Cybersecurity, Privacy & AI Governance Executive

Helping organizations govern risk, data, and AI responsibly.

I bring 20+ years of cross-sector leadership in cybersecurity, privacy & data protection, and AI governance across financial services, aviation, healthcare, government, and enterprise manufacturing. Fluently bilingual (EN/FR). Board-ready. Available for senior-level roles including Head of Security, CISO, and GRC leadership.

Carl-John Pyne

I help organizations build cybersecurity, GRC, AI governance, and privacy programs that are defensible, pragmatic, and grounded in operational reality, leading cross-functional alignment across legal, technology, and executive stakeholders. I work fluently across mainstream and emerging security frameworks and attestations including NIST CSF, ISO 27001, CMMC and CPCSC, SOC 2, and FedRAMP, with privacy and AI regulatory depth spanning GDPR, PIPEDA, Quebec Law 25, the EU AI Act, and Canada's evolving AI governance landscape.

ISMS Oversight

Oversaw ISO 27001 and NIST CSF aligned programs across multinational, regulated, and public sector environments.

Enterprise GRC Program Development

Built from the ground up at multinational scale: third-party risk management, policy frameworks, and board-level risk reporting.

Enterprise AI Governance

Authored the organization's first enterprise AI Security Policy (2024), with governance foundations for acceptable use, risk assessment, and responsible adoption.

Multi-jurisdictional Privacy Compliance

Enterprise Data Protection Officer accountability spanning GDPR, PIPEDA, and Quebec Law 25.

Security Awareness & AI Literacy

Programs building organizational capacity to recognize risk and adopt AI responsibly.

Team Development & Capability Building

Recruited and developed security and GRC teams with cultures of accountability, growth, and trust.

AI Governance
Artificial Intelligence Governance Professional (AIGP)
Security & IT Governance
Certified Information Security Manager (CISM) Associate Certified Chief Information Security Officer (CCISO) Certified in the Governance of Enterprise IT (CGEIT)
Privacy & Data Protection
Certified Information Privacy Manager (CIPM) Certified Information Privacy Professional/Europe (CIPP/E) Certified Information Privacy Technologist (CIPT) Certified Data Privacy Solutions Engineer (CDPSE)

Open to the right conversation.

Executive roles & advisory engagements  Â·  Remote-first or hybrid  Â·  Canada & US