About the firm

André Sanz

Founder & Principal, Sanz Consulting

Leadership

Twenty years inside regulated enterprise technology.

André Sanz has spent more than twenty years inside regulated enterprise technology — most recently as Principal for Technology Risk & Governance at Evernorth Health Services (Cigna), and before that as a Senior Vice President leading technology operations and risk programs at Wells Fargo.

His work sits where cyber risk stops being a scanner output and becomes a management problem: who owns the finding, what it costs to leave open, and how an executive committee sees the answer. He has built enterprise vulnerability governance across estates of more than ten thousand assets, stood up an emergency response function that carried seventeen high-severity zero-day events to on-time closure, and taken HIPAA and SOX control environments through annual audit cycles without a control failure.

He also builds and operates the infrastructure behind his own multi-site platform — one deploy pipeline, one reconciler managing DNS, SSL, and reverse-proxy configuration declaratively across every domain, shared authentication, object storage, and a job scheduler. That operator's discipline — automate the repeatable parts, keep the architecture legible, write down the parts a human still has to decide — is the same one he brings to client work.

Sanz Consulting is an independent practice. Engagements are led personally: no bench of juniors, no markup, and nobody you will never speak to.

Focus

Enterprise Vulnerability ManagementTechnology & Cyber Risk LeadershipAudit & Regulatory Control ResponseZero-Day / Critical Vulnerability ResponseGRC Tooling & SIEM OversightTechnology Governance & Debt ReductionExecutive & Board-Level CommunicationNIST / HIPAA / SOX / PCI-DSS FrameworksCross-Enterprise Program Execution
20+

Years leading technology risk in regulated enterprise

17

High-severity zero-day events driven to on-time closure

10,000+

Assets brought under enterprise vulnerability governance

Zero

Control failures across annual HIPAA and SOX audit cycles

Career

Where the practice comes from.

Twenty years of programs run inside the organizations that carry the obligations this firm advises on.

2023–2026 Evernorth Health Services (Cigna)

Principal — Technology Risk & Governance

Enterprise point of contact for Technology Risk across the Cigna Information Protection organization, Global Infrastructure & Operations, and Audit. Operated within HIPAA and SOX regulatory control environments.

  • Built an enterprise vulnerability governance framework covering 10,000+ assets; reduced mean time to remediate critical findings by 18% within the first 12 months.
  • Established centralized reporting and governance for vulnerabilities, audit issues and technology debt, giving executives visibility into risk posture and remediation performance across four business units.
  • Drove cross-organization accountability, accelerating closure of multiple audit findings and reducing the open critical vulnerability backlog by more than 20%.
  • Partnered with security, infrastructure and audit teams to align with HIPAA and internal SOX controls, achieving zero control failures in annual audit cycles.
2017–2023 Wells Fargo

SVP & Senior Manager — Technology Operations & Risk Programs

Led enterprise technology risk operations and built the firm's Emergency Vulnerability Response function in a heavily regulated financial services environment (SOX, PCI-DSS).

  • Established and led the Emergency Vulnerability Response function — managed 17 high-severity zero-day events with 100% on-time remediation and zero regulatory escalations.
  • Directed enterprise risk and performance reporting for senior leadership, reducing reporting cycle time by 25% through automated dashboards.
  • Oversaw Incident, Problem, Change, Release and Knowledge Management governance for an infrastructure environment supporting over 2,000 customers.
  • Coordinated cross-functional teams of 50+ across technology and security, achieving a 15% year-over-year reduction in critical open vulnerabilities.
2015–2017 GE Capital

Operations Leader — Technology Infrastructure & Vulnerability Risk

  • Led a 24-person operations team supporting 24/7 enterprise Wintel and Unix environments across three data centres.
  • Implemented vulnerability monitoring and remediation oversight, reducing unpatched critical CVEs by 20% within six months.
  • Managed vendor operations and SLA performance across multi-client environments; improved on-time delivery from under 20% to more than 65%.
2013–2015 GE Capital

Service Delivery Manager

  • Ensured performance and availability of critical banking applications supporting $6B in managed assets.
  • Improved SLA performance by roughly 20% through incident recovery process redesign and governance improvements.
2007–2013 GE Capital

Senior Program Manager

  • Delivered enterprise risk-reduction initiatives including disaster recovery readiness for revenue-critical systems serving four or more business lines.
  • Managed 10+ concurrent infrastructure and application releases; reduced release-related incidents by 50% through improved change governance.
2003–2007 Altria Corporate Services

Senior Program Manager / Solutions Architect

  • Delivered global network and data centre initiatives supporting financial systems across five countries; completed the flagship infrastructure program three months ahead of schedule.
  • Implemented shared-services infrastructure reducing operational overhead across global support operations.

Credentials

Frameworks, tooling, and qualifications.

Frameworks & Standards

  • NIST CSF
  • HIPAA
  • SOX
  • PCI-DSS
  • ITIL

Platforms & Tooling

  • Qualys
  • ServiceNow (ITSM & GRC)
  • Splunk
  • Archer
  • Jira

Certifications

  • ITIL Service Manager

Education

  • MBA, Information & Decision Technology Management — Iona College
  • MS, Public Administration — Long Island University
  • BS, Criminology — Long Island University

Tell us what is breaking, what is slow, or what you are afraid to touch.

Every engagement starts with a conversation about outcomes, not hours. If we are not the right fit, we will say so.