Derek Lazzaro, JD, CISSP, CIPP/US

Derek lazzaro, jd, cissp, cipp/us

bookmark on deepenrich
location of Derek Lazzaro, JD, CISSP, CIPP/USLos Angeles, California, United States
Followers of Derek Lazzaro, JD, CISSP, CIPP/US2000 followers
  • Timeline

  • About me

    Chief Information Officer | Cybersecurity Leader | City Council Member

  • Education

    • University of southern california

      -
      Doctor of law - jd american/u.s. law/legal studies/jurisprudence
    • Ucla

      -
      Double ba psychology and political science
  • Experience

    • Carpenter research corporation

      Dec 2000 - May 2001
      Technical assistant / intern

      Technical assistant at a DARPA contractor.

    • Newspaper

      Jun 2002 - Jun 2005
      Editorial director/online director
    • Travbuddy llc

      Oct 2006 - Oct 2007
      Vice president

      Vice President for TravBuddy.com, a travel blog website with nearly 1 million registered users.

    • Iverson yoakum papiano & hatch

      May 2008 - Jul 2010
      Associate attorney

      Litigation associate. Drafted complaints, motions, appeals briefs, and other legal documents. Represented clients at various hearings and court appearances. Also served as a legal intern prior to graduation.

    • University of southern california

      Jul 2010 - Aug 2015

      - Managed strategic planning for a $60 million IT budget, including all technical project approvals- Created, hired, and managed the university's Project Management Office (PMO).- Successfully planned and implemented a major departmental review, including title, compensation, and/or KPI changes for nearly 350 employees.- Reviewed and negotiated major contracts for IT infrastructure and services.- Co-led the revision of key IT policies and frameworks, including those for HIPAA, PCI DSS, etc.- Led the communications and customer engagement team for the IT department.- Served on the university's Executive Cyber Risk Committee, reporting to the CFO/Board. Show less

      • Assistant Chief Information Officer

        Dec 2013 - Aug 2015
      • Manager of Academic Initiatives and Counsel

        Jul 2010 - Dec 2013
    • Information sciences institute

      Jan 2016 - Sept 2018
      Chief information officer and facility issm

      - Implemented a full NIST cybersecurity program in 6 months (external audit found 98% compliance with 110 key controls).- Designed and implemented a complete new data center environment supporting A.I. research and other cutting-edge programs.- Designed and implemented a network (WAN and LAN) redesign for the primary facility.- Served as facility Information Systems Security Manager (ISSM) for U.S. Government programs.

    • Lewis brisbois

      May 2018 - Jul 2023
      Chief information officer

      - Successfully led a broad digital transformation, completing 30+ major projects over five years, while leading a team of 65 IT professionals, plus 200 cross-functional staff. - Reduced telecom and other costs by over $3 million by deploying an SD-WAN network and renegotiating key vendor contracts.- Reviewed and optimized the 200-person Records Department, saving $3 million in annual expense.- Created a comprehensive cybersecurity and risk management program and wrote supporting policies, including a third-party vendor risk policy, change management policy, and vulnerability management policy.Major project accomplishments include:- Led conversion from NetDocuments to iManage Cloud, migrating nearly 100 million documents while aligning dozens of data schemas.- Migrated infrastructure and business applications to modern cloud or web applications, including email, identity management, and mail management, enabling hybrid work options.- Led the firm's migration to Zoom Meetings and Zoom Phone, reducing costs, improving user satisfaction, and retaining existing hardware investments.- Implemented a second physical data center, plus an Azure Cloud data center, improving resilience and optimizing data center costs.- Deployed a cybersecurity solution to monitor vulnerabilities as well as threats in real-time.- Co-led the firm's Aderant Expert (ERP) conversion project. Show less

    • Defensive networks (formerly shamrock consulting group)

      Sept 2023 - Apr 2024
      Field chief information security officer

      - Review and reduce IT expenses; ensure IT budget is spent on key business and security goals.- Cybersecurity audit prep (SOC 2, NIST, cyber insurance, etc)- Vulnerability assessment and program management- Third-party and vendor risk management- Review, test, and update Business Continuity and Disaster Recovery plans- Review and update IT and cybersecurity policies- Customized IT consulting and advisory services- Alignment with privacy frameworks including HIPAA, CCPA/CRPA, and more. Show less

    • Nossaman llp

      Apr 2024 - now
      Chief information officer
    • City of palos verdes estates

      Nov 2024 - now
      City council member (elect)
  • Licenses & Certifications

    • Ics402 incident command system overview for executives and senior officials

      California specialized training institute
      Oct 2025
    • Emergency planning, is-235.c

      Fema
      Jan 2025
    • Attorney

      State bar of california
    • Certified information privacy professional - united states (cipp/us)

      Iapp - international association of privacy professionals
    • Incident command system, ics-100.c

      Fema
      Jan 2025
    • Standardized emergency management system sems g606

      California specialized training institute
      Aug 2025
    • Certified information systems security professional (cissp)

      Isc2
      Nov 2023
      View certificate certificate