With over 14 years of progressive experience in the IT industry, I am a seasoned IT security professional. I possess a proven ability to identify and address business risks and compliance issues proactively. My expertise lies in designing and implementing robust solutions to ensure the security and compliance of IT systems, demonstrating a track record of success in navigating the evolving landscape of information security.
As a Senior Consultant, I specialize in conducting audits and assessments for ISO 27001, 27017, 27018, 27701, and 42001, as well as privacy evaluations, internal audits, and GAP assessments. My responsibilities include planning and executing engagements, leading client meetings, performing audit testing, and ensuring effective communication throughout the audit lifecycle.
I bring expertise in reviewing reports, supervising teams, organizing critical client documentation, and providing regular project status updates. My approach combines deep knowledge of international standards, project management skills, and a commitment to excellence, ensuring audits deliver measurable value and support organizations in achieving compliance and operational resilience.
Delivering official certification trainings:
ISO 27001 Introduction/Foundation/Lead Implementer/Lead Auditor/Transition
As a Senior Consultant, I focus on executing ISO 27001, 27017, 27018, and 27701 examinations, as well as Privacy, internal audit, and GAP assessments. My responsibilities include planning and executing engagements, leading client meetings, performing audit testing, maintaining effective communication, reviewing reports, providing project status updates, organizing client information, supervising staff.
As the vCISO (virtual Chief Information Security Officer), accountable for governance activities and the management of information security and risk. Responsible for advising and overseeing security measures to safeguard company or client assets effectively.
Responsible for implementing practical computer security solutions to enhance overall cybersecurity posture. Engaged in the analysis and development of the Information Security Management System (ISMS) to establish a comprehensive framework for safeguarding sensitive information and ensuring compliance with security standards.
Responsible for identifying, developing, implementing and maintaining processes in the organization to reduce risks in the information assets and technology platform, as well as responding to incidents, establishing appropriate standards and policies and ensuring that these are properly complied with.
Information security
Risk Management
Risk Assessment - Gap Analysis
Internal Audit
ISO/GDPR/SOC/PCI-DSS/SWIFT Compliance
Incident Management and Resolution
Business Continuity/Disaster Recovery
Vendor Management
Project Management
Data Security
Asset Management
Procurement
CISA | Certified Information Security Auditor | ISACA | 2023
CISM | Certified Information Security Manager | ISACA | 2022
CDPSE | Certifies Data Privacy Solutions Engineer | ISACA | 2021
ISO/IEC 27001 Senior Lead Auditor | PECB | 2021
ISO/IEC 27001 Senior Lead Implementer | PECB | 2021
ISO/IEC 27701 Senior Lead Auditor | PECB | 2024
ISO/IEC 27701 Senior Lead Implementer | PECB | 2024
NIST Cybersecurity Consultant | PECB | 2025
IPC Management Systems Auditor | PECB | 2023
ISO/IEC 42001 | 27701 | 27002 | 27035 | 20000 | Cybersecurity Foundation | PECB | 2024/2025
Certified Lead Cloud Security Manager | PECB | 2021 (based on ISO/IEC 27017 and ISO/IEC 27018)
Certified Trainer | PECB | 2023
ITIL® 4 Foundation | PeopleCert Axelos | 2020
Info: https://www.youracclaim.com/users/sergio-a-morales-s/badges
ISACA Panama Chapter
(Director of Communications) 2024/2025