Principal / Consultant Resume
Arlington Va Fort Lauderdale, FL
SUMMARY:
- Information security executive and Confidential with extensive experience delivering defensive information security and proactive protection within highly regulated organizations. Dedicated to developing and leading cutting - edge information security operations that fortify organizations’ IT infrastructures and enhance their security posture.
- Present high-ROI, evidence-based technology investment strategies and transformative process improvements.
- View complex business challenges as opportunities to innovate, collaborate, and overcome perceived limitations.
- Influence team success by creating cultures based on trust, cooperation, and open and honest communication.
- Transformed Confidential ’s CISO organization into a world-class security function, from developing a clear mission and vision to creating new job descriptions and driving enthusiastic adoption of new security protocols.
- Established a continuous PCI-DSS compliance program for Confidential to strengthen compliance while simplifying the onsite audit process and eliminating delays in delivery of the annual report on compliance.
- Built out the infrastructure, SOPs, and culture of operational excellence necessary to both propel and support Confidential ’s rapid growth to $3B+ in annual ecommerce transactions processed.
AREAS OF EXPERTISE:
- Information Security
- Technology Strategy
- Risk Assessments
- Continuity Planning
- Security Team Leadership
- SLA and KPI Development
- Regulatory Compliance
- Process and Policy Design
TECHNICAL SKILLS:
Regulatory Compliance: HIPAA/HiTrust; Sarbanes Oxley; GLBA
Information Security Frameworks: PCI-DSS; ISO27001; CIS Critical Security Controls; NIST
IAAS / Cloud Platforms: AWS; Azure; Digital Ocean; Rackspace
Servers and Databases: Linux; Windows; VMWare / VSphere; MySQL; MSSQL; Apache; IIS; WebLogic
Security Tools: Security Center; Core Impact; Tripwire; Varonis; ArcSight; Splunk
Additional Tools: Perl; C/C++; PHP; Java; Kali Linux; MetaSploit; BackTrack
PROFESSIONAL EXPERIENCE:
Confidential, Arlington, VA & Fort Lauderdale, FL
Principal / Consultant
Responsibilities:
- Provide technology roadmaps against organizational business goals and objectives while assuring technology’s overhead costs provide the greatest value and efficiency possible.
- Provide full enterprise risk assessments, gap analysis and technical solutions to mitigate the organizational risks.
- Help organizations prepare for audits to obtain or maintain compliance for PCI-DSS, HIPAA/HiTrust, ISO27001, SOC 1&2.
- Working with the leadership of companies on a fractional basis to lower the full-time cost of executive leadership roles, CIO / CISO.
Confidential, Washington, DC
Chief Information Security Officer
Responsibilities:
- Partnered with Carnegie Mellon’s Software Engineering Institute’s Maturity Assessor to leverage Confidential (Resiliency Maturity Model) to evaluate the organization and enhance its business resiliency.
- Optimized labor and cost allocations to reduce expenses $1.1M annually and provide extra funding for tools and services to strengthen the organization’s security programs and overall posture.
- Influenced a culture of rigor around vulnerability and patch management. Rolled-out an enterprise-wide program to ensure systems are rapidly updated and configured with latest vendor security patch releases.
- Developed and implemented an enterprise-wide Risk Management Framework across all groups utilizing technology resources, providing a mechanism to track, evaluate, and mitigate security risks.
Deputy Chief of Information Security and Risk Management
Confidential
Responsibilities:
- Led development and implementation of an Identity and Access Management program to protect sensitive data without compromising employees’ and contractors’ ability to work efficiently and effectively.
- Performed a comprehensive security analysis to identify and rapidly address vulnerabilities, develop stronger security policies, and increase Confidential ’s overall security posture.
- Drove adoption of best practices for both transportation and general enterprise information security, including updating IT policies, introducing risk assessments and technical security reviews, and establishing KPIs.
Confidential, Lake Mary, FL
Director of Network Operations
Responsibilities:
- Migrated Confidential to a managed hosting provider, enabling the company to achieve PCI-DSS compliance, meet critical customer SLAs, and securely process e-commerce transactions.
- Transformed software development operations and off-shored foundational QA testing to increase software quality while maximizing resources and adhering to an aggressive development schedule.
Confidential, Orlando, FL
Senior Network Engineer
Responsibilities:
- Provided day-to-day Tier 3 engineering support for all network and server applications.
- Researched and recommended new technologies to streamline operations and enhance security.
- Partnered in designing the most technically advanced working courtroom in the nation at the time, providing the infrastructure to try high-profile cases