We provide IT Staff Augmentation Services!

Information Assurance Manager Resume

3.00/5 (Submit Your Rating)

Indianapolis, IN

SUMMARY

  • Federal Government - Achieved teh highest levels of Information Assurance responsibility wifin teh Department of Defense as teh Accrediting Authority, Senior Information Assurance Officer (SIAO) and teh Certifying Authority (CA) for a Confidential agency. Lead civilian guiding teh start up, development and maintenance of teh DIACAP information assurance certification and accreditation program for a new agency wifin teh Confidential . Voting member of DIACAP TAG and eMASS CCB
  • Leadership - Designed, managed security/recovery architectures and administrative staffs from scratch seven different times in teh banking, healthcare and telecommunications industries leading to cost TEMPeffective controls and assuring compliance to company policies, government laws and regulations.
  • Banking - Developed a comprehensive cost TEMPeffective information security program and architecture to ensure confidentiality, integrity and availability of customer information and company intellectual property and to assure compliance wif laws and bank regulations for a major financial holding company ranked among teh top 50 in teh United States wif approximately $11 Billion in assets.
  • Telecommunications - Created and managed a corporate-wide Data Security and Disaster Recovery program encompassing a staff of 24 for a $2.3 billion corporation wif 18,000 employees and 1,500 locations nationwide.
  • Health Care - Managed a hospital corporate data center wif a staff of 11 professionals and reengineered teh facility to assure greater stability, productivity and resiliency for 24/7/365 operations. Developed and managed a security, recovery and privacy program for a two billion dollar national laboratory.
  • Utilities - Wifin 60 days, resolved over 200 outstanding internal audit issues dat had been outstanding up to five years.
  • Health Care - Directed a business applications group of 7 professionals responsible for upgrading, developing and supporting all corporate applications for a 400 bed hospital.
  • Insurance - Chosen as teh first EDP internal auditor and established a baseline of controls corporate-wide for information systems. Resulted in greater stability, integrity and security in teh production environment.
  • Telecommunications - Selected from 1,500 information systems employees to be trained as one of nine certified "Total Quality Management" (TQM) instructors and conducted training classes corporate-wide.

PROFESSIONAL EXPERIENCE

Confidential, Indianapolis, IN

Information Assurance Manager

Responsibilities:

  • Information Assurance Manager (IAM) for two Confidential Defense Logistics Agency (DLA) programs - Electronic Document Access (EDA) and teh Standard Procurement System (SPS).
  • Ensure Confidential Information Assurance Certification and Accreditation Process (DIACAP) compliance of all applicable information assurance controls for assigned systems
  • Maintain full Authority To Operate (ATO) certification and accreditation production status of systems.
  • Annually review and test all DIACAP controls and exercise teh Continuity of Operations (COOP) and Incident Handling Plans.
  • Enforce all Confidential and agency Information Assurance (IA) policies and procedures.
  • Act as primary technical advisor and support for teh assigned scope of responsibility on all IA matters.
  • Provide oversight of all appointed Information Assurance Officers (IAO).
  • Ensure teh proper handling of all computer incidents wifin teh assigned scope of responsibility.
  • Ensure security instructions, guidance and Standard Operating Procedures are prepared, maintained and implemented for assigned systems.
  • Serve as member of all Configuration Control Boards and assess IA risks and impacts of any changes.

Confidential, Indianapolis, IN

Information Technology Specialist

Responsibilities:

  • Deputy Designate Accrediting Authority (DAA) for teh agency. Teh only agency employee authorized to accept information assurance risk. (Note: Acting DAA in final months of agency shutdown.)
  • Senior Information Assurance Officer (SIAO) for teh agency.
  • Certifying Authority (CA) ensuring and validating compliance wif teh Confidential Information Assurance Certification and Accreditation Process (DIACAP).
  • Voting member of teh DIACAP Technical Advisory Group (TAG).
  • Senior advisor to teh agency Designated Accrediting Authority (DAA) in all IT security matters.
  • Responsible for certifying teh majority of teh IT programs wifin teh BTA and for additional IT programs wifin teh Acquisition, Technology and Logistics agency (AT&L).
  • Advise and provide guidance to IT program Information Assurance Managers/Officers (IAM/IAO) concerning security best security practices, weakness mitigation solutions, disaster recovery planning, security of facilities, security architectures, privacy impact analysis,
  • Assure teh identification of all identifiable residual information assurance (IA) risks and brief DAA.
  • Develop BTA IA policies and IA strategies for agency management approval.
  • Key implementer and administrator of teh BTA instance of Enterprise Mission Assurance Support Services (eMASS) - Confidential ’s automated DIACAP system - and voting member of teh eMASS Configuration Control Board (CCB).

Confidential, Indianapolis, IN,

Certification Authority Representative (Systems Engineer)

Responsibilities:

  • Lead Information Assurance Consultant for teh entire Business Transformation Agency (BTA) inventory of 50+ systems directing program management through teh Confidential Information Assurance Certification and Accreditation Process (DIACAP). Providing best security practice and mitigation consulting, compliance validation of information assurance controls, recovery plans facilities, security architectures, privacy impact analysis and teh identification of all residual IA risks. Briefed teh BTA Designated Accrediting Authority (DAA) and, draft BTA IA policies and IA strategies for agency management approval.)
  • Developed required information assurance documentation and guided a $140 million system (DCAS 0 Defense Cash Accountability System) through a rigorous prescribed process to ensure compliance wif teh Confidential Information Technology Security Certification and Accreditation Process (DITSCAP).
  • Designed $1.2 million disaster recovery architecture to support high availability for teh DCAS system.
  • Assumed teh duties of teh DCAS project Information Assurance Officer (IAO).
  • Produced a privacy impact analysis of teh DCAS and ensured compliance wif all federal laws and policies.

Confidential

Senior Vice President Information Security

Responsibilities:

  • Provided onsite information security and privacy risk inspection in six states and 300+ locations.
  • Assured teh development and implementation of global security policies, standards, guidelines and procedures to ensure ongoing information security, privacy and recovery.
  • Managed teh corporate information security architecture.
  • Implemented security architecture improvement plans, developed and sponsored security product purchase proposals, and managed implementation schedules.
  • Interfaced wif regulators, internal and external audit teams on information security matters.
  • Consulted wif corporate management on all information security, privacy and recovery matters.
  • Investigated breaches in information security and assist wif disciplinary and legal matters associated wif such breaches.
  • Provided monthly and quarterly progress reports to teh executive team and teh Audit Committee of teh Board of Directors.

Confidential, NC

Director, Security and Business Continuation Planning

Responsibilities:

  • Created and implemented first comprehensive data security and disaster recovery architectures to support Information Assurance, developed and published data security, disaster recovery policies and standards.
  • Developed and tested directory based security controls for authentication and access control. Implemented web blocking technologies, enhanced network and firewall security, consulted and designed application and database security improvements. Implemented encryption solutions from Entrust PKI and VeriSign authentication to web and FTP solutions, implemented intrusion controls and monitoring.
  • Developed and implemented corporate wide privacy architecture and encryption in support of teh Health Insurance Portability and Accountability Act (HIPAA).
  • Oversaw a reporting System design, implemented and integrated into IBM’s accounting processes to keep Global Systems management informed of budget process.
  • Tracked and reported sales of Global Systems, revenue projections an actual expenses. Provided recommendations on cost saving measures.

Confidential, NC

Supervisor, Information Technology Security Service

Responsibilities:

  • Managed a staff of 9 data processing professionals responsible for development and support of enterprise wide computer security, disaster recovery, application quality assurance, software configuration management and auditing liaisonship for an enterprise consisting of 6,000+ employees.
  • Additional responsibilities included strategic planning for network security, internet security, computer security, disaster recovery.
  • Designed and implemented a corporate wide security monitoring strategy for all operating platforms and Oracle.
  • Managed a staff of 11 data processing professionals responsible for around teh clock operation and support of teh enterprise wide corporate data center which supports 3,500 users. Responsibilities included information security, disaster recovery planning, Help desk, Y2K planning.
  • Managed a group of 7 technical and business professionals to upgrade, develop, and support all corporate applications (Human Resources, Payroll, all Accounting applications, Enterprise wide billing, Patient Management, Executive Information Systems, and Marketing) for a 400 bed hospital.
  • Directed a multi-Million dollar project to completely replace, and greatly enhance teh data integrity of, teh previous billing system.

We'd love your feedback!