Melissa Lawlor, CISSP
Director, Cybersecurity GRC @ Hackensack Meridian Health
About
A seasoned, business-focused cybersecurity leader with a Big 4 consulting background, specializing in building and scaling cybersecurity programs from the ground up. Serves as a trusted advisor to the C-suite and boards, excelling at translating complex technical risks into business-centric strategy to secure multimillion-dollar budgets and gain executive buy-in. Acknowledged for driving enterprise-wide change and maturing security posture in complex, highly regulated industries.Core Competencies:Cybersecurity Strategy and Governance: Program Strategy and Design, Governance, Risk and Compliance (GRC), Policy and Standard Development, Security Culture and Awareness ProgramsRisk Management and Compliance: Enterprise Risk Management, Third-Party Risk Management (TPRM), Regulatory Frameworks (HIPAA, PCI-DSS), NIST Cybersecurity Framework (CSF), NIST Special Publications (800-30, 800-53, 800-61, 800-66, 800-88, etc.)Technical and Operational Leadership: Incident Command and Response, Security Architecture and Design, Cloud Security (Azure/GCP), Vulnerability Management, Business Continuity and Disaster Recovery (BC/DR)Executive Leadership and Management: Strategic Planning and Execution, Team Leadership and Development, Budgeting and Financial Management, Stakeholder and Board Communication, Vendor Contract and NegotiationCertifications:- Certified Information Systems Security Professional (CISSP)- Certified Information Security Manager (CISM)- Certified in Risk and Information Systems Control (CRISC)- Certified Cloud Security Professional (CCSP)- GIAC Law of Data Security and Investigations (GLEG)- GIAC Cyber Incident Leader (GCIL)- GIAC Security Operations Manager (GSOM)- Infrastructure Technology Infrastructure Library (ITIL) v4 Foundations
United States
Greater Philadelphia
Hospital & Health Care
-
Experience

Director, Cybersecurity GRC
As Director of Cybersecurity GRC at Hackensack Meridian Health, Melissa specializes in building security programs that protect the enterprise while enabling business growth. She led the transformation of the cybersecurity function from the ground up, scaling the department 5x and embedding a culture of security across the organization. Key achievements include: 1. Strategy & Leadership: Co-authored the organization's first multi-year cybersecurity roadmap, securing executive buy-in and managing the annual budget to align security investments with business objectives. 2. Risk & Compliance: Established the enterprise's first Cybersecurity Incident Management and Third-Party Risk Management (TPRM) programs, directing response to critical incidents and managing risk across 600+ vendors. Successfully directs enterprise-wide compliance efforts for HIPAA, PCI-DSS, FERPA, and more. 3. Technical Transformation: Architected security controls for a "Cloud First" strategy, enabling the secure migration of over 50 applications to GCP. Additionally, built the Vulnerability Management program from scratch, achieving a 90% reduction in critical vulnerabilities. 4. Team Leadership: Scaled the cybersecurity team from 7 to over 35 professionals, redesigning roles and creating clear career paths to improve retention and attract top talent. She is driven by the challenge of solving complex security problems and building high-performing teams. Her focus is on creating a resilient security posture that safeguards organizational assets while supporting innovation.

Director
A strategic cybersecurity consultant recognized for driving multimillion-dollar revenue growth and leading complex security transformations for clients across diverse industries. With a proven track record in both practice leadership and hands-on CISO-level advisory, she excels at building resilient security programs that align with executive-level business objectives. Key achievements include: 1. Business & Practice Leadership: Drove practice growth by managing a $4M average annual sales pipeline, consistently securing $2.5M in new business year-over-year, and managing a $1.5M annual delivery portfolio. 2. Executive Leadership (Co-Interim CISO): Served as the cybersecurity leader for a 17-hospital healthcare system. Architected and implemented its first three-year cybersecurity strategy, served as the primary security advisor to the board's audit committee, and overhauled the entire cybersecurity policy framework. 3. Crisis & Remediation Command: Directed a large-scale, co-sourced engagement to remediate critical security gaps across eight workstreams. Additionally, served as a key leader in the incident command team during a major ransomware attack, coordinating recovery for over 7,000 systems. 4. Strategic Frameworks: Benchmarked client programs against NIST CSF and HIPAA, using the results to build foundational, multi-year strategies that secure executive and board-level buy-in.

Director, Cyber Practice
A nationally recognized cybersecurity leader with a fast-tracked career progression from Associate to Director at KPMG. She was selected as one of three National Quality Directors for Healthcare Security, where she was responsible for driving practice growth, enhancing firm-wide methodologies, and leading complex client engagements. Key achievements include: 1. National Leadership & Methodology: As National Quality Director, co-led the firm-wide revamp of KPMG's HIPAA Security and Cyber Maturity Assessment methodologies, creating new delivery tools and sales collateral used by practitioners across the country. 2. Business Development & Practice Growth: Drove significant practice growth by managing a $4M average annual sales pipeline, consistently securing $2M in new business year-over-year, and managing a delivery portfolio with $1.5M in annual revenue. 3. Interim CISO Leadership: Served as the Interim CISO for a 17-hospital healthcare system, where she authored its first three-year cybersecurity strategy, benchmarked the program against NIST CSF and HIPAA, and launched a security awareness program for over 40,000 employees. 4. Large-Scale Program Management: Orchestrated a multi-million dollar cybersecurity remediation program by establishing a central PMO to govern 11 parallel workstreams, successfully integrating co-sourced and internal teams to meet aggressive deadlines.
Melissa Lawlor, CISSP's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.


