Aug. 21, 2023, 2:19 p.m. | /u/b_dont_gild_my_vibe

cybersecurity www.reddit.com

I was just laid off as Information Security Officer for a small fintech firm dealing with auto dealer finance.

When I started they were all kinda of fucked up in terms of security. Everyone had Admin access to their lone legacy infrastructure account. They didn't have patching, logging, alerting, encryption, IAM, least privilege, SSO, MFA, policies, risk assessments, or anything really in place.

They gave me 8 months to get them SOC2 Type 2 compliant.... and I fucking did it. …

access account admin alerting auto cybersecurity encryption finance fintech iam information information security information security officer infrastructure least privilege legacy logging mfa officer patching privilege security security officer sso terms

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Lead Technical Product Manager - Threat Protection

@ Mastercard | Remote - United Kingdom

Data Privacy Officer

@ Banco Popular | San Juan, PR

GRC Security Program Manager

@ Meta | Bellevue, WA | Menlo Park, CA | Washington, DC | New York City

Cyber Security Engineer

@ ASSYSTEM | Warrington, United Kingdom

Privacy Engineer, Technical Audit

@ Meta | Menlo Park, CA