ISO 27001/27002NIST CSFNIST 800-53COBITSOX / Bill 198 / 52-109PCI DSSSOC 2 / SSAE 18ITIL
30+
Years in IT, security & audit
40+
Enterprise clients served
5
Active certifications
7
Regulated sectors
Sectors Served
Trusted by Canadian enterprises in regulated industries
Energy & Pipelines
Oil & Gas
Utilities
Financial Services
Telecommunications
Public Sector & Education
Life Sciences
Practice Areas
Four pillars. One integrated practice.
A senior-led advisory built around how regulated organizations actually buy GRC and cybersecurity — by outcome, not by deliverable.
Pillar 01
GRC Advisory & Governance
Independent advisory to design, mature, and operate enterprise GRC programs — from policy frameworks to board-level reporting.
GRC program design, framework selection (ISO 27001, NIST CSF, COBIT)
Security policy, standards, and process authoring
IT governance structures and steering committee enablement
Board and executive reporting, metrics, and risk dashboards
Program rationalization for established control environments
Pillar 02
Risk Management & Assessments
Threat, vulnerability, and third-party risk assessments grounded in 15+ years of TRA, TPRA, and PPI engagements across regulated sectors.
Threat Risk Assessments (TRA) and Privacy Impact Assessments
Third-Party Risk Assessment (TPRA) programs and execution
Enterprise risk identification, treatment, and reporting
Operational Technology (OT) and IT-OT convergence risk
Risk register design and continuous monitoring strategy
Pillar 03
Compliance & Audit Readiness
SOX, C-SOX (Bill 198 / 52-109), PCI DSS, and SOC 2 readiness from a former PCI QSA and CISA-certified auditor.
SOX, Bill 198 / 52-109 IT compliance program management
IT General Controls (ITGC) design, testing, and remediation
PCI DSS readiness, gap assessment, and assessor liaison
SOC 2 / SSAE 18 / ISAE 3402 control mapping and prep
Internal audit support aligned to IIA professional standards
Pillar 04
Cybersecurity & Virtual CISO
Part-time CISO leadership, security architecture consultation, and AI-enhanced threat and resilience advisory.
Virtual / fractional CISO engagements
Security architecture and cloud / SaaS migration assurance
Disaster Recovery and Business Continuity Planning (DRP/BCP)
Incident, problem, and change management process reviews
AI-driven threat detection and predictive risk modeling advisory
Selected Engagements
Anonymized outcomes from real engagements.
Representative work across energy, financial services, and public sector — all delivered under independent advisory engagements.
Energy · Pipeline
Standing up risk and vulnerability management for a major Canadian pipeline operator
Embedded as cyber security advisor to assist a national pipeline operator establish its risk and vulnerability management programs across IT, Operational Technology (OT), Industrial Control Systems, and SCADA. Performed risk assessments of new and legacy systems and coordinated remediation with engineering and IT teams to close audit findings.
IT-OT ConvergenceRisk AssessmentsOT/SCADA
Outcome
Risk and vulnerability programs operationalized across IT and OT estates.
Energy · Gas Distribution
Three-year engagement as Information Security Systems Officer at a Canadian gas distributor
Delivered cyber security advisory, Threat Risk Assessments on solutions, projects, and programs, third-party risk assessments, and security architecture consultation across a large regulated gas distribution organization.
Hundreds of solution-level TRAs and TPRAs delivered against enterprise risk appetite.
Oil & Gas · Public Company
Long-running IT compliance and security partnership with an upstream operator
Provide ongoing SOX compliance program management, ITGC rationalization, awareness and training on logical and physical security, risk and security metrics, and guidance to management on conducting risk management assessments.
SOX / 52-109ITGCRisk Management
Outcome
Sustained SOX-ready control environment and a rationalized ITGC portfolio.
Public Sector · Education
Disaster Recovery and Business Continuity build for a Canadian school district
Developed Disaster Recovery and Business Continuity Planning artefacts for a large Canadian Catholic school district, aligning recovery objectives with operational and regulatory priorities.
DRP/BCPResilience
Outcome
DRP/BCP program delivered and handed over to internal owners.
Energy · Utility
IT General Controls rationalization for a major Western Canadian utility
Performed a rationalization exercise across the IT General Controls environment, mapping business process controls to general computing controls and applying COBIT, ISO/IEC 27002, and ITIL frameworks.
ITGC RationalizationCOBITISO 27002
Outcome
Streamlined ITGC portfolio with reduced audit burden and clearer control ownership.
Financial Services · Telecom
PCI DSS, SAS70-to-SSAE16, and continuous compliance at a national telecom
Led the IT Services risk management program, emergency management initiatives in support of DRP, and the transition from the SAS70 standard to SSAE16. Consolidated controls across the organization — including PCI DSS — to achieve continuous compliance with policy, regulatory, and legislative requirements.
PCI DSSSAS70 → SSAE16Continuous Compliance
Outcome
Single, consolidated control set supporting PCI, audit, and regulatory obligations.
Credentials & Frameworks
Senior credentials. Framework-fluent advisory.
Engagements are led personally by a senior practitioner holding the principal GRC, audit, security, and privacy certifications — backed by a 30-year career in IT, audit, and security operations.
Former Payment Card Industry Qualified Security Assessor (PCI QSA). Bilingual English / French; working Spanish and Italian.
CISSP
Certified Information Systems Security Professional
(ISC)²
CISA
Certified Information Systems Auditor
ISACA
CRISC
Certified in Risk and Information Systems Control
ISACA
CDPSE
Certified Data Privacy Solutions Engineer
ISACA
ITIL
Foundation Certificate in IT Service Management
AXELOS
PCI QSA
Former Payment Card Industry Qualified Security Assessor
PCI SSC
About the Principal
A career built inside regulated environments.
AG
Angelo Gallo
Principal & Founder, GRCSEC Services Corporation
CISSP, CISA, CRISC, CDPSE, ITIL
Angelo Gallo is a senior IT security, risk, and governance practitioner with over 30 years in the field — including 20+ years in audit, security, and risk advisory across pipelines, utilities, oil & gas, telecommunications, financial services, education, and life sciences.
His engagements emphasize independence, board-level clarity, and audit-ready outcomes — from threat and risk assessments and SOX / 52-109 programs to virtual CISO retainers and OT / IT convergence advisory.
Education
B.Eng. Automated Production — ETS, Université du Québec à Montréal
Languages
English & French (fluent); Spanish & Italian (working)
Career milestones
2017 – Present
GRCSEC Services Corporation
Founder and Principal — GRC, audit, and security advisory to enterprises across Canada.
2023 – Present
Trans Mountain Canada Inc.
Cyber Security Consultant — risk and vulnerability programs across IT, OT, ICS, and SCADA.
2020 – 2023
Enbridge Gas Distribution
Information Security Systems Officer IV — TRAs, TPRAs, and security architecture consultation.
IT audit, risk, security, compliance leadership including the SAS70 → SSAE16 transition and PCI DSS consolidation.
Community
Former Board Director and Chair of the Risk Management Committee at Kids Code Jeunesse — a bilingual Canadian charity for digital and AI literacy education.
Get in touch
Let's discuss your risk & compliance challenges.
Whether you're standing up a GRC program, preparing for audit, or looking for senior virtual CISO support — start with a confidential conversation.