Andrés Stiven Sánchez Buitrago

Cybersecurity and Compliance Head at iFactum - Highweb & Page Group Inc.
  • Claim this Profile
Contact Information
Location
Bogota, D.C., Capital District, Colombia, CO

Topline Score

Topline score feature will be out soon.

Bio

Generated by
Topline AI

You need to have a working account to view this content.
You need to have a working account to view this content.

Credentials

  • Internal Auditor ISO/IEC 27001:2022
    SGS
    May, 2023
    - Sep, 2024
  • Internal auditor ISO 27005:2022
    SGS Colombia
    May, 2023
    - Sep, 2024
  • Scrum Fundamentals Certified
    SCRUMstudy - Accreditation Body for Scrum and Agile
    Jan, 2023
    - Sep, 2024
  • Lead Auditor ISO/IEC 27001:2013
    CQI | The Chartered Quality Institute
    Sep, 2021
    - Sep, 2024

Experience

    • Canada
    • Information Technology & Services
    • 1 - 100 Employee
    • Cybersecurity and Compliance Head
      • Dec 2021 - Present

      Analysis and implementation and documentation of policies, procedures and controls related to information security. Planning, coordinating and executing internal and external audits and compliance activities related to international standards such as ISO 27001, ISO 27017, SOC 2, PCI-DSS, among others. Training and education of personnel in security matters and management of the ISO 27001 certification program. Information security management and analysis of the company's development environments. Execution and verification of vulnerability analysis to the company's development environments. Verification and implementation of security controls based on the analysis performed. Show less

    • United States
    • IT Services and IT Consulting
    • 700 & Above Employee
    • Cyber Security Specialist
      • Jan 2023 - Jul 2023
    • Information Security Consultant
      • Jul 2022 - Jan 2023

      Provide advice to organizations that require the implementation of the Information Security and Business Continuity Management System, ethical hacking and cybersecurity, based on ISO 27001:2013. Develop the necessary activities to fulfill the object of the contract, following the procedures and standards defined by the client. Analyze the internal functioning of the client's company. Maintain a fluid communication with the client, in order to obtain clear information about the necessary procedures to successfully implement them. Show less

    • Colombia
    • IT Services and IT Consulting
    • 1 - 100 Employee
    • Systems Engineer
      • Sep 2020 - Jan 2022

      Plan, coordinate and execute internal information security audits with focus on ISO 27001:2013. Validation and preparation of cybersecurity reports. Administration of security measures, creation, update and/or modification of contingency, availability, anti-disaster and continuity plans. Advising on information security matters to customers and submitting reports, concepts or documents related to the management performed as appropriate. Administration of servers, communication equipment. Inventory management of the IT area. Access management on the different platforms of the company. Show less

    • Argentina
    • Advertising Services
    • 1 - 100 Employee
    • Support and Test Engineer
      • Oct 2019 - Aug 2020

      Ensure compliance with the procedures and guidelines determined by the Information Security Management System, for your position and process, maintain the confidentiality, integrity and availability of NEURONA information, Comply with security policies and standards. Documentation of functional and non-functional tests Handling of SOAP REST. Management based on Colombian financial models (NACHAM, ACH and CENIT). Ensure compliance with the procedures and guidelines determined by the Information Security Management System, for your position and process, maintain the confidentiality, integrity and availability of NEURONA information, Comply with security policies and standards. Documentation of functional and non-functional tests Handling of SOAP REST. Management based on Colombian financial models (NACHAM, ACH and CENIT).

    • Technology Analyst
      • Jan 2019 - Sep 2019

      Support systems of varying complexity, performing information gathering, requirements analysis, physical designs, logical designs communication and scope of the project, coordinate the work of programmers in projects of various nature and size, support and perform the necessary tests to verify that the developed systems meet the requirements and specifications of analysis and design, inventory management of software and hardware of the company with IT support, administration of CRM and SAR within the company, user management, modification of roles permissions, parameterization of the application. Implementation, support to projects such as BioData, SAR, SAIR, SSGT, SARLAFT among others. Show less

    • Systems Technician
      • May 2014 - Jan 2019

      ITIL support for PCs, laptops, servers and firewall. Printer support: hp Operating system management: Windows. Configuration and set up of workstations. Enterprise software such as: SAP Business One, SARA. Operating systems management: Windows, Linux, Mac Osx. Support for Office 365 business software. ITIL support for PCs, laptops, servers and firewall. Printer support: hp Operating system management: Windows. Configuration and set up of workstations. Enterprise software such as: SAP Business One, SARA. Operating systems management: Windows, Linux, Mac Osx. Support for Office 365 business software.

Education

  • Universidad Piloto de Colombia
    Especialista en Seguridad Informática, Seguridad informática y de sistemas
    2023 - 2024
  • Escuela Colombiana de Ingeniería Julio Garavito
    Diplomado en Ciberseguridad, Seguridad informática y de sistemas
    2022 - 2022
  • Universidad Autonoma de Colombia
    Ingeniero de Sistemas, Ingeniería de sistemas
    2015 - 2021
  • Servicio Nacional de Aprendizaje (SENA)
    Tecnico Sistemas, Ingeniería informática
    2013 - 2014

Community

You need to have a working account to view this content. Click here to join now