Summary
Overview
Work History
Education
Skills
Accomplishments
Affiliations
Certification
Interests
Timeline
Additional Information
Work Availability
Generic
Jean Guy Rioux, Jr. CD

Jean Guy Rioux, Jr. CD

IT & Cyber Security Management

Summary

For over eighteen years, I served with various Signal Intelligence and Electronic Warfare units of the Canadian Forces. After early retirement in 1989, I worked as an Intelligence Analyst with EWA-Canada, then as an R&D engineer at Iwatsu Electric and NTT in Japan. I developed the Technogenesis Approach (integrating new technologies into standard communication systems for greater functionality and synergy).

In 1998, I formed NetRational YK, a Management of Technology consultancy focused on creating synergy between European and North American technology researchers, developers, and a wide range of Asian companies. In 2005, I made a move to TÜV Rheinland Japan and Singapore; I managed TÜV’s worldwide Common Criteria for Information Technology Security Evaluation Laboratory (ISO/IEC 15408) and acted as a Senior Auditor for PCI DSS, ISMS standards (the ISO/IEC 27000 series), and Security Management Systems for the Supply Chain standard (ISO/IEC 28000) across Asia, the Middle East, and Africa primarily focused on the financial and shipping/port industries.

Since 2011, I have been consulting mainly with Information Security and Cyber Intelligence Services (Open Source Intelligence – OSINT) internationally. Also, I am a firm believer, and often preach, about Zero Trust architecture, always encrypted data, and Trust No One (TNO) networking, just because it is an ugly world out there, and to remind everyone that security is not for the passive.

Overview

51
51
years of professional experience
5
5
years of post-secondary education
8
8
Certificates
3
3
Languages

Work History

Cyberist

Cyberistix LLC
06.2018 - Current

I am a Cyberist. Best described, a Cyberist is someone with a dynamic career who plays a vital role in the community and broader society protecting information and systems we care about and rely on in our daily lives—in my case, consulting and training people to be proactive with cyber and data security.

Consultant, Info Sec & Cyber Intelligence

Freelance Consultant
07.2011 - 08.2018

Focusing on implementation and maintenance of Enterprise Information Technology Systems, with emphasis on Information Security awareness, training, and internal audit. Also included Cyber Intelligence through seminars or education programs, in addition to development, assessment, and implementation of rule-based auditing, governance capabilities, and risk mitigation. Insightful in implementing and maintaining awareness, training, and second-party auditing of Payment Card Industry Data Security Standard (PCI DSS).

Project management for protecting and securing information systems and resources based on internationally recognized standards. Consult to anticipate and mitigate strategic risks to counter threats that affect mission-critical ICT infrastructure and business continuity through developing, assessing, and implementing rule-based technologies, governance, and standards. I strongly support proven, cost-saving, sustainable, security-relevant Open Source applications and international standards. My areas of operations were the Middle East, Africa, and Asia Pacific for the following matters and companies:

ISO 27001 and PCI implementation consultant to GRC 360 (UK).

InfoSec consultant and trainer to LiquidNexxus (UK)

Common Criteria (ISO/IEC 154080 subject-matter (SME) expert to Innosquared (Germany)

ISO 28000 lead auditor to ERAM International (KSA) and Gucci (Italy)

Japan technologies SME to Coleman Research (HK)

InfoSec and PCI DSS senior consultant to GRC (Thailand).

Information Collection Management System field support (undisclosed, EU)

Security & Risk Management Lead Auditor

TUV Rheinland Singapore
05.2010 - 01.2011

Transferred from Japan to develop and manage AP marketplace for Information Security Management System (ISMS) assessment (auditing) services in financial and banking industry. Responsibilities included assessing compliance as Qualified Security Assessor (QSA) for Payment Card Industry Data Security Standard (PCI DSS) and as Lead Auditor for ISO 27001 (Information Security Management System). In addition, I provide consulting services as subject-matter expert for ISO 38500 (Corporate governance of information technology). Furthermore, I support ISO 28000 (Security management systems for supply chain) audits in South-East Asia region as Lead Auditor and conduct TAPA Freight Security Requirements (FSR) and Truck Security Requirements (TSR) certification service.
Also, provide auditing and consulting services for Business Continuity Management (Singapore Standard 540) and Green Data Centre (SS564); and provide ISO 31000 (Risk Management) consulting services.

Information Security Practice Manager

TUV Rheinland Japan
08.2005 - 05.2010

Managed and operated the Common Criteria Evaluation Laboratory (CCEL – ISO/IEC 15408). Oversaw ICT Security Techniques and Evaluation Consulting Services. I served as Information Security Management System (ISMS) Lead Auditor and PCI DSS Qualified Security Assessor (QSA). I led international Information Assurance projects to research and model ICT risk and security life-cycle principles. Additionally, I established evaluators' skills criteria and training programs and contributed to developing global, regional, and local standards and regulations. I perform ISO 28000 (Security Management Systems for the Supply Chain) audits. Lead Auditor and Senior Consultant for ISO 19092 (Financial services – Biometrics - Security framework), ISO 22307 (Financial services - Privacy impact assessment), ISO 27033-1 (IT - Network security), ISO 27005 (IT - Information Security Risk Management), and ISO 31000 (Risk Management).

Technology Management Consulting Principal & CEO

NetRational YK
01.1998 - 06.2005

Founded ICT consultancy that specialized in assessing, developing, implementing, and managing risks of secured information systems; provided technology and service sourcing, outsourcing services, assisted merging technologies, and developed strategic business and technology alliances and partnerships; provided subject matter expertise and services to European, North American, Japanese and Gulf region firms; and supported business and technology intelligence for multiple firms.
Significant clients: Ayala, EWA, FAST, Fujitsu, Globe Telecom, Hitachi, HSBC, IBM Japan, Infosys, Matsushita, Mitsubishi, Sakura Bank, Sanwa Bank, SEI, Sumitomo Bank.

Technologist, Mobile & Information Systems

Iwatsu Electric Co. Ltd.
08.1990 - 12.1997

Assistant General Manager (Technologist),-International Business (03-1994 to 12-1997): Managed merging of Telecom and computer technologies, initiated cross-industry product alliances and outsourcing, and secured global technology agreements, along with several international business partnerships. In addition, I established Iwatsu's R&D centre in San Jose, California, to maximize alliances with American and Canadian companies and acquire new technologies and software development methodologies with North American universities. Manager-New Business Development (Lead Engineer) (03-1993 to 03-1994):

Organized a 12-members cross functionality team into the New Business Development department; lowered product development's operating costs through better sourcing and commonality usage; improved new product quality through enhanced programming method; and significantly sped new cross-technology ideas to marketplace Team Leader (Lead Engineer),

R&D Wireless Communications Systems (08-1990 to 03-1993):

Developed "Technogenesis Principle" for computer telephony, resulting in two derivative patents for Iwatsu; developed first print-band internal antenna for cellular phone, and worked as Lead Engineer on the first 'follow-me' digital smartphone network Wireless Infra-red Communication System (WICS).

Intelligence Analyst

EWA Canada Ltd.
08.1989 - 08.1990

I worked on various classified Electronic Warfare (EW) and Signal Intelligence (SIGINT) projects in Canada and the United States.

Assisted in the R&D of an Independent Speaker and Language-Recognition System on behalf of North American Security and Law Enforcement agencies for intelligence and commercial applications; SME in developing the Canadian Electronic Warfare Operation Centre.

Signal Intelligence and Electronic Warfare Analyst

Canadian Forces
06.1971 - 08.1989

Served as Signal Intelligence (SIGINT) Analyst and Electronic Warfare (EW) Technologist; developed, deployed, operated, and commanded a broad range of sophisticated SIGINT and EW-related applications and systems on land, air, and sea-born platforms in North America and Western Europe (NATO).

Education

Ph.D. - Organizational Behavior

Wilfrid Laurier University
Canada
08.2001 - 12.2003

Signal Development

CFSCEE
Canada
01.1979 - 01.1980

Communications Research And Signal Intelligence

CFSCEE
Canada
06.1971 - 03.1973

Skills

Active Listening

undefined

Accomplishments

I recently received a Life Member to the Institute of Electrical and Electronics Engineers (IEEE). This is a special honor reserved for individuals who have truly distinguished themselves through their sustained and lasting contribution to IEEE.

Created Now On The Spot (NOT$) where my wife and I select a worthy local organization during our travels to buy and donate needed commodities locally to that organization.

Affiliations

I am a member:

Institute of Electrical and Electronics Engineers (https://www.ieee.org/)

SUPRAD Oldtimers (https://supradoldtimers.ca/)

Radio Amateur of Canada (https://www.rac.ca/)

Malaysian Amateur Radio Transmitters' Society (MARTS) (https://marts.org.my/)

American Radio Relay League (ARRL) (https://www.arrl.org/)

Japan Amateur Radio League (JARL) (日本アマチュア無線連盟) (https://www.jarl.org/)

Certification

Certified Payment-Card Industry Security Auditor (CPISA)

Interests

Amateur Radio (VE2TWT, JH1GRT, OK8CND)

Photography

OSINT

Timeline

Cyberist

Cyberistix LLC
06.2018 - Current

Consultant, Info Sec & Cyber Intelligence

Freelance Consultant
07.2011 - 08.2018

Security & Risk Management Lead Auditor

TUV Rheinland Singapore
05.2010 - 01.2011

Certified Payment-Card Industry Security Auditor (CPISA)

04-2010

ISO 27001 Lead Auditor - Information Security Certification

01-2010

Certified in Risk and Information Systems Control (CRISC)

01-2009

Certified in the Governance of Enterprise IT (CGEIT)

05-2008

Security Management Systems for the Supply Chain Lead Auditor

01-2008

Information Security Practice Manager

TUV Rheinland Japan
08.2005 - 05.2010

Common Criteria (ISO 15408) Auditor

07-2005

Ph.D. - Organizational Behavior

Wilfrid Laurier University
08.2001 - 12.2003

Project Management Professional (PMP) Graphic Project Management Professional (PMP)

02-2000

Technology Management Consulting Principal & CEO

NetRational YK
01.1998 - 06.2005

Technologist, Mobile & Information Systems

Iwatsu Electric Co. Ltd.
08.1990 - 12.1997

Intelligence Analyst

EWA Canada Ltd.
08.1989 - 08.1990

Signal Development

CFSCEE
01.1979 - 01.1980

Advance Amateur Radio Operator (Canada, Japan, Malaysia, Czechia)

07-1974

Signal Intelligence and Electronic Warfare Analyst

Canadian Forces
06.1971 - 08.1989

Communications Research And Signal Intelligence

CFSCEE
06.1971 - 03.1973

Additional Information

Received the Canadian Forces' Decoration (CD) (https://www.canada.ca/en/department-national-defence/services/medals/medals-chart-index/canadian-forces-decoration-cd.html)

and Special Service Medal (SSM) (https://www.canada.ca/en/department-national-defence/services/medals/medals-chart-index/special-service-medal-ssm.html)

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse
Jean Guy Rioux, Jr. CDIT & Cyber Security Management