• background image
  • About

    I'm a cybersecurity and cloud security leader with progressive experience across cloud security, vendor and product management, governance, cloud enablement, and platform security.

    My work sits at the intersection of security, risk, governance, and technology -- helping translate complex requirements into practical approaches that support secure cloud adoption and modernization.

    Over the course of my career, I've worked across cybersecurity, business information security, cloud governance, product oversight, financial management and enterprise transformation.

    I bring a business-minded approach to security with a strong focus on collaboration, clarity, and practical solutions that help technology teams move forward securely.

  • Career

    Truist

    Truist, formerly SunTrust | 2019 - Present

    Vice President

    Cloud Operations Reliability Engineering | 2025 - Present

    Cloud Platform Security | Enablement | Governance | Automation

    • Advance cloud platform initiatives across enablement, onboarding, governance, automation, and operational improvement.
    • Partner across security, engineering, architecture, risk, and technology teams to translate cybersecurity requirements into cloud platform solutions.
    • Contribute to automation, data-quality, reliability, resilience, and process-improvement with a cybersecurity and risk-management perspective.

    Cloud Center of Excellence | 2024 - 2025

    Cloud Enablement | Governance | Adoption

    • Advanced cloud enablement and adoption by translating security, governance, and risk requirments into practical guidance for technology teams.
    • Partnered across cloud, architecture, engineering, risk, and business functions to support secure onboarding, modernization, and consistent cloud.

    Governance & Product Management | 2022 - 2024

    Cloud Governance | Security Controls | Compliance

    • Led cloud security governance efforts across controls, standards, policies, compliance, and risk management.
    • Assessed security risk and control effectiveness across cloud-related products, services, and third-party solutions; supported cloud controls, IAM-related compliance, and automation initiatives.

    Vendor & Product Management | 2020 - 2022

    Vendor Security | Product Integration | Risk

    • Managed cloud security governance for vendor solutions, cloud-enabled technologies, and SaaS/API integrations across assessment, procurement, integration, and implementation lifecycles.
    • Evaluated security risk and control effectiveness for cloud-related vendor products and services, while supporting security tooling, automation, and product-integration efforts

    Cloud Security Advisory | 2019 - 2020

    Strategy | Architecture | Risk | Controls

    • Provided cloud security advisory support across strategy, architecture, implementation, and operations, helping align technology decisions with security and risk requirements.
    • Supported security architecture, application security, third-party risk, and emerging-technology assessment, while contributing to policies, controls, and secure cloud adoption.
    Citibank

    Business Information Security Officer | 2017 - 2018

    Assistant Vice President

    • Translated information security requirements into practical business and technical guidance across security architecture, application security, third-party risk, and risk remediation teams.
    • Supported information security risk management, control monitoring, incident response , and senior stakeholders reporting across NIST, ISO 27001, SOX, PCI-DSS, and GDPR-aligned environments.
    Section image

    Information Security Communications & Financial Strategist | 2014 - 2016

    • Managed a $10M+ global cybersecurity budget, including financial analysis, roadmap alignment, and executive reporting.
    • Coordinated cybersecurity initiatives across compliance, audit, IAM, application security, policy, licensing, and internal technology delivery while supporting stakeholder communication and adoption.
    Arthur Rutenberg Homes

    Sales and Marketing Support Coordinator | 2012 - 2014

    • Supported digital modernization, knowledge management, sales enablement, training and customer-facing technology initiatives across a franchise environment.
    Telovations

    Special Projects Manager | 2010 - 2011

    • Managed cross-functional projects across operations, sales & marketing, account support, and process improvement within a telecommunications startup.
    Lovett Miller

    Research Manager | 2000 - 2010

    • Managed research, financial analysis, operations, internal controls, documentation, and stakeholder relationships within a venture capital environment.
  • Core Capabilities

    Cloud Platform Security

    Cloud Enablement

    Cloud Governance

    Security Controls & Compliance

    Cybersecurity Risk Management

    Security Automation

    Vendor & Product Security

    IAM Governance

    Application & API Security

    Data Protection & Privacy

    Technology Risk

    Policy & Standards

  • Download Resume

  • Section image

    I have worked with Gabby for almost a year now and she is an amazing individual who has taken on new responsibilities and role as an Information Security Officer. She is always eager to learn and had picked up complex processes and techniques faster than anyone in recent memory.
    With her help and support we have managed to take action and resolve many past due Information Security (IS) initiatives and metric items, allowing us to trend green on senior management reports. Gabby is an asset to our team and the overall IS program.

    - Daniel Reyes, BISO

    One of the most talented individuals I have ever worked with. Her passion and dedication to her work has made her one the best. She was a key factor in implementing huge project's like Okta and Microsoft 365. Her project management skills are second to none.

    - Chris Pearson, Head of Information & Data Security

  • Awards

    Finalist ­ Oktane Lightning Award (August 2016)

    The Oktane Awards celebrate the organizations and individuals who are taking big steps that enable their teams to worry less about technology, and focus more on innovative ways to drive value for the business. The Oktane Awards recognize inspiring and forward-thinking customers that are achieving ground-breaking results with Okta. The award nomination is a recognition of Walther Ardon and the entire Okta project team for their long hours, days and weekends committed to ensuring the Okta project’s success. The Okta project team members include Walther Ardon, Greg Fisher, Heantee Foo, Michael Theriault, Bryan Bowie, Chris Pearson & Gabriella Nelms.

    Awards Winner and Nominee – T.E.N. ISE Southeast Executive of the Year (March 2016)

    John Graham and the GCIA team won this award in recognition of the outstanding leadership and performance in risk management, data asset protection, regulatory compliance, privacy, and network security.Tech Exec Networks enables relationships and opens channels of communication between technology and security executives to interact with peers, industry visionaries and solutions providers. The company’s offerings include some of the country’s most well-acclaimed executive programs including virtual and traditional executive roundtables, road shows, private executive engagements and leadership recognition programs.

    Finalist and Nominee ­ T.E.N. ISE North America Leadership Summit (November 2015)

    This award recognizes information security executives and their teams who demonstrate outstanding leadership in risk management, data asset protection, regulatory compliance, privacy, and network security. Tech Exec Networks enables relationships and opens channels of communication between technology and security executives to interact with peers, industry visionaries and solutions providers. The company’s offerings include some of the country’s most well-acclaimed executive programs including virtual and traditional executive roundtables, road shows, private executive engagements and leadership recognition programs.

    Winner and Nominee ­ T.E.N. ISE Southeast Project of the Year (March 2015)

    This award recognized GCIA’s Employee Access Ecosystem team (John Graham, Walther Ardon, Greg Fisher, Michael Theriault, Troy Riley, Erik Collasius, and Gabriella Nelms) for their outstanding leadership in risk management, data asset protection, regulatory compliance, privacy, and network security. Jabil’s global customer base is highly competitive regarding intellectual property, cutting edge innovation, and the secrecy surrounding new product launches. Losing this data would result in millions of dollars in contract fines, as well as, major loss of existing and future business. To minimize customer and Jabil risk, Jabil created and adopted a portfolio of security-as-a-service solutions in order to better protect and secure the company’s critical information. The security-as-a-service initiative spanned three areas: application access, data loss prevention and external threats. This project enables Jabil to close security gaps, have an accelerated rapid time to value, leverage its security technology and practices as a market differentiator and create a competitive business advantage in the marketplace.

    Nominee ­ T.E.N. ISE North America Leadership Summit and Awards (November 2014)

    This award recognizes information security executives and their teams who demonstrate outstanding leadership in risk management, data asset protection, regulatory compliance, privacy, and network security. Tech Exec Networks enables relationships and opens channels of communication between technology and security executives to interact with peers, industry visionaries and solutions providers. The company’s offerings include some of the country’s most well-acclaimed executive programs including virtual and traditional executive roundtables, road shows, private executive engagements and leadership recognition programs.

    Nominee – CIO’s Digital Edge 25 Awards (November 2014)

    The Digital Edge 25 Awards honor enterprises that have leveraged the digital technologies of social, mobile, analytics or cloud to transform or innovate in their business by:
    -Focusing on the cross-functional business leadership that drives success.
    -Attesting to the power of digital leadership.
    -Recognizing a select group of digital achievers who have made great strides towards being a digital-centric business.

  • Education & Development

    USF

    AWS Certified Cloud Practitioner

    August 2026

    The AWS Certified Cloud Practitioner validates foundational, high-level understanding of AWS Cloud, services, and terminology. AWS is the largest cloud platform powering enterprise infrastructure, data processing, and modern AI workloads.

    Microsoft Security Compliance

    February 2023

    Earners of the Security, Compliance, and Identity Fundamentals demonstrate a functional understanding of security, compliance, and identity (SCI) across cloud-based and related Microsoft services.

    CCSP

    September 2021

    The Certified Cloud Security Professional (CCSP) is a global credential that represents the highest standard for cloud security expertise. It was co-created by (ISC)² and Cloud Security Alliance (CSA), leading stewards for information security and cloud computing security. The CCSP shows you have the advanced technical skills and knowledge to design, manage and secure data, applications and infrastructure in the cloud using best practices, policies and procedures

    CDSPE

    July 2021

    Certified Data Security Privacy Engineer (CDSPE) is a certification offered by ISACA, a nonprofit, independent association that advocates for professionals involved in information security, assurance, risk management and governance. Modern privacy laws and regulations require organizations to implement privacy by design and by default into IT systems, networks, and applications. To do so, privacy professionals must partner with software developers, system and network engineers, application and database administrators, and project managers to build data privacy and protection measures into new and existing technology environments.

    UCLA Women in Governance

    November 2020

    UCLA 's intensive, experiential program delivers a highly applicable toolkit of leadership skills, governance acumen and networking savvy that will prepare senior women executives, professionals and entrepreneurs to overcome the obstacles and seize the opportunities that they face in seeking corporate board service.

    Azure Fundamentals

    March 2020

    Earners of the Azure Fundamentals certification have demonstrated foundational level knowledge of cloud services and how those services are provided with Microsoft Azure.

    CRISC

    December 2019

    Certified In Risk and Information Systems Control (CRISC) is a certification offered by ISACA, a nonprofit, independent association that advocates for professionals involved in information security, assurance, risk management and governance. ISACA’s Certified in Risk and Information Systems Control certification indicates expertise in identifying and managing enterprise IT risk and implementing and maintaining information systems controls.

    CISM

    March 2018

    Certified Information Security Manager (CISM) is a certification offered by ISACA, a nonprofit, independent association that advocates for professionals involved in information security, assurance, risk management and governance. ISACA’s Certified Information Security Manager certification indicates expertise in information security governance, program development and management, incident management and risk management.

    CISSP

    September 2017

    The Certified Information Systems Security Professional (CISSP) is an objective measure of excellence. It’s the most globally recognized standard of achievement in the industry. And, this cybersecurity certification was the first information security credential to meet the strict conditions of ISO/IEC Standard 17024. The CISSP designation is a globally recognized, vendor-neutral standard at testing to an IT security professional's technical skills and hands-on experience implementing and managing a security program.

    Content Marketing

    December 2016

    Content Marketing Institute is the leading global content marketing education and training organization, teaching enterprise brands how to attract and retain customers through compelling, multi-channel storytelling.

    Marketing Profs

    December 2016

    MarketingProfs is the one source that individual marketers, marketing teams, and some of the world's largest organizations turn to for modern marketing tools, training, strategies, articles, online seminars, discussion forums, and much more.

    University of Maryland

    March 2016

    May 2016

    The University of Maryland is the state's flagship university and one of the nation's preeminent public research universities. A global leader in research, entrepreneurship and innovation, the university is home to more than 37,000 students, 9,000 faculty and staff, and 250 academic programs. Its faculty includes three Nobel laureates, three Pulitzer Prize winners, 47 members of the national academies and scores of Fulbright scholars. The institution has a $1.8 billion operating budget, secures $500 million annually in external research funding and recently completed a $1 billion fundraising campaign.

    ITIL

    December 2015

    ITIL® is the only consistent and comprehensive documentation of best practice for IT Service Management. Used by many hundreds of organizations around the world, a whole ITIL philosophy has grown up around the guidance contained within the ITIL books and the supporting professional qualification scheme.

     

    ITIL consists of a series of books giving guidance on the provision of quality IT services, and on the accommodation and environmental facilities needed to support IT. ITIL has been developed in recognition of organizations' growing dependency on IT and embodies best practices for IT Service Management.

    Tampa SEO

    February 2012

    The Tampa SEO Training Academy is a Licensed Training Associate of the Search Engine Academy and offers participants in Florida access to the premier SEO Training Certification Courses in the industry. Now available are a 2-Day SEO Basics, 3-Day SEO Advanced and a combined 5-Day SEO Mastery Workshop.

    USF

    Master Business Administration ( Finance, MIS, Management)

    August 2003 - December 2007

    USF ranks 50th in the nation for federal expenditures in research and total expenditures in research among all U.S. universities, public or private, according to the National Science Foundation. Serving more than 47,000 students, the USF System has an annual budget of $1.5 billion and an annual economic impact of $3.7 billion. USF is a member of the American Athletic Conference.

     

    Activities: · Graduate Business Association · Kosove Society · National Conference of Community and Justice · Phi Kappa Phi · Beta Gamma Sigma · Hui Na Aikanes o Hawaii · Ka Pa Hula o Kahekili

    USF

    Bachelor of Science (Biology)

    August 1996 - August 2000

    USF ranks 50th in the nation for federal expenditures in research and total expenditures in research among all U.S. universities, public or private, according to the National Science Foundation. Serving more than 47,000 students, the USF System has an annual budget of $1.5 billion and an annual economic impact of $3.7 billion. USF is a member of the American Athletic Conference.

     

    Activities: · Kosove Society · ASIA · Physics Club · Honors Program · Biology Honors Program · Hui Na Aikanes o Hawaii · Ku'u Home o Polynesia · HOSA

  • Contact

    Work + Love = Play.

    I welcome the opportunity to work with great people doing inspiring things.

  • Graphic Design & Digital Marketing Consulting Services

    My Creative Outlet

  • Creative Portfolio

    Gabriella Nelms Portfolio of Work

    I’ve learned that people will forget what you said, people will forget what you did,

    but people will never forget how you made them feel.

    - Maya Angelou