Principal Technology Security Specialist - Chief Security Office Resume
0/5 (Submit Your Rating)
SUMMARY:
- Confidential is a former Sr. Principal Technology Security Specialist for Confidential &T reporting to the ( Confidential ) Chief Security Office and is celebrating his twenty - first year of service with Confidential &T Communications.
- Confidential ’s technical and managerial responsibilities has spanned across all ten security domains in his thirty-year IT Technology and Information Security career. He has designed and implemented several security information and cybersecurity programs. products, tools, and solutions to minimize risk and exposure to a diverse number of corporations and business partners such as; Confidential, Confidential, Confidential, Confidential Systems, Confidential and Confidential, including providing security-consulting services for Confidential and a board member of the DHS sector.
- While Confidential as the Senior Security Technical Manager, he managed staff concentration and career path expansion in the Information Security, Operations and Business Continuity domains. He assisted the Confidential directly in establishing Confidential Information Security and Business Continuity programs, including the design, planning and implementation of logical security mainframe, midrange, and handheld access control systems. As the Director of Information Security for Confidential 3PL Confidential Solutions Provider), he managed staff concentration and career path expansion in several security domains and developed their Corporate Information Security and Business Continuity programs, including responsibility for facility security consisting of design and implementation of security access control systems, alarms, walk through metal detectors, surveillance and biometric systems for Corporate headquarters, datacenters, offices and business partner subsidiary facilities, domestically and internationally.
- Confidential joined Confidential in 2000 as the Directory of Information Security and developed an ISP security strategy, to minimize risk and exposure to Confidential and customer information assets. He led a Third-Party extensive security assessment engagement of Confidential ’s ISP Internet accessibility that included penetration testing to critical supporting infrastructure components, to evaluate and improve Confidential ’s Internet security posture where applicable. He shortly thereafter joined Confidential &T Confidential in early 2001 after Confidential &T acquired Confidential . Confidential immediately stepped into the Senior Technical Security Manager role and assumed responsibility for Internet Services, with further expansion that included Confidential, Confidential, Confidential &T Labs, Confidential, and Confidential business partner. In the seven-year period in the Affiliate Manager space, he managed 350+ VPMO and additional projects, both in an out of his immediate realm of responsibility, including SME participation on several Confidential Risk Management Task Force teams.
- In 2009, Confidential ’s responsibility expanded to the Corporate Security Compliance domain and managed both technical and administrative staff concentration with regards to public facing Web Application layer testing for Confidential &T’s portfolio of applications. His team successfully developed a new application compliance testing and review process and is currently being applied to Confidential &T public facing websites, portals, back-end applications, and associated databases using a three-tier application layer approach. Confidential currently reports into the Confidential Supplier Review Team organization and is responsible for third party supplier security compliance audits and reviews. He has held the Computer Systems Security Professional since 1990 and holds additional domestic and international s. Confidential has assisted local and Federal law enforcement agencies on several security investigative and forensic cases and for his efforts, has received several commendations from the Confidential ., Confidential and Homeland Security agencies. He has developed several corporate security patents and in 2010 was appointed to the Executive Advisory Board of Directors of the Confidential Security and Computer Forensics ( Confidential ). He is a Member of the Confidential .
PROFESSIONAL EXPERIENCE:
Confidential
Principal Technology Security Specialist - Chief Security Office
Responsibilities:
- Successfully established Confidential ’s Information Security Program enterprise wide.
- Established “Information Security” processes in the forefront of system, application, product design and development.
- Reduced external public system scans, Spam, virus dissemination and attempted exploits (i.e. 60%) by implementing a proven enterprise security strategy.
- Provided security support Confidential all levels to Confidential ’s Internet Operations team, internal users, and customer community (3.2 million) accounts.
- Formulated and established enterprise-wide computer security policies and data security classification for information ownership assignment including business continuity plans.
- Directed and consulted others in information security related risk, threat, and/or vulnerability analysis.
- Established enterprise wide Corporate Information Security Policies Manual.
- Recommended and implemented network security access controls including Internet/Intranet.
- Implemented MQ, SSH, SSL, PGP, and encryption for Internet transactions through ISP services.
- Developed enterprise wide password algorithm for NT and UNIX platform systems.
- Recommended, implemented, and managed off-site storage of critical data for business continuity.
- Designed, maintained, and administered programs concerning information security automation (e.g. patch compliance, software compliance, UNIX system security controls).
- Developed enterprise-wide business continuity plans for Fortune 100 companies.
- Responsible for hiring/dismissing//scheduling/motivating and supervising technical staff (i.e. 45).
- Established minimum ISP standards for security defense systems (e.g., firewalls, intrusion detection systems, server security systems, single-sign-on, and honeypot solutions using automated system policy enforcement.
- Coordinated internal efforts pertaining to network and system exploits with the FBI in minimizing ISP risk to network and system components.
- Implemented Corporate and Field Location security controls.
- Evaluated and recommended security products and applications to enhance ISP security technology (i.e. SSH, SSL, PGP, MQ, VPN’s, B2B, SecurID and Server Security s).
- Recommended appropriate security design modifications to minimize risk to network applications, systems, and product components (e.g. firewalls, hubs, routers, and switches).
Confidential
Security Architecture - Design - Corporate & Compliance
Responsibilities:
- Employee Awareness Program
- Employee Awareness Booklet (part of new employee orientation) process.
- Evaluated and implemented Network and Host Intrusion Detection Systems.
- Evaluated and recommended Single Sign-On enterprise solution.
- Evaluated, recommended, and implemented automated security vulnerability tools.
- Evaluated, recommended, and implemented automated systems patch solutions.
- Evaluated, recommended, and implemented access control Sever security software.
- Established enterprise computer virus prevention strategy (e-mail, host system) level.
- Established software compliance audit, inventory, and validation process.
- Positioned Information Security in the forefront of application, system, and product design to minimize risk and exposure, prior to production implementation (e.g. Risk Assessment Policy).
- Evaluated, recommended and proposed customer security solutions and products (encryption, e-mail, and server security s) including the use of encryption protocols SSH and SSL.
- Conducted annual system security audits.
- Recommended security software best solution options for systems, applications, and products.
- Managed and directed security staff projects based on company and department goals.
- Investigated and reported external/internal system user abuse and security violations.
- Established company direction and strategy pertaining to system intrusion and compromise handling.
- Assisted Human Resources and Legal departments to establish company added value policies and guidelines.
