Claire Schuster

Claire Schuster

Senior Director, Information Security GRC @ Planned Parenthood Federation of America

About

Strategic and effective healthcare Information Security leader aligning business needs to HIPAA Security & Privacy Rules, PCI DSS, and NIST. Skilled in Information Security and Privacy Controls, Risk Management, Policy Governance & Compliance, Vendor Due Diligence, Program Management, Investigations, Incident Response, Dashboard Metrics, and Process Improvement. Educational background in Risk Management and Management of Information Systems (MBA) from Saint Peter’s University with industry certifications (CISSP, CISM, HCISPP, CTPRP, GLEG).

Country

United States

City

Bernardsville

Industry

Hospital & Health Care

Skill

Gap Analysis, Vendor Management, HITRUST, Business Continuity, Risk Analysis, Information Security Awareness, Policies & Procedures, Vendor Contracts, SOC 2, Security Management, Regulatory Requirements, Security Information and Event Management (SIEM), Information Security Management, IT Risk Management, Business Alignment, Third Party Risk Management (TPRM), Contractual Obligations, ISO 27001, Certified Information Security Manager (CISM), Vulnerability Management

Experience

Planned Parenthood Federation of America

Senior Director, Information Security GRC

Planned Parenthood Federation of America

LinkedIn
2026-3 - Present · 7 mos
Planned Parenthood Federation of America

Senior Director (Interim), Information Security GRC

Planned Parenthood Federation of America

LinkedIn
2026-1 - 2026-3 · 3 mos
Planned Parenthood Federation of America

Director, Information Security GRC

Planned Parenthood Federation of America

LinkedIn
2024-9 - 2026-1 · 1 yr 5 mos
Planned Parenthood Federation of America

Associate Director, Information Security GRC

Planned Parenthood Federation of America

LinkedIn
2022-1 - 2024-9 · 2 yrs 9 mos

• Leading Information Security & Technology and HIPAA Security accreditation reviews of PPFA’s 49 brand-affiliated organizations to raise the overall security and compliance posture of the federation by validating control effectiveness, identifying potential risks, and proposing mitigation solutions • Initiating the creation and curation of risk analysis metrics and data visuals; presenting risk and compliance trends to PPFA CIO Leadership and affiliate Executive and IT Leadership; producing and updating risk-based education resources and materials • Collaborating interdepartmentally to enhance security practices and compliance activities throughout the National Office and at Affiliates by leveraging risk-based metrics for large-scale service enhancements, most notably Vendor Risk Analysis & Management, Business Continuity & Disaster Recovery readiness, and Incident Response Planning • Proactively enhancing and operationalizing InfoSec GRC Program processes within the National Office through gap analysis to strengthen controls, mature the security posture and ensure alignment to regulatory requirements (HIPAA, PCI) and industry standards (NIST) • Training and managing two team members on assessment and evaluation strategies, assignment prioritization, and timeline management to align with CIO and Accreditation & Evaluation Department goals • Overseeing InfoSec GRC Program initiatives to ensure strategic plans are met on time without exceeding approved budget, including implementation of a controls evaluation, risk management and remediation solution; an internal data/process mapping workflow; and HIPAA Security & IS policy gap remediation

Med-Metrix

Manager, Information Security

Med-Metrix

LinkedIn
2021-1 - 2022-1 · 1 yr 1 mo

• Established and administered an enterprise-wide Information Security Management Program, including Vendor Risk Management, Policy Governance & Compliance, Cyber Security Incident Response, Awareness & Training, and Vulnerability Management aligning to NIST and HIPAA • Gathered InfoSec and IT data and evidence to meet HIPAA and SOC 2 compliance, identified process and documentation gaps, and formulated corrective actions plans for remediation • Provided dedicated guidance to strategic business units (product development, business development, IT, finance, legal) regarding security and privacy concerns for new technology, third party vendors, and partner/merger considerations • Proactively created and implemented policies, procedures, and standards aligned to business requirements and regulatory requirements to mitigate risks • Enhanced third-party security risk assessment processes with addressing gaps in document retention, assessment scheduling, and risk tracking to ensure repeatability; conducted vendor security risk assessments, reported control gaps, and managed remediation plans to ensure mitigation/remediation occurred within an appropriate time frame • Led IT team members to drive security enhancements by delivering robust and necessary improvements throughout the organization to reduce risks, and enhanced processes to ensure business alignment with regulatory requirements (HIPAA) and industry standards (NIST) • Instituted a monthly Information Security Awareness Program to continually educate employees on security, privacy, and compliance best practices and increased simulated phishing and vishing campaigns to a monthly cadence

Horizon Blue Cross Blue Shield of New Jersey

Lead Information Security Risk Analyst

Horizon Blue Cross Blue Shield of New Jersey

LinkedIn
2019-6 - 2021-1 · 1 yr 8 mos

Newark, NJ

• Developed and operationalized a vendor segmentation model to determine criticality and monitoring frequency for active third parties based on risk identification and a data restrictions model to determine data access allowance based on a vendor’s identified critical risks to improve the third-party risk security assessment process and overall security posture • Conducted vendor security risk assessments, reported control gaps, and managed remediation plans to ensure mitigation/remediation occurred within an appropriate time frame; discussed assessment results with business owners and provided dedicated guidance whether to continue vendor onboarding based on identified risks • Gathered InfoSec and IT data and evidence to meet SOC 2 compliance, identified process and documentation gaps, and formulated corrective actions plans for remediation • Partnered with Proposals and Sales teams to respond to inbound security risk questionnaires in promoting the overall security posture of the company to maintain and gain business • Reviewed and recommended data security and privacy requirements in contracting documents in collaboration with Compliance and Legal teams

Horizon Blue Cross Blue Shield of New Jersey

Cyber Security Analyst

Horizon Blue Cross Blue Shield of New Jersey

LinkedIn
2018-4 - 2019-6 · 1 yr 3 mos

Newark, NJ

• Conducted dedicated monitoring, initial incident triage, analysis and mitigation of cyber security events and risks; audited and reviewed system security logs for security risks such as unauthorized access, non-compliant activity, or access misuse; analyzed activity and drafted corrective/remediation action plans of identified risks • Cataloged activity observations and identified risks, and processed incident communications, inclusive of initial reporting, follow-ups, evidence requests, resolution activity, and corrective action plans to mitigate risks • Assisted Program Integrity and Risk Management teams with spearheading simulated phishing campaigns, provided guidance and direction in review of Policy/Standard exception requests, and completed Request for Information questionnaires regarding our Information & Cyber Security Program • Managed data metrics collection and analysis for delivery of monthly Divisional Security Metrics Program for use by the CEO, CSO, Executive Leadership; continued oversight and management of monthly departmental data metrics program for CSO, IT Stakeholders

Horizon Blue Cross Blue Shield of New Jersey

IT Security Analyst

Horizon Blue Cross Blue Shield of New Jersey

LinkedIn
2016-10 - 2018-4 · 1 yr 7 mos

Newark, NJ

• Provided guidance regarding security control elements in policies and standards throughout the organization; conducted appropriate follow-up and documented corrective action plans on information and cyber security issues and risks identified by Internal Audit • Collaborated with cyber security to perform risk analysis and remediation efforts for external threats, risks, and vulnerabilities; monitored for access to and exfiltration of sensitive data and escalated as appropriate • Managed project upgrade of a data loss prevention tool by implementing modifications to technical rules and policies to ensure encrypted transmission of member and company data while reducing the number of false positives for enhancement of our security posture • Led and managed an enhanced departmental data metrics collection and analysis program for monthly delivery to CSO, IT Stakeholders

Horizon Blue Cross Blue Shield of New Jersey

Senior Investigator

Horizon Blue Cross Blue Shield of New Jersey

LinkedIn
2014-8 - 2016-10 · 2 yrs 3 mos

Newark, NJ

• Independently planned, developed, and conducted investigations related to allegations of data and information security policy violations, corporate policy violations, HIPAA violations, fraud/corruption, among others • Interviewed case subjects; drafted clear, concise, and accurate reports for distribution; maintained confidentiality of all investigations; worked with key business units to discuss investigative results, as appropriate, for case disposition and remediation of risks identified • Enhanced and improved a Fraud Surveillance Program to proactively and accurately identify and detect information security, compliance, and financial risks for further investigation; worked to mitigate internal risks and threats identified during the investigative process • Leveraged tools to proactively monitor email exchanges for suspect behavior, and reviewed technical rule violations to prevent data exfiltration • Maintained departmental case statistics and provided status reports for use by Executive Leadership, as well as the Audit & Finance Committee

Horizon Blue Cross Blue Shield of New Jersey

Investigator

Horizon Blue Cross Blue Shield of New Jersey

LinkedIn
2011-2 - 2014-8 · 3 yrs 7 mos

Newark, NJ

• Jointly investigated internal matters related to Corporate Policy violations, information security violations, HIPAA violations, insurance fraud, and theft; interviewed case subjects; drafted reports • Assisted in the implementation and installation of an enterprise forensic solution; provided support to ICSO regarding encryption and device security information • Developed and implemented a Fraud Surveillance Program to proactively identify and detect information security, compliance, and financial risks • Accurately updated case file database; actively identified fraudulent use of Social Security numbers • Presented fraud training to newly hired employees; upheld the integrity of the Code of Business Conduct & Ethics; maintained confidentiality of all investigations

Education

Saint Peter's University

Saint Peter's University

LinkedIn

Management of Information Systems, Risk Management

2014 - 2017 · 3 yrs
John Jay College (CUNY)

John Jay College (CUNY)

LinkedIn

International Criminal Justice

2006 - 2009 · 3 yrs

Publications: · “Massacring Machu Picchu” John Jay’s Finest, Vol. XXIV, 2009 · “Stolen Talent: The Illicit Trafficking of the World’s Greatest Treasures” John Jay’s Finest, Vol. XXIII, 2008

Claire Schuster's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.