Summary
Overview
Work History
Education
Skills
Certification
Languages
Timeline
Generic
Windy Chan

Windy Chan

Amsterdam

Summary

With information security experience in specifically security awareness, GRC and GDPR, I am currently looking for an IT-auditing role.

In this role I can use my integrity, eye for detail, empathetic character and multicultural background to analyze, zoom in and identify on systems, processes and human behavioural patterns to continue further develop the information processing facilities of the organization.

Overview

8
8
years of professional experience
1
1
Certification

Work History

GRC consultant

Maxima Technologies
04.2022 - Current

Notable projects:

Flemish government, Brussels

  • ISO 27001 certification preparation for the project Digitaal Vlaanderen
  • Review the contracts with third-parties to ensure GDPR compliance
  • Setting up risk assessments and mitigation strategies for data protection
  • Assisting in developing their information security policies


Maritime and Coastal Services, Amsterdam

  • Reviewing contracts with their third-party data processors
  • Conducting risk assessments and mitigation strategies for data protection
  • Assisting in risk mitigation by implementing security controls, such as data encryption, anonymization, pseudonymization and access control

Sabbatical leave

10.2021 - 03.2022
  • Embarked on a 6-month sabbatical focused on personal mental health and well-being, acquiring mindfulness techniques that benefit both my personal and professional life
  • Followed a Spanish language course for beginners
  • Followed online modules about how Microsoft safeguards customer data

Information Security consultant

Ordina
01.2019 - 09.2021

Project at Pro Persona, Nijmegen

  • Increase the information security level by rewriting the data protection policies
  • Identify the data processing activities of the patients of the clinic
  • Risk analyses of patient's data and communication devices within the clinic
  • Raising the security awareness level by educating the staff on phishing, social engineering and secure data handling

Information Security consultant

ilionx
01.2017 - 12.2018

Notable projects: ASML, Eindhoven

  • Determining the current level (IST) and desired (SOLL) level of the security awareness and helping mitigating the gap by implementing security controls
  • Mapping the information security landscape for the strategic roadmap
  • Developing and implementing awareness campaigns on a national and international level
  • Training employees on data protection and GDPR compliance


SURFnet, Utrecht

  • Creating an online community for the target group (CISO's and privacy officers of Dutch educational institutions) where they can share thoughts and ideas
  • Developing the Cyber Save Yourself campaign and toolkit which the target group uses to increase the security awareness level of their students and colleagues

Education

Master of Arts - Contemporary Asian Studies

University of Amsterdam
Amsterdam

Bachelor of Arts - Sociology

University of Amsterdam
Amsterdam

Skills

    Governance, Risk and Compliance (GRC)

    GDPR

    ISO 27001/2

    Security awareness

    Risk management

    Risk analysis

    Process management

    Project management

Certification

Certified Information Systems Auditor (CISA), ISACA

In progress


ISO/IEC 27001 Lead Implementer, PECB

2023 — 2023


Certified Information Security Manager (CISM), ISACA

2020 — 2020


Security Awareness Officer, Security Academy, Woerden (NL)

2018 — 2018


Systems Security Certified Practitioner (SSCP), Koenig Solutions, New

Delhi (India)

2017 — 2017

Languages

Dutch
Native language
English
Proficient
C2
Chinese (Cantonese)
Intermediate
B1

Timeline

GRC consultant

Maxima Technologies
04.2022 - Current

Sabbatical leave

10.2021 - 03.2022

Information Security consultant

Ordina
01.2019 - 09.2021

Information Security consultant

ilionx
01.2017 - 12.2018

Master of Arts - Contemporary Asian Studies

University of Amsterdam

Bachelor of Arts - Sociology

University of Amsterdam
Windy Chan