Group for SAS70 Type II (replaced by SOC 2), ISO 27001, PCI DSS, & Verified by Visa in US, Europe, Middle East & Asia.

Information Security Manager

Verid
05.2003 - 04.2007

Developed effective, sustainable & scalable information security program for a startup company. Oversaw every aspect of information security for Verid's Knowledge-based Authentication offering including:

  • Developed, implemented & maintained security policies & procedures documentation.
  • Performed risk assessments & analyzed system data to identify security risks, prioritize risks & present those risks to executive management along with identified controls to help mitigate risks.
  • Act as primary liaison to customers & prospective customers on information security diligence processes & audits.
  • Prepared Verid for SAS70 Type II audit & successfully completed audit.

Education

Master of Science - Management Information Systems

Florida International University
Miami, FL
12.2001

Bachelor of Science - Business Administration - Finance

Florida International University
Miami, FL
1998

Skills

  • Governance, risk & compliance (GRC)
  • Cloud Attack Surface Protection (AWS & Azure)
  • Cyber Threat Intelligence (CTI)
  • Project management
  • Security operations center
  • Risk assessment & compliance
  • Incident detection & response
  • Penetration testing
  • Threat & vulnerability management

Accomplishments

    Leadership

  • Led a team of over 100 cybersecurity & risk professionals overseeing cybersecurity program strategy & oversight, application security & testing, data protection, vulnerability management, cloud risk management, security risk metrics & analytics, cyber threat management, vendor security oversight.
  • Regular presenter to the CEO, C-suite. Direct report to the Chief Operating Officer.
  • Developed and implemented enterprise security strategy and framework overseeing the successful completion of organization wide security audits / certifications including HIPAA / HITRUST, SOC 2 Type II, ISO 27001, ISO 27002, ISO 20000, PCI DSS, Privacy Shield (GDPR), identifying & remediating critical vulnerabilities, leading to improvement in overall security posture.
  • Conducted webinars on Attack Surface Coverage including Cloud Attack Surface.
  • Strategy and Planning

  • Developed a cybersecurity roadmap that reflects long-term thinking, appropriately identifies/prioritizes risks & opportunities, & implements security controls & technologies that raise the bar for cybersecurity.
  • Developed & implemented information security policies & procedures to ensure the safety & security of confidential data.
  • Developed & executed employee security awareness program, increasing staff adherence to security policies by 90% & reducing the likelihood of successful phishing attacks by 95%.
  • Redesigned customer daily critical findings reports using business intelligence tools to automate the report and reduce production from an average of 6 hours to 30 minutes resulting in 90% increase in efficiency and cost savings.
  • Team Collaboration

  • Collaborated with cross-functional executives to establish enterprise security framework to accomplish common IT security objectives and leverage common tools to reduce costs.
  • Coordinated the activities of Information Security Officers to define and establish unified program-wide approach to address IT security issues and mitigate IT security risks.

Timeline

SVP, Operations

Netsurion
11.2019 - 06.2024

Chief Information Security Officer (CISO)

Netsurion
11.2014 - 06.2024

Director of Business Security Enablement

EMC Corporation
04.2011 - 11.2014

Senior Manager Risk & Compliance

EMC Corporation
04.2007 - 04.2011

Information Security Manager

Verid
05.2003 - 04.2007

Master of Science - Management Information Systems

Florida International University

Bachelor of Science - Business Administration - Finance

Florida International University
Lenny Mansilla