Mr. Salas has been a business and technology leader and visionary for over 28 years, including 19 years of achievements focused on information security assurance, and enterprise risk management. He has a proven track record, notably in the financial and legal service industries, technology, and media leadership. His career achievements include a track record in technology strategic planning and business continuity planning at global Fortune 500 corporations. Tactically, he has rolled up his sleeves, provided IT oversight, and created a project management operational framework, a measurable accountability model for information assurance and GRC control governance. Patrick authored policy baseline documentation for ISO 27001 ISMS', ISO 27701, and NIST 800-53 frameworks. He has also documented effective data security architectures, incident response workflows, and breach communication plans.
Professional experience curriculum includes:
• Chief Information Officer (CIO) and Senior Engagement Partner at Corporate Process Optimizers, LLC
• Chief Information Security and Privacy Officer at Kramer Levin Naftalis & Frankel, LLP
• Information Security and Privacy Officer at Morrison Foerster, LLP
• Chief Information Officer - Partner at Corporate Process Optimizers, LLC
• Vice-President of Information Security at Societe Generale Global Investment Bank
• Vice-President of Information Risk Governance at Sumitomo Trust & Banking
• Director of Information Risk and Security Management at Canon USA
• Business Information Security Officer at Citigroup - Citibank
• Vice-President of Systems Development at Merrill Lynch (Bank of America)
• Business Group MIS Systems Development Director at Bear Stearns (Brokerage Firm)
• Vice-President of PC/LAN Architecture at Bankers Trust Company (Deutsche Bank)
Notable work accomplishments:
* ISO 27K Certifications after having championed and successfully led ISO standardizing at least 3 global companies in a record timeline. Developed their Information/data security programs.
* Successful in bridging gaps of communication between technical staff and board-level leadership.
* Establishment of Enterprise Risk Management programs and implementation of Governance Risk Control (GRC) solutions.
Chief Information Officer (CIO) and Senior Engagement Partner at Corporate Process Optimizers, LLC
In my role as CIO, and as a partner, I have the responsibility to operate, further develop, and grow the vCISO consulting practice, delivering key consulting services like these to our clients:
• Information Privacy compliance with HIPAA, CCPA/CPRA, GDPR, and other laws and regulations.
• Information security program evaluation and prescriptive recommendations to improve their security posture.
• Information Security Program and Policies to assure data protection and readiness for saucerful ISO27001, and for SSAE18 SOC Type 2 attestation audits.
• Information
• Cloud security (Azure & AWS) services that help clients contextualize the secure architecture of their cloud environments and applications to implement distributed controls and management visibility.
• Cyber resilience services that help clients prepare for, respond to, and recover from cyber incidents.
• Cyber education and awareness services that help clients train and empower their employees to be cyber savvy.
• Business process optimization and proper workflow automation.
CISSP - Certified Information Systems Security Professional (Mastery-level on Information Security and Data Risk Assurance.
Has teamed up with great and competent CIOs, and COOs to streamline Technology Strategic Planning, policy and procedural documentation and overall systems development and architecture improvements.