Cybersecurity & AI Governance Executive

Helping organizations govern risk, data, and AI responsibly.

I bring 20+ years of cross-sector leadership in cybersecurity, AI governance, and data protection across financial services, aviation, healthcare, government, and enterprise manufacturing. Fluently bilingual (EN/FR). Board-ready. Available for senior-level roles including Head of Security, CISO, and GRC leadership.

Carl-John Pyne

I help organizations build cybersecurity, GRC, AI governance, and privacy programs that are defensible, pragmatic, and grounded in operational reality, leading cross-functional alignment across legal, technology, and executive stakeholders. Fluent across mainstream and emerging security frameworks including NIST CSF, ISO 27001, CMMC and CPCSC, SOC 2, and FedRAMP, with privacy and AI regulatory depth spanning GDPR, PIPEDA, Quebec Law 25, the EU AI Act, and Canada's evolving AI governance landscape.

ISMS Oversight

ISO 27001 and NIST CSF aligned programs across multinational, regulated, and public sector environments.

Enterprise GRC Program Development

Built from the ground up at multinational scale: third-party risk management, policy frameworks, and board-level risk reporting.

Enterprise AI Governance

Authored a first enterprise AI Security Policy in 2024, with governance foundations for acceptable use, risk assessment, and responsible adoption.

Multi-jurisdictional Privacy Compliance

Enterprise Data Protection Officer accountability spanning GDPR, PIPEDA, and Quebec Law 25.

Security Awareness & AI Literacy

Programs building organizational capacity to recognize risk and adopt AI responsibly.

Team Development & Capability Building

Recruited and developed security and GRC teams with cultures of accountability, growth, and trust.

AI Governance
AIGP
Security Leadership
CISM CCISO CGEIT
Privacy & Data Protection
CIPM CIPP/E CIPT CDPSE

Open to the right conversation.

Executive roles & advisory engagements  Â·  Canada-based  Â·  Remote-first or hybrid  Â·  North America