Andrés Stiven Sánchez Buitrago
Cybersecurity and Compliance Head at iFactum - Highweb & Page Group Inc.- Claim this Profile
Click to upgrade to our gold package
for the full feature experience.
Topline Score
Bio
Credentials
-
Internal Auditor ISO/IEC 27001:2022
SGSApr, 2023- Nov, 2024 -
Scrum Fundamentals Certified
SCRUMstudy - Accreditation Body for Scrum and AgileJan, 2023- Nov, 2024 -
Lead Auditor ISO/IEC 27001:2013
CQI | The Chartered Quality InstituteSep, 2021- Nov, 2024
Experience
-
iFactum - Highweb & Page Group Inc.
-
Canada
-
Information Technology & Services
-
1 - 100 Employee
-
Cybersecurity and Compliance Head
-
Dec 2021 - Present
Analysis and implementation and documentation of policies, procedures and controls related to information security. Planning, coordinating and executing internal and external audits and compliance activities related to international standards such as ISO 27001, ISO 27017, SOC 2, PCI-DSS, among others. Training and education of personnel in security matters and management of the ISO 27001 certification program. Information security management and analysis of the company's development environments. Execution and verification of vulnerability analysis to the company's development environments. Verification and implementation of security controls based on the analysis performed. Show less
-
-
-
NEORIS
-
United States
-
IT Services and IT Consulting
-
700 & Above Employee
-
Cyber Security Specialist
-
Jan 2023 - Present
-
-
-
CrossBorder Tech
-
Colombia
-
Information Technology & Services
-
1 - 100 Employee
-
Information Security Consultant
-
Jul 2022 - Jan 2023
Provide advice to organizations that require the implementation of the Information Security and Business Continuity Management System, ethical hacking and cybersecurity, based on ISO 27001:2013. Develop the necessary activities to fulfill the object of the contract, following the procedures and standards defined by the client. Analyze the internal functioning of the client's company. Maintain a fluid communication with the client, in order to obtain clear information about the necessary procedures to successfully implement them. Show less
-
-
-
Protecdata Colombia
-
Colombia
-
IT Services and IT Consulting
-
1 - 100 Employee
-
Systems Engineer
-
Sep 2020 - Jan 2022
Plan, coordinate and execute internal information security audits with focus on ISO 27001:2013. Validation and preparation of cybersecurity reports. Administration of security measures, creation, update and/or modification of contingency, availability, anti-disaster and continuity plans. Advising on information security matters to customers and submitting reports, concepts or documents related to the management performed as appropriate. Administration of servers, communication equipment. Inventory management of the IT area. Access management on the different platforms of the company. Show less
-
-
-
Neurona Tecnología Financiera
-
Colombia
-
IT Services and IT Consulting
-
1 - 100 Employee
-
Support and Test Engineer
-
Oct 2019 - Aug 2020
Ensure compliance with the procedures and guidelines determined by the Information Security Management System, for your position and process, maintain the confidentiality, integrity and availability of NEURONA information, Comply with security policies and standards. Documentation of functional and non-functional tests Handling of SOAP REST. Management based on Colombian financial models (NACHAM, ACH and CENIT). Ensure compliance with the procedures and guidelines determined by the Information Security Management System, for your position and process, maintain the confidentiality, integrity and availability of NEURONA information, Comply with security policies and standards. Documentation of functional and non-functional tests Handling of SOAP REST. Management based on Colombian financial models (NACHAM, ACH and CENIT).
-
-
-
Protecdata Colombia
-
Colombia
-
IT Services and IT Consulting
-
1 - 100 Employee
-
Technology Analyst
-
Jan 2019 - Sep 2019
Support systems of varying complexity, performing information gathering, requirements analysis, physical designs, logical designs communication and scope of the project, coordinate the work of programmers in projects of various nature and size, support and perform the necessary tests to verify that the developed systems meet the requirements and specifications of analysis and design, inventory management of software and hardware of the company with IT support, administration of CRM and SAR within the company, user management, modification of roles permissions, parameterization of the application. Implementation, support to projects such as BioData, SAR, SAIR, SSGT, SARLAFT among others. Show less
-
-
-
Virtual Studios Fotografia
-
Bogotá, Bogotá D.C., Colombia
-
Systems Technician
-
May 2014 - Jan 2019
ITIL support for PCs, laptops, servers and firewall. Printer support: hp Operating system management: Windows. Configuration and set up of workstations. Enterprise software such as: SAP Business One, SARA. Operating systems management: Windows, Linux, Mac Osx. Support for Office 365 business software. ITIL support for PCs, laptops, servers and firewall. Printer support: hp Operating system management: Windows. Configuration and set up of workstations. Enterprise software such as: SAP Business One, SARA. Operating systems management: Windows, Linux, Mac Osx. Support for Office 365 business software.
-
-
Education
-
Universidad Piloto de Colombia
Especialista en Seguridad Informática, Seguridad informática y de sistemas -
Escuela Colombiana de Ingeniería Julio Garavito
Diplomado en Ciberseguridad, Seguridad informática y de sistemas -
Universidad Autonoma de Colombia
Ingeniero de Sistemas, Ingeniería de sistemas -
Servicio Nacional de Aprendizaje (SENA)
Tecnico Sistemas, Ingeniería informática