Matthew Sain

Matthew Sain

Cybersecurity & GRC Executive

Strategic leader with 10+ years driving enterprise security transformation across Fortune 10/100 corporations, government agencies, critical infrastructure, and healthcare institutions. Proven expertise in governance, risk management, and regulatory compliance on a global scale.

CISSP Certified $4M+ Budget Oversight Global Team Leadership

Leadership Overview

CISSP-certified executive specializing in governance, risk, and compliance across ISO 27001, ISO 31000, NIST, NIS2, GDPR, SOC 2, PCI DSS, and FedRAMP frameworks. Hands-on experience aligning regulatory requirements across EMEA and the Americas.

Proven ability to advise Directors, CISOs, and executive boards on security governance, compliance strategies, and risk remediation across hybrid cloud and enterprise networks. Led deployment and optimization of SIEM, SOAR, and vulnerability management platforms including Splunk, Microsoft Defender, and Azure Sentinel.

Oversees implementation of security automation using Python, Logic Apps, and JSON; integrates best practices into CI/CD pipelines and DevOps infrastructure with extensive background in firewall architecture, perimeter security, and secure cloud adoption across AWS, Azure, and hybrid environments.

10+
Years Experience
$4M+
Budget Managed
12+
Team Size Led
15+
Certifications

Professional Experience

Nov 2025 – Present

Member Board of Directors – President

USA Jobs Data

Board leadership role providing strategic direction and governance oversight for organizational operations.

Sep 2024 – Present

Principal Owner

Vulnguard

Leading independent cybersecurity consultancy delivering enterprise security strategy, GRC advisory, and technical implementation services.

May 2025 – Nov 2025

Governance, Risk, and Compliance Manager

Vatican

Supporting governance, risk, and compliance operations within the Vatican's global cybersecurity framework. Designing risk management and compliance strategies aligned with cyber ethics and resilience objectives.

Dec 2017 – Sep 2024

Principal Consultant

CloudMedic

Directed a global team of 12 cybersecurity engineers, delivering security strategy across AWS, Azure, and hybrid environments for multinational enterprises. Led regulatory compliance initiatives across government, defense, healthcare, and critical infrastructure sectors. Consulted for Fortune 10 and Fortune 100 enterprises, advising executive leadership on high-impact security projects. Oversaw $4M+ cybersecurity budget.

Aug 2023 – Apr 2024

Cyber Monitoring & Defense Center Expert

Knorr-Bremse AG

Designed and optimized SIEM, SOC, and SOAR workflows. Developed security governance frameworks aligning SOC operations with ISO 27001 and GDPR standards. Delivered strategic risk assessments to executive stakeholders.

Jan 2022 – Jul 2023

Senior Security Engineer

Veeam Software

Led cross-functional teams deploying threat detection solutions including Splunk and Azure Sentinel. Implemented GRC strategies for AWS, Azure, Linux, and Windows environments. Achieved and maintained compliance with ISO 27001, GDPR, and NIST standards.

May 2019 – Jan 2022

Network Security Engineer

Fortinet

Collaborated with enterprise clients and government agencies across EMEA and the Americas to design secure network architectures. Ensured compliance with ISO 27001, NIST, GDPR, HIPAA, and PCI DSS frameworks.

Professional Certifications

Security

  • CISSP – Certified Information Systems Security Professional
  • SC-200 – Microsoft Security Operations Analyst
  • SC-900 – Microsoft Security, Compliance, and Identity
  • PCNSE – Palo Alto Networks Certified Engineer
  • Fortinet NSE Level 7 – Advanced Security
  • Fortinet NSE Level 4 – Security Professional

Cloud & Infrastructure

  • AWS Solutions Architect – Associate
  • Microsoft Azure Data Explorer
  • AZ-900 – Microsoft Azure Fundamentals
  • CCNA – Cisco Certified Network Associate
  • JNCIA-Junos – Juniper Networks Certified Associate

Management & Tools

  • Certified ScrumMaster (CSM)
  • Splunk Power User
  • B.S. Business Management – Western Governors University

Technical Expertise

GRC & Compliance

NIST CSF, ISO 27001, SOC 2, HIPAA, PCI DSS, GDPR, MITRE ATT&CK, NIS2, FedRAMP, ISO 31000

Cloud Security

AWS Security Hub, Azure Security Center, Prisma Cloud, Hybrid Environments, CI/CD Pipeline Security

SIEM & Threat Detection

Splunk, Microsoft Sentinel, QRadar, Elastic Security, Azure Sentinel

Endpoint & Network Security

Microsoft Defender, CrowdStrike, Fortinet, Palo Alto Networks, NGFW, DLP/DPS

Vulnerability Management

Tenable Nessus, Qualys, Rapid7, ServiceNow, Archer GRC

Automation & Scripting

Python, PowerShell, Terraform, Logic Apps, JSON, DevOps Integration

Get in Touch

Location
Wilmette, Illinois
Website