# Frank Helm **Business Information Security Officer | CISSP, CRISC, CISA** Frank is a cyber security professional with extensive experience in risk and exception management, threat modeling, and M&A activities. Frank presently serves as a Business Information Security Officer (BISO) at BMO Financial Group where he is the primary Cyber SME for Operations across the bank. Away from the desk, Frank formerly operated an online video game community of >1000 users and presently organizes a bi-weekly running club. He also enjoys both video and tabletop games, and is trying to instill the hacker mindset in two tiny humans. ## Contact - **Email:** [email protected] - **Website:** https://www.BeerMetalPC.com/ - **Location:** Chicago, Illinois, US ## Profiles - **LinkedIn** (/in/FrankHelm): https://www.linkedin.com/in/frankhelm/ - **Credly** (BeerMetalPC): https://www.credly.com/users/beermetalpc/badges - **Bluesky** (@BeerMetalPC.com):https://bsky.app/profile/beermetalpc.com ## Work Experience ### BMO Financial Group — Business Information Security Officer Chicago, IL | https://www.bmo.com/ | *2021-11-01 – Present* BISO supporting BMO's Technology & Operations group. - Supporting many Cyber-led initiatives, with emphasis on identifying business impacts unforeseen by leading area and providing actionable feedback. - Cyber SPOC and trusted advisor for middle and back office Operations orgs within BMO. Reviews and opines on exception requests (e.g. DLP, USB access, blocked email release, etc.), assets with a wide variety of stuck/no-known-process issues, and routes requests to appropriate resources if/when beyond BISO capability. - Provides metrics and reporting to multiple lines of business, including phishing test results and pending access recertifications. ### BMO Financial Group — Information Security Specialist Chicago, IL | https://www.bmo.com/ | *2020-01-01 – 2021-11-01* Cyber M&A Lead and 'Technical ISO.' - Cyber M&A delivery lead for acquisition of Clearpool Group Inc. as well as multiple divestiture and pre-deal due diligence efforts. - Fulfilled 'TISO' responsibilities including project consulting, Vuln/SAST/DAST scan reviews, production data transfer requests, etc. while team transitioned to new threat modeling program. - Performed threat modeling application risk assessments as part of project requirements to a high quality standard under short timeframes. Notably led the bank's first STRIDE threat modeling engagement in support of a major cloud migration project. ### BMO Financial Group — Senior Security Analyst Chicago, IL | https://www.bmo.com/ | *2017-04-20 – 2020-01-01* Cyber M&A Delegate and Senior GRC Analyst. - Cyber M&A delivery delegate for acquisition of KGS-Alpha Capital Markets. - Supported technology-managed application controls testing via process enhancements, UAT, end-user education and support, and RSA Archer data imports. - Continued to perform prior role GLBA/OSFI assessments and other misc. GRC taskings in addition to this new remit. - Recipient of 'Being BMO' award for fiscal year 2019. ### BMO Harris Bank — Information Security Analyst Chicago, IL | https://www.bmo.com/ | *2015-08-01 – 2017-04-20* Junior GRC Analyst, Cyber and Technology Risk. - Provided recommendations for 'PAD' process to avoid regulatory issues that went forward to full implementation. - Delegate to Technology Risk Officers, reviewing tech risk in all projects >$1MM in spend in P&BB, Wealth, and Capital Markets. - Fulfilled multiple compliance functions, including FFIEC controls assessment of web-facing applications, and combination GLBA/OSFI-driven controls assessments of high risk LOBs. ### SolomonEdwardsGroup — Information Security Consultant Chicago, IL | https://solomonedwards.com/ | *2014-12-29 – 2015-04-30* Junior Analyst supporting Cyber Consulting Practice. - Developed sales material and penetration testing playbook based on NIST guidance and open-source Penetration Testing Execution Standard. - Attended employer-sponsored training on X-Ways Forensics Toolkit (v18.1). ### Alliance Computers — Technician Harrisburg, PA | https://alliancecomp.com/ | *2014-05-31 – 2014-08-31* Retail PC sales, customer support, and repair. - Honed problem-solving and customer-facing communication skills. - Operated independently, fulfilling back office repair and front office sales responsibilities; often while solo at a satellite location. - This role satisfied an internship requirement at Harrisburg University of Science and Technology. ## Volunteer ### Blue Team Con — Volunteer, Safety Team Chicago, IL | https://blueteamcon.com/ | *2022-08-26 – Ongoing* Safety team volunteer at Blue Team Con. Safety team provide friendly customer service, while also being responsible for safety of the attendees and adherence to the conference code of conduct. - Worked multiple safety shifts across several Blue Team Con annual events, most notably 2022 and 2026. - Have assisted with teardown, and storage/upkeep during 2022, '23, and '26 events. ### Computer Ministry Inc — Volunteer, General Labor Mechanicsburg, PA | https://missioncentral.org/ | *2008-06-30 – 2012-12-31* Organization operating under the "Mission Central" umbrella, which collected and recycled computers and other electronics. Devices that were still usable were securely wiped of donor's data, refurbished, and distributed to other non-profits. - Worked with Computer Ministry as a volunteer throughout high school and as available during undergrad. - Was an important on-ramp for hands-on work in IT. Provided exposure to full spectrum of consumer and small business grade devices and infrastructure, quickly. ## Education ### Harrisburg University of Science and Technology *Bachelor of Science, Computer Science* 2013-01-01 – 2015-04-30 · GPA: 3.6 ### East Stroudsburg University of Pennsylvania *Undergraduate Studies, Computer Science* 2010-08-01 – 2012-12-31 · GPA: 3.0 ## Certifications | Certification | Abbreviation | Issuer | Date | | --------------------------------------------------- | ------------ | ------ | ---------- | | Certified Information Systems Security Professional | **CISSP** | (ISC)² | 2025-07-16 | | Certified In Risk and Information Systems Control | **CRISC** | ISACA | 2022-08-31 | | Certified Information Systems Auditor | **CISA** | ISACA | 2021-11-30 | | Certified Cloud Security Professional | **CCSP** | (ISC)² | 2020-02-28 | Verification Providers: - Credly — https://www.credly.com/users/beermetalpc/badges/credly - ISACA — https://www.isaca.org/credentialing/verify-a-certification - (ISC)² — https://www.isc2.org/MemberVerification ## Skills - **Soft Skills** — Team first mentality · Embraces complexity · Clear communication - **Risk Management** — 1A LOD · 1B LOD · 2 LOD · ONFR · Emerging Technologies - **Cyber Security** — Cyber GRC · Exception Management · Project Consulting and Pre-Implementation Review · Data Loss Prevention · Awareness/Education - **Knowledge Management** — Documentation · Confluence · SharePoint · Obsidian.md · Mediawiki · Wiki.js · Maps of Content - **Regulatory Compliance** — Gramm-Leach-Bliley Act (GLBA) · NIST CSF · NIST 800-53 · NIST 800-63 · PCI-DSS · ISO 27001 - **Mergers & Acquisitions (M&A)** — Due Diligence · Integration · Divestiture · Program Enhancements - **Threat Modeling** — STRIDE · DREAD · Microsoft Threat Modeling Tool - **Software** — RSA Archer GRC · ServiceNow · SD Elements · MS Office, Visio, Project - **Messaging Administration** — MS Teams · Zoho Mail · Discord · Teamspeak 3 · Slack ## Miscellany - **Sports** — Arsenal ⚽ & Borussia Dortmund ⚽️ - **Homelab** — Ubiquiti Unifi stack (Network, Protect, Drive) · Proxmox VE · Home Assistant · Gravwell · Uptime Kuma · Jellyfin · Commafeed · PiAware - **Running** — 5k · 10k · Meetup Organizer - **Food and Drink** — Beer · Japanese Whisky · Scotch · Smoking · Sous Vide · Canning · Late Night Shawarma - **Tabletop Games** — Pen and Paper RPGs · Resource Management · Deck Builders - **Video Games** — Battletech · DOOM · STALKER · Final Fantasy · Warhammer 40000