Cybersecurity Governance

Matthew Kaufman

Vice President — Head of Cybersecurity Governance

mkaufman1@gmail.com · LinkedIn · Self-hosted on AWS

Technology executive at the intersection of enterprise risk and business growth with 18 years of experience, combining executive presence with technical credibility to build security governance programs that withstand regulatory scrutiny and align cybersecurity investments with business priorities. Currently Head of Cybersecurity Governance at IDB Bank, directing implementation of cybersecurity strategy. Track record of partnering with cross-functional teams to drive consensus-based decisions to achieve cybersecurity maturity with oversight of a $3M budget.

CISSP

Certified Information Systems Security Professional

CGRC

Certified in Governance, Risk and Compliance

CDPSE

Certified Data Privacy Solutions Engineer

CCSK

Certificate of Cloud Security Knowledge

GCAD

GIAC Cloud Security Architecture and Design

GCIH

GIAC Certified Incident Handler

Cybersecurity and AI Governance · Regulatory Compliance · Enterprise Risk Assessments · Executive & Board Reporting · Audit & Regulatory Remediation · Incident Response Governance · Tabletop Exercises · Third-Party Risk Management · Vulnerability Management · Application Security · Secure SDLC · DevSecOps · Cloud Security (AWS/Azure) · IAM & Data Protection · Security Metrics & KRIs · Security Policy & Standards

Tools & PlatformsSplunk · CrowdStrike · Qualys · Tenable · ServiceNow · Archer · Checkmarx · SonarQube · AppSpider · Netsparker

FDIC · NYDFS 500 · FFIEC · NIST CSF · CIS Controls · ISO 27001

Vice President — Head of Cybersecurity Governance (CIO Organization)

06/2022 – Present

Israel Discount Bank (IDB Bank)

  • Own enterprise-wide cybersecurity governance across engineering, risk, and operations, reporting directly to the CISO; manage a $3M cybersecurity budget and the full-time consultants supporting multiple security engagements.
  • Trusted by executive leadership to represent cybersecurity in regulatory examinations from FDIC and DFS.
  • Reduced risk reporting timelines by 50% by standardizing the bank's view of cyber risk through a suite of dashboards integrating risk indicators.
  • Reduced repeat audit findings 100% by overhauling how issue evidence and remediation are tracked and owned.
  • Own the cybersecurity issues management program end-to-end — identification, tracking, remediation planning, and closure — for exercises such as FedLine, SWIFT CSCF, and internal audit findings, managing 15+ open issues at any given time in Archer.
  • Partner across vulnerability management, security engineering, IT asset management, and Application Security to keep governance embedded in IT processes.
  • Lead vendor evaluations (e.g., ZeroFox) for the CISO, evaluating vendor claims against real performance before committing budget.
  • Helped shape AI governance control requirements, including CrowdStrike's AI detection and response capabilities, ensuring AI systems are secured from a controls perspective.

Vice President, Information Security Officer

04/2021 – 06/2022

Mizuho Americas — Americas Risk Management (2LOD) & CIO Organization (1LOD)

  • Led governance oversight for the enterprise Incident Response program, including tabletop exercises, policy management, and maturity initiatives.
  • Built and led the bank's first application security governance program, collaborating with developers on SAST/DAST testing across 100+ applications (Checkmarx, SonarQube, AppSpider, Netsparker).
  • Built KRIs and reporting metrics to track application security risk and remediation progress.
  • Worked directly with Internal Audit, Compliance, and Risk Management to close remediation items and keep governance controls audit-ready, using Archer as the system of record.
  • Rewrote security policies for cloud, acceptable use, and end-user computing. Ran monthly security awareness communications.

Assistant Vice President, Information Security Officer

12/2018 – 04/2021

Mizuho Americas — Americas Risk Management (2LOD)

  • Held the same core responsibilities as the role above prior to promotion to Vice President, building the foundation for the Incident Response, application security governance, and GRC reporting programs.

Vice President, Information Security Specialist

06/2017 – 12/2018

BNY Mellon, New York, NY

  • Led and quality-controlled cybersecurity assessments for bank affiliates and third parties using NIST, ISO 27001, and BNY Mellon's Cybersecurity Services Model.
  • Identified control gaps and vulnerabilities, partnering with stakeholders as part of the mergers and acquisition process to fix root causes across several boutique banks and affiliate institutions.
  • Built cybersecurity maturity dashboards that improved executive visibility on program adoption and risk-based decision-making across business units.

Security Assessment Technical Lead & Security Subject Matter Expert

09/2014 – 05/2017

Blue Canopy Group, Arlington, VA

  • Led 20+ NIST 800-53A security assessments for federal enterprise systems.
  • Coordinated vulnerability assessments and penetration testing aligned with OWASP Top 10 using Tenable, Splunk, and SailPoint.
  • Developed Windows and macOS security configuration baselines to meet USGCB and FDIC requirements.
  • Led secure architecture review and remediation initiatives across infrastructure and application environments.

George Mason University, Fairfax, VA

M.S., Applied Information Technology, 2013

B.S., Management, 2008