d
douetts

Michel D

@douetts

Technology Risk GRC Specialist

Brazil
Portuguese, English
About me
Technology risk and GRC specialist with 13 years across Big 4 audit, payments and healthcare. At PwC I audited IT controls on 50+ engagements; today I run the ISO 27001, ISO 27701 and PCI DSS certification programme of a payments company; before that I spent 6 years leading privacy and security risk at a large hospital group. I help companies get audit-ready for ISO 27001, SOC 2, PCI DSS, GDPR, CCPA and HIPAA, with documents written for your business, not generic templates.... Read more

Skills

d
douetts
Michel D
Offline • 
Average response time: 1 hour

See my services

Business
I will write a gdpr and ccpa compliant privacy policy for your website or app
IT & Cybersecurity Certification
I will prepare a hipaa security risk analysis and policies for your healthtech

Portfolio

Work experience

ConectCar

Technology Risk Specialist

ConectCar • Full-time

May 2026 - Present • 5 mos

Own the ISO 27001, ISO 27701 and PCI DSS certification programme of a payments company. Secured ISO 27001 recertification with no major non-conformities. Introduced Big 4 process walkthrough testing to map critical processes and control points end to end. Built the business continuity capability from zero (BIA and continuity programme). Run risk assessments and control testing under ISO 31000, NIST CSF and COBIT, and report to the Risk Committee.

Einstein

Privacy & Information Security Risk Specialist

Einstein • Full-time

Feb 2020 - Mar 2026 • 6 yrs 1 mo

Built and led the LGPD compliance programme from the ground up for one of the largest private hospital groups in Latin America (100+ systems, 10,000+ employees), and reviewed and maintained its public privacy policy. Ran risk assessments across the technology estate; the remediation plans I recommended cut security incidents by around 35%. Designed key risk indicators and reported risk directly to the Board. Managed control gap analyses and remediation in RSA Archer and OneTrust. Member of the Privacy Committee.

PwC

Senior Risk & Internal Controls Analyst

PwC • Full-time

Mar 2013 - Feb 2020 • 6 yrs 11 mos

Audited IT general controls on 50+ client engagements across financial services, telecoms, energy, pharma and retail. Supported SOC reporting engagements, designed control matrices under COSO, tracked remediation to closure and presented findings to client management. Progressed from trainee to senior over 7 years.