We provide IT Staff Augmentation Services!

Senior Security Architect Resume

4.00/5 (Submit Your Rating)

SUMMARY:

Senior information professional with extensive experience in design, security, development, project management and deployment of enterprise wide systems in the United States and abroad. Subject matter expert on various regulations that include but is not limited to FISMA, FISCAM, SOX, GLBA and HIPAA. Hands on experience in code review, risk assessment, penetration testing, vulnerability testing multiple versions of Unix, Linux, Oracle, Sybase, SQLServer and Informix.

TECHNICAL SKILLS:

Network: F5, Cisco, TCP/IP, X.25, OSI, ISN, ISDN, PPP, ODBC, LDAP, Kerberos

Internet: Apache, HTML, CGI, DBI, LDAP

Internet Security: Nessus, nmap, SNORT, ZAP, Burp, TripWire, PKI, Root Tool Kits, Cisco, Juniper

Firewall Tool: Kit, RSA, Bluecoat, Firepass, FW, IDS, IPS, HIDS, NIDS, DLP

Database: ORACLE 9.X, 10X, Sybase 10.X, SQL Server 200X, ERWin, Informix, PostGreSQLOperating Systems: Solaris, UNIX, AIX, Linux, DG/UX, HP/UX, Windows 2008, Windows 7

Languages: C, C++, Java, PERL, PHP, sed, AWK

PROFESSIONAL EXPERIENCE:

Senior Security Architect

Confidential

  • Designed the vulnerability assessments for the Data Services Hub of the Federal Health Exchange including policies, scan zones
  • Led the technical team that trouble shoots security and performance problem
  • Cataloged assets and resources in a system
  • Assigned quantifiable value and importance to the resources
  • Identified the vulnerabilities or potential threats to each resource

Security Engineer

Confidential

  • Wrote Unix shell exploit in shell, awk and perl
  • Wrote audit files for nessus to automate linux compliance
  • Cataloging assets and resources in a system
  • Assigning quantifiable value and importance to the resources
  • Identifying the vulnerabilities or potential threats to each resource
  • Mitigating or eliminating the most serious vulnerabilities for the most valuable resources

Security Service Delivery (CISO) Manager

Confidential

  • Wrote an integrity check application for PKI OCSP.
  • Manage, configure and customize various appliances filters including but not limited to Bluecoat, F5 Fires appliance, Cisco, Juniper, IDS, IPS, HIDS, NIDS, RSA, Linux, Unix
  • Provided risk assessment along with penetration testing of several systems. Tools included traceroute, BackTrack, SNORT, NMAP, Nessus, whois, sniffer, etc.
  • Ensure SLA’s are achieved and client expectations are met (or exceeded) according to FISMA.
  • Ensure quality and profitable services are performed to the agreed SLA.
  • Ensure that systems, processes and methodologies as specified are followed to ensure effective monitoring, control and support of service delivery.

Chief Information Security and Enterprise Risk Officer

Confidential

  • Provided IT security for the entire Confidential
  • Successfully supervise both the management and resolution of technical issues in relation to the 2009 Presidential Inauguration.
  • Responsible for the designing, developing and testing the Business Continuity Plan for the Confidential ’s technical communication, involving primary, secondary and tertiary support.
  • Provided security guidelines for the District’s enterprise - architecture.
  • Developed the HIPAA assessment policy and procedures using NIST and MITA
  • Provided risk assessment along with penetration testing and vulnerability testing
  • Provided IT assessment for all government agencies in C&A Certification process which included utilizing the FISMA and ISO 9000 guidelines
  • Provided security audits for Oracle and Sybase installations.
  • Manage several security consultants and developers that were responsible for intrusion detection, policies and procedures.
  • Audited several applications for security compliance. Tools included but were not limited to Java, Oracle, Informix, LDAP, Cisco, SQL Server, Sybase, Oracle, Solaris, Linux, Unix and Windows.

Enterprise Security Manager

Confidential

  • Provided risk assessment along with penetration testing and vulnerability testing to ensure compliance with FISMA and FISCAM
  • Actively served as Security Lead for the ongoing C&A process, worked with FISMA SCAP/NIST 800-26 Self-Assessment Spreadsheet, SCAP/NIACAP/NIST Guidelines, FAA ( Confidential ) disaster recovery/contingency report review.
  • Modified the SCAP/NIST SP 800-18- Guide for Developing Security Plans for Information Technology Systems, SCAP/NIST SP 800-30- Risk Management Guide for Information Technology Systems, SCAP/NIST 800-34-Contingency Planning Guide for Information Technology Systems, and SCAP/NIST SP 800-37, Guidelines for the Security Certification and Accreditation of Federal IT Systems to work with the FAA policies and procedures.

Confidential

Director of Information Security

  • Provided physical and logical designs for Oracle, Sybase and Informix databases using ER/Win.
  • Developed Stored Procedures and Triggers in Oracle and Sybase.
  • Developed the HIPAA assessment policy and procedures using FISMA, NIST and MITA
  • Provided IT assessment for all government agencies in C&A Certification process which included utilizing the FISMA and ISO 9000 guidelines
  • Provide external penetration, internal penetration assessments and security audits.
  • Developed policies and procedures outlining enterprise wide security.
  • Provided risk assessments, penetration testing, vulnerability testing and intrusion detection for a large pharmaceutical firm operating in a heterogeneous environment running Solaris and Windows networked by TCP/IP that led to the cracker being discovered. Tools included but were not limited to SNORT, IDS, IPS, HIDS, NIDS, DLP, Root Tool Kit and NMAP. In addition policies and procedures were refined and developed.

Confidential

Division Director of Data Architecture & Security

  • Managed the Data Architecture Division and later the Digital Solutions Group (joint venture with Intel) which produced the first ecosystem for health systems.
  • Managed the administrative responsibility for a three million dollar budget.
  • Supervised over 25 managers, database administrators, and security specialists that were responsible for all enterprise wide online transactional databases, datawarehouse and information security.
  • Provide external penetration, internal penetration assessments and security audits.
  • Developed policies and procedures outlining enterprise wide security.
  • Designed, developed, and managed a website and infrastructure (redundant CPUs, fiber disk array) used by the enrollment and verification application written in Java using LDAP. Tools included but were not limited to Java, Informix, LDAP, SQL Server, Sybase, Oracle, Solaris and WindowsNT/Windows 2000.
  • Designed, developed and implemented a disaster recovery plan.

Confidential

Database Development Manager

  • Managed seven database administrators for on-line transactional databases.
  • Designed, developed and implemented auditing tools for enterprise wide databases.
  • Web-enabled the data warehouse, which reduced telecommunication costs by 75% and increased sales by 15%.
  • Designed, developed, and implemented a data warehouse over 30 terabytes, which required complete daily reloads.
  • Trained, developed, and managed database administration team using Informix and Redbrick on DEC Alpha clustered hardware.
  • Designed and developed several tools and utilities that included benchmarking, auditing, system resources and concurrency.

Confidential

Director, Internet Services

  • Designed and developed tools for security and administration of websites. Technologies included:
  • UNIX,HTML, AWK, PERL, shell, and SED.
  • Analyzed, developed, and implemented firewalls, mailservers, websites, data gathering systems, and security policy procedures.
  • Engineered a 200 percent increase in Internet project related billings.

Confidential

Senior Technical Architect

  • Designed and managed several projects in the United States and abroad.
  • Managed and redesigned business processes and systems at the World Economic Forum in Geneva, Switzerland. Technologies included: Sybase, UNIX, TCP/IP and Visual Basic.
  • Designed and developed several web sites and the tools for managing websites. Technologies included: UNIX, HTML, AWK, PERL, shell and SED.
  • Increased database performance over 500 times at a major retailer. Technologies were: SQL

We'd love your feedback!