Summary
Overview
Work History
Education
Skills
Certification
Work Flexibility
Accomplishments
Willing To Travel
Personal Information
Timeline
Generic

Sherrod Wm. Beckles

New Windsor

Summary

Cybersecurity governance and risk executive specializing in the design and implementation of scalable frameworks aligned with industry standards. Adept at leading regulatory compliance initiatives and developing comprehensive training programs that elevate organizational security posture. Experienced in delivering executive-level insights to enhance decision-making and stakeholder engagement.

Overview

32
32
years of professional experience
1
1
Certification

Work History

IT Risk & Security Senior Director

Jackson Lewis P.C.
09.2015 - 04.2026
  • Established and led the firm’s cybersecurity governance program, building an enterprise-wide framework aligned to NIST and ISO standards.
  • Developed and managed the full lifecycle of cybersecurity policies, standards, and procedures, including governance processes for approvals, exceptions, and periodic reviews.
  • Partnered with Legal, Privacy, Compliance, and IT teams to operationalize governance requirements and ensure alignment with business objectives and regulatory obligations.
  • Designed and implemented enterprise cybersecurity awareness and training programs, including phishing simulations, role-based training, and executive awareness initiatives.
  • Led regulatory compliance initiatives including SSAE SOC 2 Type II, HIPAA, and PCI Lite, improving audit readiness and strengthening control effectiveness.
  • Maintained mappings of regulatory requirements, policies, controls, and supporting evidence, facilitating audits and client due diligence.
  • Delivered executive-level reports on cybersecurity governance posture, compliance status, and key risk indicators, enhancing stakeholder awareness and decision-making.
  • Built and mentored a cybersecurity risk and compliance team, establishing scalable governance processes and performance expectations.
  • Developed the firm’s Third-Party Risk Management (TPRM) program based on BITS Shared Assessments and CIAQ frameworks.
  • Developed the firm’s Client Inquiry and Audit process, including creation of a centralized repository of approved IT General Controls (ITGCs) governing network infrastructure.
  • Led all client audit and inquiry engagements, including conducting interviews and presenting supporting evidence to substantiate control assertions.
  • Managed the firm’s cybersecurity insurance policy, ensuring coverage alignment with organizational risk profile, regulatory expectations, and evolving threat landscape.
  • Developed the firm’s AI Governance Program aligned with the NIST AI RMF, AI DLP controls (web content blocking, etc.), and supporting AI policies.

Information Technology

KPMG LLP
01.1994 - 09.2015
  • Managed IT network operations, infrastructure, and foundational IT service delivery, ensuring reliability and efficiency during 8 years of a 22-year tenure.
  • Advised Fortune 500 clients on cybersecurity governance, IT risk management, and regulatory compliance programs.
  • Conducted enterprise IT risk assessments, control evaluations, and regulatory audits across financial services, consumer markets, and industrial sectors.
  • Developed governance frameworks, policy structures, and compliance programs aligned with industry standards to enhance organizational compliance and risk management.
  • Partnered with executive leadership to strengthen control environments and implement sustainable risk management practices.
  • Established KPMG’s Cybersecurity Risk Management Program internally, developing enterprise-wide risk governance capabilities after being recruited from the Advisory Practice.
  • Managed the design and implementation of the firm’s risk assessment process based on the FIPS 199 framework as Senior Manager of Security Risk Assessment, conducting risk assessments for key initiatives across Advisory, Audit, Information Technology, and Tax practices.

Education

Associate of Arts - Information Technology

Interboro College
New York, NY

Skills

  • Regulatory Compliance (NIST, ISO 27001, NYDFS, GLBA, HIPAA, SEC)
  • Cybersecurity Governance & Policy Lifecycle Management
  • Audit & Assessment Leadership (SOC 2, Client Audits, Regulatory Exams)
  • Incident response planning
  • Data Privacy Management
  • Cybersecurity Awareness & Training Programs
  • Control framework design
  • Cybersecurity Awareness & Training Programs
  • Program development
  • Cross-functional leadership
  • Board reporting

Certification

CIPP/IT

Work Flexibility

Hybrid

Accomplishments

  • Built and operationalized enterprise cybersecurity governance aligned to NIST and ISO.
  • Established Third-Party Risk Management (TPRM) and client audit programs, improving audit readiness and trust.
  • Led SOC 2 Type II, HIPAA, and PCI Lite audits, strengthening control effectiveness.
  • Implemented enterprise cybersecurity awareness program, improving user risk posture.
  • Developed AI Governance Program aligned to NIST AI RMF with integrated controls.
  • Managed cybersecurity budget and insurance aligned to risk priorities.
  • Centralized ITGC controls and client inquiry process, improving audit efficiency.

Willing To Travel

True

Personal Information

Citizenship: U.S. Citizen

Timeline

IT Risk & Security Senior Director

Jackson Lewis P.C.
09.2015 - 04.2026

Information Technology

KPMG LLP
01.1994 - 09.2015

Associate of Arts - Information Technology

Interboro College
Sherrod Wm. Beckles