David W Kuo

Roles available for:
-
Fractional
-
Consulting
-
Contract
-
Interim
-
Piedmont, California, United States
-
Country experience:
-
United States of America
Northern America
-
Achievements


-
Expertise
Data Protection and Privacy GDPR, CCPA, ISO 27001, BS10012, C5, FFIEC, HIPAA, PCI, HITRUST, NIST compliance IT Internal Audit Security Strategy ad Governance Security Risk Management Program Management Borad Reporting -
Services
Security Strategy, Trusted AI/ML consulting, IT Risk Management, Security Compliance Readiness Assessment
-
Employees overseen
30 employees
-
Budget overseen
$ 20,000,000
Roles available for:
-
Fractional
-
Consulting
-
Contract
-
Interim
-
Piedmont, California, United States
-
Country experience:
-
United States of America
Northern America
-
Achievements

Why hire me in a fractional role
Experience
- Head of Security Compliance and Privacy
- Chief Information Security Officer, Consulting Principal Director
Strengths in this role: Audit and compliance, data protection and privacy, cloud compliance, SaaS solution, SOC1 & 2, ISO 27001, BS 10012, GDPR, CCPA, HIPAA, HITRUST, C5, TTISAX, Third Party Risk, Security Strategy and Governance, User Awareness,
Industry Group: High Tech
Industry: Computer & Network Security
Years of experience: 17 years
Company name: SAP SuccessFactors
Company size: 1,200 employees
Role in this company: Serving as the global leader for Compliance, Privacy and Risk Management for the market leading cloud based human capital management (HCM) solution. My focus has been operationalizing a sustainable security compliance and privacy program that is risk based and identify, detect, and protect against key data security threats for cloud SaaS offering.
Strengths in this role: FFIEC, NIST CSF, ISO 27001, HIPAA, Security Strategy and Governance, Information Governance, Data Protection and Privacy, Privacy Impact Assessment, GDPR,
Industry Group: High Tech
Industry: Computer & Network Security
Years of experience: 25 years
Company name: Accenture
Company size: 150,000 employees
Role in this company: Led the Data Privacy and IT Risk capabilities within the Strategy & Consulting domain. • Served as the portfolio lead for the X-industry (Tech, Media, and Telecom) Digital Risk and Compliance, a $14 million per year portfolio, driving and leading consulting engagements ranging from Enterprise Risk Management, Financial Crime Prevention, Regulatory Change Monitoring, Payment Compliance, Data Privacy, and IT Risk in the US West Region.
Company name: Ripcord
Company size: 250 employees
Role in this company: As the global information technology and security leader for Ripcord, a Series B start-up for robotic digitization and AI/ML based records management SaaS offering, I was responsible for safeguarding the company and its customers' information assets against current and future security risks. My key accomplishments include: • Advised the Board of Directors on cybersecurity and customer-trust related matters to ensure that company's security posture aligned with business objectives.
Company name: SWORD Health
Company size: 500 employees
Role in this company: Contracted as the Global Head of Information Technology & Security for a Series-B digital healthcare start-up for MSK care with proprietary devices for pos-data privacy incidents remediations. Responsibilities include but not limited to: • Successfully architected and implemented comprehensive programs and processes to evaluate and enhance SWORD's information security policies which resulted in improved security posture and compliance with industry standards.
Company name: SAP SuccessFactors
Company size: 15,000 employees
Role in this company: As the Global Compliance, Privacy, and Risk Management Leader for a leading cloud-based HCM SaaS solution, my primary focus was on establishing a customer-focused privacy and compliance program that protected customer data.
Company name: KPMG
Company size: 50,000 employees
Role in this company: I served as the Cyber Account Lead for Platinum Accounts, managing the delivery of security and privacy projects averaging $2-5MM for each assigned account. Some of my notable accomplishments include: • Developed, led, and delivered several Cyber Compliance Assessment and Readiness programs that enabled clients to achieve compliance with various standards and privacy regulations such as GDPR, FFIEC, GLBA, NYDFS, PCI, ISO27001, and HIPAA.
-
Board membership
Company: Ponemon Institute
Position: Distinguished Fellow
From: 08/01/2017
To: Present
-
Degrees & accreditations
CIPT
CISA
-
Membership & affiliations
ISACA
IAPP
-
Success story
I have served as the retained cybersecurity and privacy advisor to the CEO and Board of Directors for number of large financial services institution by providing regular briefing on emerging security technology trends issues and risks. For the same institution, I also helped with CISO transition support, conduct cybersecurity risk assessment, developing strategy for cybersecurity risk mitigation, identity and access management, security governance, risk and compliance.