vCISOonCall
vCISOonCall
  • Home
  • About

NICOLE ROSEN

CAREER EXPERIENCE (Full-time & Contracting)


vCISO On Call (formerly 180security.com)  |  2019–PRESENT   |  Founder & Chief Consultant 

Aledade  |  2024–2025  |  Security & Head of GRC 

Disney Streaming / Hulu  |  2019–2023  |  Head of Security GRC, Data Protection & Content Security 

Global Eagle  |  2015–2019  |  Head of Information Security, Risk & Compliance 

Banc of California  |  2014–2015  |  Information Security / Deputy CISO Leader

AAA of Southern California  |  2012–2013  |  Third-Party Information Protection Risk Management 

PCV Murcor  |  2010–2011  |  Head of Information Security

Experian  |  2008–2010  |  Enterprise Information Security

Zions Bancorporation  |  2007–2008  |  Privacy Officer & Information Compliance Leader

CoreLogic (formerly First American CoreLogic)  |  2007  |  Information Security Management Leader

ACC Capital Holdings  |  2005–2007  |  Information Security & Privacy

PacifiCare Health Systems  |  2004–2005  |  HIPAA Privacy & Security Program Management

CompPartners  |  2002–2004  |  HIPAA Compliance Officer & Technical Documentation Leader

HNC Software  |  1998–2000  |  Software Technical Writing, Quality Assurance & Regulatory Research


EDUCATION


Master of Information Technology (MIT), Internet Security — 2004

Bachelor of Business Administration (BBA) — 1997


CERTIFICATIONS


CISSP — Certified Information Systems Security Professional   

CIPP/US — Certified Information Privacy Professional

CIPT — Certified Information Privacy Technologist

CDPSE — Certified Data Privacy Solutions Engineer

FIP — Fellow of Information Privacy

GSTRT — GIAC Strategic Planning, Policy & Leadership

GLEG — GIAC Law of Data Security & Investigations

GSLC — GIAC Security Leadership Certification.


GRC,  AI ASSURANCE & GOVERNANCE, AND PERSONAL SOFTWARE PROJECTS 


AI Agent Trust & Transparency Platform  — Provides visibility into what autonomous and semi-autonomous AI agents are actually doing, not just what they are saying. It discovers agents, tracks identities and ownership, maps data lineage, tools and APIs, monitors downstream dependencies and cross-boundary activity, and produces live agent transparency and trust reporting.


AI Governance Module for Integrated Governance, Risk & Compliance Platform — The embedded AI governance capability within the integrated governance, risk and compliance platform. It provides governance around AI use, including inventory, ownership, risk classification, lifecycle oversight, policy and control requirements, assessments, approvals, and alignment with frameworks such as the NIST AI RMF.


AI Governance, Assurance & Testing Platform — An AI assurance platform designed to continuously test, evaluate, and monitor AI systems using multiple testing and evaluation engines. It turns technical AI testing into governance and executive-level visibility across security, safety, reliability, compliance, and trust.


Accessible Reading & Audiobook Platform — A personal reading and listening platform for PDF and EPUB libraries that combines traditional reading with natural text-to-speech and read-along capabilities. It supports local OCR for scanned books, highlights, notes, bookmarks, definitions, pronunciation corrections, customizable reading modes, library-wide search, metadata and genre organization, collections, reading status, and exportable notes and highlights.


Compliance Visibility & Evidence Platform — A standalone compliance management platform designed to make regulatory and framework obligations understandable and operational. It maps requirements to controls and evidence, identifies gaps and overlaps, and gives organizations a clearer view of compliance posture across multiple frameworks rather than managing each one in isolation.


Cyber Risk Quantification & Scenario Modeling Platform — A standalone quantitative risk platform using FAIR-based analysis and Monte Carlo simulation to translate cyber scenarios into financial exposure. It helps leadership understand probable loss, compare mitigation options, evaluate investment decisions, and communicate cyber risk in business terms.


Decision-Centric GRC Platform — Reimagines GRC around the decision rather than the control, risk, or compliance requirement. It connects obligations, interpretations, controls, evidence, risk, appetite, approvals, agent activity, and decision receipts so organizations can understand not only whether a decision was permitted, but why it was made and whether it remains valid as conditions change.


End-of-Life Planning & Family Information Platform — A separate death doula/midwife-focused platform designed to help individuals organize the information, wishes, documents, contacts, accounts, and personal details their families may need at the end of life. Its purpose is to make an extraordinarily difficult period less confusing for the people left to handle everything and covers what medical and legal documentation does not address.


Enterprise Risk Register & Risk Management Platform — A practical risk management platform for capturing, assessing, prioritizing, assigning, treating, accepting and continuously monitoring organizational risk. It is intentionally designed to be easier and more intuitive than many of the complex risk and GRC offerings available today, while providing a structured alternative to the spreadsheets many organizations still rely on for risk management.


ISO Management & Certification Readiness Platform — A purpose-built platform for managing ISO 27001 implementation, ongoing compliance, and certification readiness. It connects requirements, controls, risks, evidence, ownership, gaps, corrective actions, and audit activity in one operational environment, with support for ISO 27002 guidance and ISO 42001 AI management capabilities as organizations expand their programs.


Infrastructure Governance & Assurance Platform — A governance-first Infrastructure as Code platform that connects source control, CI/CD, cloud environments, IaC tools, and security scanners to continuously evaluate infrastructure changes and deployed environments. It identifies misconfigurations, policy violations, drift, control gaps, and exceptions while maintaining ownership, approvals, evidence, and traceability from code through deployment.


Integrated Governance, Risk & Compliance Platform — A unified GRC platform bringing risk, compliance, third-party risk, AI governance, security operations, privacy, resilience, and executive reporting together. It serves as the integrated environment that brings the specialized capabilities of the broader portfolio into a single operational view.


Local AI Agent Development & Testing Platform — A local environment for building, configuring and testing AI agents, their tools, integrations and behaviors while maintaining greater visibility and control over the development environment. It provides a practical workspace for experimenting with agent capabilities and understanding how agents interact with models, data, APIs and external systems before they are introduced into more consequential environments.


Personal Music Memory & Life Soundtrack Platform — A consumer music storytelling platform that connects songs with the memories, people, places, photos, and moments that give them meaning. It can use music libraries and listening history to help surface significant songs and build personal soundtracks for everyday memories and major life events, including birthdays, weddings, anniversaries, and celebrations of life, with integration into end-of-life planning platform for memorial music and storytelling.


Regulatory & Standards/Frameworks Change Monitoring Platform — Monitors regulatory, legislative and standards/frameworks developments across AI governance, privacy and information security, tracking proposals, approvals and implementation milestones so organizations can prepare before requirements take effect. Retains supporting evidence, distinguishes confirmed changes from unverified announcements, and provides searchable, topic-filtered views tailored to an organization or project.


Risk Assessment & Security Maturity Management Platform — A streamlined platform for conducting security, privacy, compliance and AI governance risk and maturity assessments without turning the assessment itself into an administrative burden. It brings together framework requirements, interviews, observations, evidence, findings, maturity scoring, risk, remediation priorities and roadmaps while keeping maturity and finding severity distinct and maintaining traceability from assessment through action.


Security Representation Assurance Platform egulatory — Continuously verifies whether what an organization says about its security is actually true. Identifies security representations across contracts, questionnaires, policies, audits, insurance applications, Trust Centers, and other sources, links claims to supporting evidence and operational reality, and detects contradictions, unsupported assertions, and changes that could invalidate prior commitments.


Third-Party Risk Intelligence Platform — A standalone third-party risk management platform for evaluating and continuously understanding vendor risk. It combines evidence and document analysis, security and privacy assessment, regulatory and framework mapping, contracts, insurance, subprocessors, geographic exposure, AI usage, exceptions, and year-over-year risk intelligence into a consolidated vendor view.

Copyright © 2026 vCISO On Call - All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept