{"id":16,"date":"2026-07-30T20:26:05","date_gmt":"2026-07-30T18:26:05","guid":{"rendered":"https:\/\/www.johnsalomon.com\/?page_id=16"},"modified":"2026-07-30T20:29:46","modified_gmt":"2026-07-30T18:29:46","slug":"resume","status":"publish","type":"page","link":"https:\/\/www.johnsalomon.com\/?page_id=16","title":{"rendered":"Resume \/ CV"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">Overview<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Highly experienced, international information security leader with cross-cultural management experience and strong technology background.&nbsp; Outstanding networker, innovative solutions-oriented strategist and critical advisor, excellent communicator, engaged coach, startup board advisor, and pace-setter<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Keywords: cybersecurity, information security, risk management, governance, compliance, GRC, resilience, business continuity management, CISO \/ vCISO, cyber threat defense, strategy, policy, consulting, advisory, team building<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Education<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2007 \u2013 2008<\/strong><br><strong><a href=\"https:\/\/insead.edu\" target=\"_blank\" rel=\"noreferrer noopener\">INSEAD<\/a><\/strong> (France) \u2013 Master of Business Administration<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1992 -1996<\/strong><br><strong><a href=\"https:\/\/berkeley.edu\" target=\"_blank\" rel=\"noreferrer noopener\">University of California, Berkeley<\/a><\/strong> (USA) \u2013 B.A. International Relations<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Experience<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Current<br>Various Clients<\/strong><br>Information Security Leadership Advisor \u2013 International<br><em>Expert advisor to solution providers in the domains of information security, resilience, policy, testing, GRC (governance, risk, compliance), strategy, and risk management<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Development of cybersecurity product strategy and implementation planning\/rollout<\/li>\n\n\n\n<li>Development of risk \/ compliance control maps for various cybersecurity products<\/li>\n\n\n\n<li>Creation of pilot industry mentorship programme for cybersecurity career aspirants in university<\/li>\n\n\n\n<li>Launch and management of communications strategy and public relations channels for various cybersecurity industry groups<\/li>\n\n\n\n<li>Business development \/ client acquisition and go-to-market for cybersecurity startups in the EMEA region<\/li>\n\n\n\n<li>Coaching and board advisory function for multiple high-visibility, innovative cybersecurity startups<\/li>\n\n\n\n<li>Board membership, strategy and community development, and activity coordination for global crypto credit\/lending industry advocacy association<\/li>\n\n\n\n<li>Development and maturing of multiple cross sector consortia and industry associations in the information security space<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2014 \u2013 2022<\/strong><br><strong><a href=\"https:\/\/fsisac.com\" target=\"_blank\" rel=\"noreferrer noopener\">Financial Services Information Sharing and Analysis Center (FS-ISAC)<\/a><\/strong><br>Director, Europe (2014-2015) \u2013 Cologne (DE)<br>Director, Australia &amp; New Zealand (2015-2017) \u2013 Melbourne (AU)<br>Director, EMEA (2017-Present) \u2013 Munich (DE), Barcelona (ES)<br><em>Regional lead at global financial sector consortium for collective defence and resilience building \u2013 world\u2019s largest sector-specific information security community with more than 7,000 member firms<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Developed and led regional member communities and services portfolio<\/li>\n\n\n\n<li>Responsible for >500% FS-ISAC regional membership revenue growth in EMEA and AUNZ over 7 years, building and managing relationships with large number of major financial institutions, including ca. 30% G-SIB member firms<\/li>\n\n\n\n<li>Initiated FS-ISAC expansion into Latin America<\/li>\n\n\n\n<li>Initiated and\/or expanded FS-ISAC stakeholder and MoU network, with key entities such as <a href=\"https:\/\/interpol.int\" target=\"_blank\" rel=\"noreferrer noopener\">Interpol<\/a>, <a href=\"https:\/\/ebf.eu\" target=\"_blank\" rel=\"noreferrer noopener\">European Banking Federation<\/a>, <a href=\"https:\/\/efr.be\" target=\"_blank\" rel=\"noreferrer noopener\">European Financial Services Round Table<\/a>, numerous NCSCs, sector CSIRTs, and intergovernmental central banks\u2019 cyber resilience coordination groups in Middle East and Africa<\/li>\n\n\n\n<li>Led, expanded, and professionalized <a href=\"https:\/\/fsisac.com\/ceresforum\" target=\"_blank\" rel=\"noreferrer noopener\">CERES Forum<\/a> for central banks, regulators, and supervisors, changing the way regulatory entities worldwide interact and collaborate<\/li>\n\n\n\n<li>Launched FS-ISAC participation in annual <a href=\"https:\/\/ccdcoe.org\/locked-shields\/\" target=\"_blank\" rel=\"noreferrer noopener\">Locked Shields<\/a> collective cyber-defence exercise \u2013 the world\u2019s first collective sector involvement in any international public-private cyber defence activity.\u00a0 Led first financial services technical component white team, and developed military \u2013 financial sector cooperation among multiple blue teams<\/li>\n\n\n\n<li>Led FS-ISAC inclusion in <a href=\"https:\/\/enisa.europa.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">ENISA<\/a>-led <a href=\"https:\/\/www.enisa.europa.eu\/topics\/cybersecurity-of-critical-sectors\/information-sharing-and-analysis-centers-isacs\/isacs-cooperating-with-enisa\" target=\"_blank\" rel=\"noreferrer noopener\">EU ISACs<\/a> community<\/li>\n\n\n\n<li>Created and professionalized wide range of FS-ISAC activities (events, metrics\/management reporting, membership contractual models), leading to major operational efficiency enhancements and revenue growth<\/li>\n\n\n\n<li>Organized and led dozens of successful, well-attended regional and local information security events in cooperation with banking associations, law enforcement, and security service providers<\/li>\n\n\n\n<li>Sought-after speaker at major industry events in support of collective resilience development and risk reduction<\/li>\n\n\n\n<li>Represented FS-ISAC in Europe-wide and national information security initiatives and related groups, resulting in significant growth in FS-ISAC visibility, credibility, and trust<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2012 \u2013 2014<\/strong><br><strong><a href=\"https:\/\/ubs.com\" target=\"_blank\" rel=\"noreferrer noopener\">UBS AG<\/a><br><\/strong>Executive Director \u2013 Zurich (CH)<br><em>Senior leader in information security engineering organization of global systemically important bank<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Deputy and Chief of Staff to the Managing Director of 180-person security technology group in European strategy, business continuity, and staff leadership forums<\/li>\n\n\n\n<li>Managed highly experienced information security consulting team with 21 reports on 4 continents, and an annual budget exceeding CHF 8 million<\/li>\n\n\n\n<li>Delivered end-to-end application security testing framework for mission-critical software across all divisions of the bank, allowing UBS to systematically reduce risk from software vulnerabilities and compliance impact<\/li>\n\n\n\n<li>Led successful international rollout of software developer security education and software assurance program<\/li>\n\n\n\n<li>Improved information security capabilities with significant regulatory impact during major budget cuts<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2009 \u2013 2012<\/strong><br><strong><a href=\"https:\/\/abnamro.com\" target=\"_blank\" rel=\"noreferrer noopener\">ABN AMRO<\/a> (External Consultant)<br><\/strong>Senior Risk Manager \u2013 Amsterdam (NL), Paris (FR), Cologne (DE)<em><br>Information security risk advisor for retail, commercial, investment, and private banking<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Responsible for information security risk analysis, avoidance and mitigation exposure for systems handling multibillion-euro transaction volumes, with quantifiable risk reduction of up to \u20ac30 million per project<\/li>\n\n\n\n<li>Single point of contact for corporate information security analysis organization on numerous major projects across Asia and Europe; principal risk manager for Germany and France<\/li>\n\n\n\n<li>Built strategic relationships between bank\u2019s country organizations and corporate information<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2000 \u2013 2009<br>Chakraborty SW GmbH<\/strong><br>Principal Consultant \u2013 Zurich (CH), Santiago (CL), Buenos Aires (AR)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>May 2000 \u2013 Nov 2000<br>Deutsche Merchant AG<\/strong><br>Chief Architect \u2013 Munich (DE)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Aug 1998 \u2013 May 2000<br>Perot Systems AG<\/strong><br>Systems and Security Engineer \u2013 Basel (CH)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Feb 1997 \u2013 Jul 1998<br>Bull (Suisse) SA<br><\/strong>Systems and Security Engineer \u2013 Basel \/ Zurich (CH)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Languages<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>English<\/strong>: native speaker<\/li>\n\n\n\n<li><strong>German<\/strong> \/ Swiss German: native speaker<\/li>\n\n\n\n<li><strong>French<\/strong>: fluent written\/spoken<\/li>\n\n\n\n<li><strong>Spanish<\/strong>: fluent written\/spoken<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Topics \/ Competencies<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">I have strong competency and experience in the following areas, including implementation of information security and resilience controls prescribed or recommended by<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Regulations, Legal Frameworks, Regulatory Guidance<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2555\" target=\"_blank\" rel=\"noreferrer noopener\">Network and Information Systems Directive \/ NIS2 \u2013 Directive (EU) 2022\/2555<\/a> (EU)<\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A32022R2554&amp;qid=1727703912666\" target=\"_blank\" rel=\"noreferrer noopener\">Digital Operation Resilience Act \/ DORA \u2013 Regulation (EU) 2022\/2554<\/a> (EU)<\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/eur-lex.europa.eu\/eli\/reg\/2024\/1689\/oj\" target=\"_blank\" rel=\"noreferrer noopener\">Artificial Intelligence Act \u2013 Regulation (EU) 2024\/1689<\/a> (EU)<\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\" target=\"_blank\" rel=\"noreferrer noopener\">General Data Protection Regulation \/ GDPR \u2013 Regulation (EU) 2016\/679<\/a> (EU)<\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=celex%3A32015L2366\" target=\"_blank\" rel=\"noreferrer noopener\">Payment Services Directive \/ PSD2 \u2013 Directive (EU) 2015\/2366<\/a> (EU)<\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.mas.gov.sg\/regulation\/cyber-security\" target=\"_blank\" rel=\"noreferrer noopener\">MAS Technology Risk Management \/ Cyber Hygiene<\/a> (SG)<\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.dfs.ny.gov\/system\/files\/documents\/2023\/03\/23NYCRR500_0.pdf\">New York State DFS 23 NYCRR 500<\/a> (US) \u2013 PDF<\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.hhs.gov\/hipaa\/for-professionals\/security\/guidance\/cybersecurity\/index.html\" target=\"_blank\" rel=\"noreferrer noopener\">HIPAA <\/a>(US)<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">Good Practices and Standards<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.nist.gov\/cyberframework\" target=\"_blank\" rel=\"noreferrer noopener\">NIST Cybersecurity Framework (CSF)<\/a> and <a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.nist.gov\/privacy-framework\/nist-sp-800-61\" target=\"_blank\" rel=\"noreferrer noopener\">NIST SP 800-61<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.iso.org\/standard\/27001\" target=\"_blank\" rel=\"noreferrer noopener\">ISO\/IEC 27001:2022<\/a> (Information Security Management Systems Protection) \/ <a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.iso.org\/standard\/75652.html\" target=\"_blank\" rel=\"noreferrer noopener\">27002:2022<\/a> (Information Security Controls)<\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.iso.org\/standard\/81230.html\" target=\"_blank\" rel=\"noreferrer noopener\">ISO\/IEC 42001:2023<\/a> (Artificial Intelligence)<\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.isa.org\/standards-and-publications\/isa-standards\/isa-iec-62443-series-of-standards\" target=\"_blank\" rel=\"noreferrer noopener\">ISA\/IEC 62443<\/a> (ICS Cybersecurity)<\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.aicpa-cima.com\/topic\/audit-assurance\/audit-and-assurance-greater-than-soc-2\" target=\"_blank\" rel=\"noreferrer noopener\">AICPA SOC2<\/a> (Trust Services Criteria)<\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.nist.gov\/itl\/ai-risk-management-framework\" target=\"_blank\" rel=\"noreferrer noopener\">NIST-AI-600-1 (AI Risk Management Framework)<\/a><\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">Industries<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">I have worked with and implemented cybersecurity controls and activities in the following industries:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Financial services (banking, insurance, financial market infrastructure, payment services, exchanges, fintech)<\/li>\n\n\n\n<li>Power generation and transmission<\/li>\n\n\n\n<li>Healthcare<\/li>\n\n\n\n<li>Telecommunications<\/li>\n\n\n\n<li>Rail transportation<\/li>\n\n\n\n<li>Industry<\/li>\n\n\n\n<li>Government (local and regional)<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Key Words<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Risk management, compliance, GRC, leadership, CISO, strategy, board advisor, security assurance, good practice, public-private, resilience, business continuity, collective defence, exercises, cybersecurity, information security, cyber-threat intelligence, fraud, leadership, consulting, sparring partner, security architecture, governance, security policy, security process, integration<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Downloadable CV (PDF)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/web.archive.org\/web\/20260509200820\/https:\/\/www.johnsalomon.com\/wp-content\/uploads\/2025\/07\/CV-John-Morgan-Salomon-1.pdf\">CV \u2013 John Morgan Salomon<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Highly experienced, international information security leader with cross-cultural management experience and strong technology background.&nbsp; Outstanding networker, innovative solutions-oriented strategist and critical advisor, excellent communicator, engaged coach, startup board advisor, and pace-setter Keywords: cybersecurity, information security, risk management, governance, compliance, GRC, resilience, business continuity management, CISO \/ vCISO, cyber threat defense, strategy, policy, consulting, advisory, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-16","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.johnsalomon.com\/index.php?rest_route=\/wp\/v2\/pages\/16","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.johnsalomon.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.johnsalomon.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.johnsalomon.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.johnsalomon.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16"}],"version-history":[{"count":2,"href":"https:\/\/www.johnsalomon.com\/index.php?rest_route=\/wp\/v2\/pages\/16\/revisions"}],"predecessor-version":[{"id":18,"href":"https:\/\/www.johnsalomon.com\/index.php?rest_route=\/wp\/v2\/pages\/16\/revisions\/18"}],"wp:attachment":[{"href":"https:\/\/www.johnsalomon.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}