Paul Gotter
Ouvert aux possibilitésSenior Cybersecurity Leader | vCISO Advisory | Managed Security | IT GRC & Strategic Advisory
Oshawa, ON
À propos
CISSP-certified cybersecurity leader and strategic advisor with over 25 years of experience across managed services, Big Five banking, Big Four consulting, and regulated enterprise environments. Combines senior cybersecurity and IT GRC leadership with deep technical experience across infrastructure, cloud security, vulnerability management, SIEM, IAM/PAM, incident response, business continuity, and disaster recovery. Experienced in executive and client advisory, security program development, remediation, team leadership, and client and vendor relationship management across enterprise and managed-service environments.
Compétences
- Active Directory
- Amazon Web Services
- assessment
- Burp Suite
- Business Application Support
- CentOS server administration
- Client Relationship Management
- Communication
- Critical Thinking
- Jira
- Leadership
- Linux
- Microsoft 365
- Microsoft Azure
- Nessus
- Policy development
- policy implementation
- Python
- Regulatory Compliance
- Risk Management
- SLA Management
- Technical Documentation
- Technical Reporting
- Gestion du temps
- Windows
- Wireshark
Expérience
Senior Security Consultant (Contract)
KPMG Canada
mai 2024 to mai 2026
Led and recovered complex cybersecurity, technology-risk, and AI-governance engagements for public-sector and energy clients across enterprise IT, operational technology (OT), AWS, and generative AI environments, working directly with project sponsors and senior business, technology, security, and risk stakeholders. • Recovered and accelerated time-sensitive cybersecurity and technology-risk engagements, restoring schedules, protecting client commitments, and delivering within budget. • Developed and presented repeatable, scalable AI-accelerated NIST CSF 2.0 and ISO 27001-aligned IT/OT risk assessment methodologies covering threat modelling, risk scenario development, inherent and residual risk scoring, control gap analysis, and prioritized treatment plans for ongoing use. • Led client workshops with project sponsors and business, technology, security, and risk stakeholders to clarify scope, resolve evidence gaps, align priorities, and drive remediation decisions. • Built reusable assessment methods, scoring models, stakeholder guides, and executive reporting templates to improve delivery consistency and client adoption. • Led IT/OT and cloud security assessments across AWS, enterprise IT, and operational technology environments, translating technical findings into business-aligned security and risk decisions for senior stakeholders. • Mapped generative AI governance risks to NIST AI RMF and ISO 42001, including shadow AI detection, acceptable use controls, AI risk scenarios, and prioritized remediation actions. • Produced executive security and risk roadmaps identifying critical control gaps, remediation actions, ownership, and implementation priorities.
Security & GRC Lead
WIS International
janv. 2022 to avr. 2024
Led the modernization of the organization's cybersecurity, governance, risk, and compliance program, directing a three-person team and partnering with IT Operations across vulnerability management, incident preparedness, policy and standards, third-party security, audit readiness, and compliance. • Led annual SOC 1, SOC 2 and PCI DSS assessments, liaising with internal risk owners and external auditors, collecting evidence, analyzing controls, and achieving zero major findings across consecutive years. • Established AI risk management practices for Microsoft 365 Copilot governance, generative AI acceptable use, shadow AI detection, and AI tool risk assessment aligned with NIST AI RMF and ISO 42001 frameworks. • Evaluated and implemented OneTrust as the enterprise GRC platform, built the ISMS and compliance workflows, and reduced manual evidence collection time by approximately 50% in the first year. • Formalized third-party risk assessment workflows, covering SaaS vendor IT security, AI usage, and data-handling risks using CAIQ and SIG Lite framework-aligned security assessment questionnaires. • Developed and maintained incident response plans and playbooks for common cybersecurity scenarios. • Managed monthly phishing simulations and security awareness campaigns to strengthen security awareness across the organization. • Managed the IT policy and standard library, creating new governance policies while updating more than 20 existing IT governance and security standards aligned with NIST 800-53, CIS Controls, ISO 27001, and ITIL. • Led endpoint vulnerability remediation oversight across Windows, Linux, and AWS systems through ManageEngine, working with IT Operations to drive prioritization and timely closure of critical findings.
Senior Security Consultant (Contract)
Toyota Canada Inc.
avr. 2020 to déc. 2020
Served as lead consultant for IT risk advisory on the enterprise modernization and IBM mainframe-to-AWS cloud migration program, providing guidance across infrastructure security and control governance. • Advised CIO and infrastructure leadership on inherent technology risk in on-prem to cloud migration, control requirements, and infrastructure protection priorities during platform modernization programs. • Conducted NIST CSF-aligned asset-based IT risk assessments across cloud, infrastructure, and enterprise technology environments, identifying control gaps and practical remediation priorities. • Defined secure deployment, hardening, and vulnerability remediation standards for Windows and Linux systems to improve infrastructure security alignment and operational consistency. • Developed CIS Benchmark-aligned security standards covering Azure, Google Cloud, Windows Server, and Linux platforms, supporting consistent control implementation across hybrid environments. • Redesigned IBM QRadar SIEM use cases to enhance alert visibility and security operations response times. • Provided Secure SDLC policy guidance to project and technology teams during application modernization.
IT Governance Team Leader
Scotiabank
sept. 2018 to mars 2020
Led a five-person IT governance team accountable to the global CISO office for bank-wide security policy governance. • Maintained the bank-wide IT governance program and ISMS on behalf of the global CISO office, gaining consensus from regional risk owners and overseeing policy review and approval cycles across teams. • Reported policy governance status, regional risk acceptance, and OSFI regulatory response progress to the CISO office and senior technical leadership, supporting executive visibility and IT risk decision-making. • Served as delegated backup to the Senior Director for OSFI regulatory response, coordinating evidence collection, regulator inquiries, stakeholder engagement, and remediation tracking artifacts. • Managed annual updates and ratification of IT security policies and hardening standards, mapping AWS, Windows, Unix and Linux security control requirements to CIS Benchmarks. • Oversaw risk acceptance workflows, compensating controls, and exception reporting for regional risk owners. • Validated security control remediations and rectified configuration drift from baseline via Tripwire CCM. • Delivered Cofense PhishMe simulations and security awareness sessions, reducing employee click rates.
Senior Security Compliance Consultant (Contract)
Bank of Montreal
juill. 2017 to juill. 2018
Engaged as senior technical specialist to lead a security tooling and control rationalization program addressing critical gaps between vulnerability assessment tooling, privileged-access controls, and BMO hardening standards. Delivered the project successfully on time and on budget. • Reconfigured Qualys vulnerability and configuration assessment logic to align with BMO hardening standards and internal security policies, resolving major discrepancies between scan output and formal control requirements. • Assessed Unix and Linux privileged-access controls across sudo, CyberArk, and CA eTrust, strengthening PAM/IAM governance and privileged-access evidence quality. • Remediated security control assessment gaps across more than 100 Unix and Linux production systems, improving hardening alignment, reporting accuracy, and control validation quality. • Validated control remediation in lower environments prior to production deployment, following ITIL change management practices to ensure fixes met bank requirements. • Provided expert-level legacy Unix and Linux platform escalation support, resolving critical infrastructure issues through vendor collaboration based on deep subject matter expertise.
Senior Technical Specialist
Blair Technology Solutions
août 2014 to mars 2017
Served as a client-facing technical account and solution delivery lead within a managed service provider (MSP), spanning account relationship management, pre-sales, solution architecture, SOW development, implementation, post-implementation transition, and ongoing support for clients in legal, financial, and manufacturing sectors. • Managed account relationships with client technical, operational, vendor, and business stakeholders, maintaining continuity across discovery, solution design, delivery, escalation, and long-term support. • Led pre-sales discovery, solution design, and SOW development through IBM and SUSE vendor partnerships, translating client requirements into platform security hardening, high-availability architecture, systems management, and recovery engagements across Windows x86, Unix/Linux, IBM Power, and Oracle SPARC environments. • Coordinated implementation and post-implementation transition activities across client teams, vendors, and internal support functions to ensure solutions were deployable, supportable, and operationally stable. • Designed business continuity and disaster recovery solutions covering cross-site failover, failback testing, operational runbooks, and platform restoration planning. • Conducted technical security assessments across client infrastructure, endpoint, and network environments, identifying vulnerabilities and configuration risks mapped to MITRE ATT&CK-aligned controls. • Developed operational runbooks, security playbooks, and incident response procedures to support escalation, recovery execution, managed service operations, and long-term account support.
Senior Technical Lead, Vulnerability Management
TD Bank
févr. 2009 to juin 2014
Led two consecutive mandates covering a multi-year vulnerability management and remediation program across more than 700 production systems, along with IBM Power/AIX legacy platform consolidation and capacity planning. • Rebuilt TD’s vulnerability remediation program across Windows, Unix, and Linux production systems by integrating third-party dashboards, establishing remediation workflows, prioritization methodology, escalation paths, and KPI/KRI reporting. • Developed CIS Benchmark-based security hardening standards for Windows, Unix, and Linux systems, creating the technical baseline for vulnerability remediation prioritization and control validation. • Coordinated infrastructure and operations teams on remediation follow-up, validating control closure and delivering KPI/KRI reporting to technology leadership throughout the program lifecycle. • Strengthened PAM/IAM and identity governance practices for privileged Unix and Linux access by enforcing sudo rules, privileged account controls, and user access reviews to meet bank audit requirements. • Drove IBM Power/AIX legacy platform consolidation across more than 100 web banking infrastructure systems, delivering server rightsizing, capacity forecasting, and growth planning that reduced end-of-life support costs.
Formation
University of Toronto, Scarborough
Computer Science
Permis et certifications
Certified Information Systems Security Professional (CISSP)
ISC²
Certified Data Protection Specialist
Data Management Institute