Junnelou Climaco

Sr. Director / Director, GRC & Third-Party Risk | Information Security Governance Leader

Director-level risk and governance leader with extensive experience building and scaling enterprise risk, third-party risk management (TPRM), and information security governance programs within highly regulated, global organizations. Combines a foundation in audit and compliance with the ability to translate complex risk data into actionable business insight, enabling faster, more informed decision-making across cross-functional environments. Proven track record leading global programs, multi-million-dollar initiatives, and teams of 30+ while improving risk visibility, operational efficiency, and compliance adoption through automation, data integration, and mergers/acquisitions. Currently positioned for and targeting senior leadership roles where governance, technology, and business strategy intersect to support scalable growth and organizational resilience.

Currently located in Metro New York City. Open to Hybrid, Remote, Travel (Up to 25%).

Bio

Experience

Mar 2024 – Present

Professional Sabbatical

Undertook a planned career pause following sustained leadership progression in global risk and governance roles, focusing on professional development, certification advancement (CISA, AWS Cloud Practitioner, MITxPro AI Strategy in progress), and family priorities.

Mar 2020 – Mar 2024

Director, Third-Party Risk Management

Directed AbbVie’s global third-party risk management program within a highly regulated, multinational environment, aligning risk governance across procurement, legal, privacy, information security, and audit functions.

Mar 2019 – Feb 2020

Director, Risk Management

Led enterprise IT risk management strategy, aligning governance frameworks, regulatory requirements, and control structures across a global organization.

Mar 2017 – Feb 2019

Associate Director, Strategy & Governance

Oversaw governance functions across information security and IT risk, supporting enterprise policy, communication standards, and cross-functional alignment.

Mar 2015 – Feb 2017

Manager, Information Security Office

Built foundational IT and third-party risk assessment programs, establishing governance structures and integrating risk evaluation into enterprise operations.

Results

Global Risk Integration

Directed a $5M post-acquisition program across 30K vendors, completing 5,000+ security and privacy assessments and 8,000+ contract addendums (one year ahead of schedule and $2M under budget).

TPRM Transformation

Converted a manual vendor risk process into a scalable, data-driven lifecycle model, doubling annual evaluations (400 to 800+) and reducing cycle times by two weeks for most vendors.

Risk Data Architecture

Built a centralized risk data environment integrating 5+ enterprise systems, enabling real-time Power BI reporting, and eliminating manual data preparation across the risk and audit workflows.

Expertise

Enterprise Risk Management

Third-Party Risk Management

GRC Strategy

Information Security Governance

Cyber Security

Regulatory Compliance

Internal Controls

Audit & Assurance

Risk Assessments

Policy Development

Continuous Monitoring

Issue Remediation

Risk Reporting

Technology Roadmaps

Project Leadership

Process Automation

Change Management

Cross-Functional Teams

Executive Communication

Operational Improvement

Education

(MBA) Master of Business Administration

Hult International Business School

(BS) Accounting & Economics

Rutgers University

Meet Junn

Testimonials

“Junnelou Climaco is a brilliant, driven, and deeply strategic risk and governance leader. Working with her at AbbVie as another Director in the same department, I have watched her successfully build and scale enterprise risk, TPRM, and infosec governance programs across highly regulated, global organizations.She is a master at translating complex risk data into actionable business insights that drive faster decision-making. Whether leading teams of 30+, managing multi-million-dollar initiatives, or navigating complex M&A, her thoughtful approach ensures both compliance adoption and operational efficiency through modern automation. On top of her outstanding professional capabilities, she is a pleasant, authentic collaborator. Junnelou is built for senior leadership roles where technology and business strategy intersect.”

Julia H., Attorney

“Junn is highly recommended as an exceptional professional who leads with a resilient work ethic, impeccable integrity, and genuine empathy for others. For two years, it has been an honor to report to her in IT third-party risk management (TPRM). Junn approaches her work with a positive attitude, maintaining a can-do mindset that inspires those around her and demonstrating exceptional leadership and analytical thinking on complex projects. Moreover, she proactively ensures the successful completion of projects by guiding collaborative, efficient teams and securing the right resources to deliver effective solutions. I truly believe she would be a valuable asset to any organization facing a challenging project.”

Lorilee Adams, Risk Manager, AbbVie (retired)

“I highly recommend Junn. She is a talented and down-to-earth professional with a strong understanding of third-party risk. She consistently builds strong relationships, is a true team player, and demonstrates excellent leadership in everything she does. She is someone you can trust to deliver and elevate those around her.”

Rohit Malhotra, Director GRC Strategy & Risk Management, AbbVie

Q & A

Why did you choose your profession?

I chose information security because it sits at the intersection of risk, strategy, and technology—areas I’ve always been drawn to, and because it offers no shortage of complex problems to solve, which is something I genuinely enjoy. Coming from internal audit, I saw an opportunity to help build a newly formed function from the ground up and shape how the organization manages risk as it grew. What has kept me in the field is the ability to translate complex technical concepts into clear, actionable insights for stakeholders and drive better business decisions.

Who are your main influences?

I’ve been fortunate to have leaders who invested in my growth and elevated my success. Michael Towers, CISO at Actavis/Allergan, consistently supported me in cross-functional leadership meetings, enabling me to excel in my role. Shawn McGuill, Acting CISO at Allergan, mentored me and became one of my strongest advocates. Trish Pierson, Senior Director of BTS Governance, Risk, and Compliance (GRC) at AbbVie, who provided opportunities that pushed me beyond my comfort zone and accelerated my growth as a leader.

What is your greatest accomplishment?

Lead a $5 million integration project that required integrating Allergan’s third party risk management program into AbbVie’s, as well as evaluating Allergan’s suppliers and providing training and awareness of Allergan employees of AbbVie’s third party risk management policies and processes.

What tools do you use?

Microsoft Office Apps (Excel, PowerPoint, Word, Visio, PowerBI, Outlook, Sharepoint, Forms CoPilot), OneTrust, SecurityScorecard, outsystems, ServiceNow, SAP, ChatGPT, and Claude AI.

What advice would you give to someone just starting in your profession?

Ask for opportunities, volunteer often, and make yourself visible beyond your team.

Interests

Tennis

Softball

Billiards