Tony Grey
Advisor - Governisto @ Governisto™
About
As an executive advisor and vCISO, I help company manage their cyber and technology risks and program building through key business inflection points like changes in business strategy, AI governance, operationalizing privacy, digital and cloud/mobile transformation, M&A, and managing the cyber impacts of insider risks. Former CISO and Vice President of Technical Operations of a US publicly traded company (Hagerty NYSE: HGTY) Executive level tech program builder. Has completely rebuilt security, techops, IT governance, and devops teams and delivered multiple strategic and program level operational and governance capabilities aligned with the business needs of their organizations. Combines business acumen and strategic business planning skills developed in multiple leadership roles at Fortune 50 companies and entrepreneurial experiences with deep experience building defenses and leading investigations in multiple "malware rich" global environments.
-
United States
Information Technology & Services
Enterprise Software, Security, Integration, Firewalls, Microsoft SQL Server, Penetration Testing, Channel Partners, Cloud Computing, ISO 27001, Computer Forensics, Cross-functional Team Leadership, CEH, Professional Services, Private Investigations, Databases, Information Security Management, Virtualization, EnCase, Business Development, Business Strategy
Experience

Information Security And Cyber Risk Executive Consultant
Infosec Consultant LLC
United States
Work with various clients to advise on development of information security strategies, roadmaps, and resources; articulating their cyber risks to executive stakeholders and Boards; maturing regulatory compliance, cyber resilience, and disaster recovery capabilities; and enhancing infosec program metrics, stakeholder engagement, and execution. Clients are generally known in their markets with global teams and regulatory requirements. They range in size and requirements from nimble ecommerce companies focused on hyper growth and enablement as part of their infosec strategy to larger, often publicly traded entities with complex internal landscapes and relationships that require crisp navigation and compelling rationales for success. Engagements range from 3-12 months on a half time or more staff augmentation basis with some onsite time and/or international travel contractually built in as required. Infosec Consultant LLC grew to multiple consultants under my leadership. These consultants work to develop and support client requirements within the infosec and regulatory data protection disciplines

Chief Information Security Officer (CISO) and V.P. of Technical Operations
FOR CISO-SPECIFIC ACCOMPLISHMENTS OF THIS ROLE, PLEASE SEE THE NEXT ROLE BELOW • Developed a global IT strategy (US, Canada, EU) and multi-year roadmap resulting in a comprehensive, responsive TechOps program aligned with best practice, peers, the Board, Audit Committee, and external auditors • Established and maintained KPIs and monitoring for two legacy on-premise data centers, 4 cloud repositories (AWS, Salesforce, Azure, O365), desktop engineering, help desk, DevOps pipelines, databases, and IAM • Measured and communicated effectively to ensure a good balance of planning, resourcing, staffing for “keeping the lights on” while driving significant digital change in a highly entrepreneurial, dynamic and remote first company • Conceived, budgeted and staffed a new TechOps Resiliency team focused specifically on raising resiliency of key systems and services through “infrastructure as code” resulting in a significant reduction in production outages • Established an IT Governance team to mature documentation, standards & policies,, data flows, and change control practices to manage business and stability risks through continuous improvement measured against the following frameworks: ISO, PCI, GDPR, SOX (2021 NYSE IPO) • Managed legacy systems risk by transitioning to more modern cloud stacks, updated protocols, or implementing additional on-premise alerting and monitoring and controls to detect & respond to production impacting events • Improved business delivery for product teams by enabling self-service IT and DevOps models as well as end to end resiliency controls across Microsoft & AWS Cloud environments and code repositories (MFA, CASB, DLP, etc.)

Vice President and Chief Information Security Officer (CISO)
Hagerty (NYSE: HGTY)
Global responsibilities - US, Canada, UK, Germany, and myriad Hagerty owned events
Responsible as the senior information security leader for the information security strategy, roadmap, cultural transformation, controls implementation, and execution of the organization’s security architecture, KPIs, cyber risk management, maturity building, IAM governance, threat intelligence, and security operations programs. Communicates with and educates the Board, senior executives and internal community on information security program risks, progress against goals, threats, and vulnerability mitigations across the entire risk landscape including third party and supply chain risks. Maintains key relationships with infosec stakeholders. Accomplishments: • Developed a global security strategy (US, Canada, EU) and multi-year roadmap resulting in a comprehensive, responsive infosec program aligned with best practice, peers, the Board, Audit Committee, and external auditors • Matured on-premise and cloud security controls while leading the team through compliance with the following frameworks: NY State Reg 500, ISO 27001, PCI, GDPR, and SOX as part of 2021 IPO on the New York Stock Exchange • Drastically improved Hagerty’s incident detection/response capabilities, vulnerability management, threat intelligence, and security operations programs utilizing data analytics, autonomous response, and addressing major gaps in asset management • Successfully guided a defense of company infosec controls and risk management program involving an industry wide issue with an external data provider and state regulators • Identified Hagerty’s vulnerable legacy systems by implementing additional on-premise security monitoring and controls to detect & respond to an anomalous security events • Streamlined business processes for performing third party risk evaluations and quantifying overall cyber risk

Managing Director
Media Development S.A.
Bolivia, Brazil , and Panama
Acquired a Latin American outsourced software development shop as investor and later majority shareholder. This company provided both products and services to the US, European, and Latin American market. Managing Director, Endpoint Security & Risk (2016-2017 Panama) US Expat Role Strategic technical director for cybersecurity services and software development helping customers identify and manage their endpoint risk as well as formalize endpoint activities into a program with objectives, roadmaps, etc. Key Accomplishments: ● Developed a custom endpoint compromise detection solution that was made available to customers as a managed service offering. Developed various courses on incident response, risk identification, and threat hunting. VP, Strategy (2012-2016 Brazil & Panama) – Part time US Expat Role Key Accomplishments: ● Developed strategy and evangelism for supporting multi-national organizations with skilled bilingual security sales engineers, regional marketing support, local language DFIR/security blog posts and technical translation services. Director, Software Engineering (2008-2011 Bolivia) US Expat Role Key Accomplishments: ● Led a 25-30 person multidisciplinary software development team in Spanish to successfully build and launch a mobile content management platform localized in multiple languages. Also led a team that built a series of digital forensics and malware detection tools. ● Authored a software development focused blog about improving software processes for in-house and outsourced software teams.

Incident Response & Internal Investigation Regional Leader
Guidance Software (NASDAQ: GUID)
Pasadena, California, United States
Served as customer focused hands-on field CISO for incident response program building, indicators of compromise, and post-incident digital forensics analysis. Comfortably interacted with international C-level decision makers and engineering leaders of publicly traded banks, telecom providers, mining companies, tax authorities, and other types of government entities to identify gaps, improve processes, and, in some cases, engage with regulators after a major information security incident. Worked with HR, general counsel, and often law enforcement to identify and mitigate insider threats within organizations holding confidential trade secrets, financial data, or personal information.

Director of Program Management, Quality Assurance and Network Operations
Motorola
Seattle, WA
• Led a large 60 person interdisciplinary software test, program management, network operations, and professional services team at the Director level within Motorola's handset division integrating a software service specifically for Motorola phones to large mobile providers worldwide on a revenue share basis. • Responsible for integrating a low maturity newly purchased and wholly owned Motorola software development subsidiary into a full fleged Motorola business unit from a process and infrastructure perspective and matuing the delivery and quality of the underlying server side mobile platform Accomplishments • Planned, gained consensus, and implemented a roadmap leading to a more standardized, resilient server-side mobile platform that enabled faster integration, wider adoption, and vastly improved stability for Motorola’s revenue sharing telecom customers. • Implemented a plan to identify and manage quality and schedule risks through best practice, documentation, KRIs/KPIs, change control procedures, and process improvements which resulted in measurably improved delivery, quality, and stability • Successfully led an initiative to transition from Sun hardware to a Linux based platform. • Gained consensus and implemented a division-wide initiative that changed how software testing of Motorola handsets was conducted. This required successfully integrating and gaining successful results from "in-sourced" Motorola teams in Brazil, St. Petersburg, and India.

Group Manager, Internet Explorer/Outlook Express
Microsoft
Redmond, WA
Responsible for all software engineering, security, patch development, and sustained engineering of the Internet Explorer (IE) and Outlook Express (OE) products that each had over 500M users. Led a number of major cross company initiatives within this Fortune 50 company that impacted every software development team and most of then-nascent product lifecycle initiatives. Several had cross industry impact such as the removal of MSJVM from all product teams which impacted almost every enterprise Microsoft customer. Worked closely with inside and outside counsel to comply with various consent agreements involving Microsoft and Internet Explorer. Averaged just over a release per day for almost 4 years and brought end to end IE security patch development from an average of 104 days to under 25 days. Led a team of 120 engineers including dev, test, program management, and build lab.
Tony Grey's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.


