Summary
Overview
Work History
Education
Skills
Accomplishments
Work Availability
Timeline
Generic
Maximilian  Gusset

Maximilian Gusset

Zurich

Summary

Hi, I'm Max. I have more than 25 years' experience as an Information Technology (IT) professional with strong expertise in: Cyber Security and Risk Management, Cyber Security Architecture and Engineering, Cloud Security Concepts and Architecture, Cyber Security Operations and Warfare, Network Security and Design.

Highly skilled, dedicated and enthusiastic team player with excellent leadership and communication skills.

Overview

10
10
years of professional experience
10
10
years of post-secondary education

Work History

Chief Information Security Officer (CISO)

APG|SGA
Zurich
06.2023 - Current
  • Developed and implemented web-based Cybersecurity Awareness Training Program for all employees.
  • Developed and implemented automated tool-based vulnerability management framework.
  • Led effort to conduct IT security risk assessments and develop security plans for departments.
  • Led implementation of governance, risk & compliance (GRC), security information and event management (SIEM), automated vulnerability management, automated penetration testing, application whitelisting, data loss prevention (DLP), intrusion detection system/intrusion prevention system (IDS/IPS), web filtering, malware defense systems for endpoints and network perimeter, and mobile device management.
  • Developed strong organizational and communication skills through coursework and volunteer activities.

Cyber Security Architect

KYNDRYL
Zurich
10.2019 - 05.2023
  • Design of Zero Trust strategy and architecture including security developing of security concepts, directives, guidelines
  • Continuous improvement of business continuity management and resiliency, including periodic BC/DR tests
  • Planning, conducting of risk-oriented security audits such as vulnerability assessment and penetration testing
  • Conducted IT security audits to ensure effective implementation of security controls.
  • Defined risk mitigation strategies and reported significant changes to senior management.
  • Ensured vulnerability and threat assessments were performed to evaluate the effectiveness of existing security controls.
  • Developed and implemented processes to enable detection, identification, and analysis of IT security threats and vulnerabilities.

Chief Information Security Officer

White & Case LLP
Berlin, London, New York
01.2014 - 08.2019
  • Directed security services to align key processes with goals and objectives of organization and regulatory compliance.
  • Oversaw safety of assets by enforcing and regulating security policies and procedures and monitoring and maintaining security systems.
  • Established measures, metrics, thresholds and targets to drive performance in alignment with security and other business strategies.
  • Conducted security audits to identify vulnerabilities.
  • Recommend improvements in security systems and procedures.
  • Performed risk analyses to identify appropriate security countermeasures.
  • Developed plans to safeguard computer files against modification, destruction or disclosure.
  • Reviewed violations of computer security procedures and developed mitigation plans.
  • Established and implemented IT security program ensuring the security of all programmatic information residing on systems that were distributed across ten NASA Centers. These systems were an integral part of five major projects: Crew Exploration Vehicle, Crew Launch Vehicle, Mission Ops, Ground Ops, and Lunar Robotics
  • Developed program IT security governance document that includes effective approach to internal and external integration and communication to accomplish IT security objectives.
  • Established and validated security requirements that include physical, command and control, communications and information security requirements.
  • Coordinated activities of to establish approach to address IT security issues and mitigate IT security risks.
  • Established IT security planning processes, including continuity of operations and disaster recovery planning, risk analysis methodologies, and test methodologies for contingency plans and security controls.
  • Provided leadership to IT security team and for resolution of IT security issues and implementation of process improvements.
  • Established measures, metrics, thresholds and targets to drive performance in alignment with security and other business strategies.
  • Performed risk analyses to identify appropriate security countermeasures.
  • Conducted security audits to identify vulnerabilities.

Education

Ph.D. - Blockchain

Capitol Technology University
Laurel, MD
02.2021 - Current

Master of Science - Master of Science in Research Methods Application

Capitol Technology University
Laurel, MD
02.2021 - 02.2022

Bachelor of Science - Business Information Technology

Kalaidos University Zurich
Zurich, Switzerland
03.2008 - 03.2014

Associate of Science - Information Technology

Polytechnics School Zurich
Zurich, Switzerland
02.2008 - 02.2008

Skills

  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Governance, risk & compliance (GRC)
  • Information protection and analysis
  • Security information and event management (SIEM)
  • Risk assessment & compliance
  • Disaster recovery planning
  • Vulnerability management
  • Information Protection /Security
  • Operation and information security
  • Information security
  • Network security
  • Security testing

Accomplishments

Leadership

  • Developed and implemented enterprise security strategy and framework that consists of strategically integrated elements of NIST risk management and Cybersecurity frameworks and ISO/IEC 27001/27002

Strategy and Planning

  • Developed Acceptable Use policy, Mobile Device Management (MDM) and Bring Your Own Device (BYOD) policy, and many other security policies and standards to all users.
  • Established policies and procedures for system administrators to perform operating system and application patching.
  • Coordinated the activities of Information Security Officers to define and establish unified program-wide approach to address IT security issues and mitigate IT security risks.

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Timeline

Chief Information Security Officer (CISO)

APG|SGA
06.2023 - Current

Ph.D. - Blockchain

Capitol Technology University
02.2021 - Current

Master of Science - Master of Science in Research Methods Application

Capitol Technology University
02.2021 - 02.2022

Cyber Security Architect

KYNDRYL
10.2019 - 05.2023

Chief Information Security Officer

White & Case LLP
01.2014 - 08.2019

Bachelor of Science - Business Information Technology

Kalaidos University Zurich
03.2008 - 03.2014

Associate of Science - Information Technology

Polytechnics School Zurich
02.2008 - 02.2008
Maximilian Gusset