Director Of Information Security Resume
Cincinnati, OhiO
SUMMARY:
- IT experience as an individual contributor and leadership roles. My current position is establishing a security program at a billion - dollar gross revenue construction company as an IT Security Director.
- The security program includes developing a security program compliant with Confidential requirements.
- Previous IT security experience is using Windows and Linux based systems, tools and development to support PCI compliance requirements for a financial company.
TECHNICAL SKILLS:
Languages: VB, T-SQL, Python, Perl, Bash, Java
Software/Tools: KnowBe4, Proofpoint, End Game, Vectra, DarkTrace, Splunk, Tenable, Nessus, OSSIM, Snort, Suricata, MySQL, Apache, OpenVAS, Wireshark, Metasploit, Kali, IDA
O/S’s: Windows, Linux - Debian, Kubuntu, Ubuntu, Red Hat, CentOS, Fedora
PROFESSIONAL EXPERIENCE:
Confidential, Cincinnati, Ohio
Director of Information Security
Responsibilities:
- Manage a small security team.
- Created initial security policies and procedures.
- Manage security services and vendors.
- Designed security architecture to add NAC, EDR, and network anomaly detection capabilities using Gartner research.
- Managed the implementation of next-generation firewalls, email filtering, and DLP.
- Created a risk assessment and vulnerability remediation process.
- Installed and supported an Alienvault SIEM and Tenable vulnerability management software.
- Evaluated network traffic analysis software using DarkTrace and Vectra.
- Provided oversite for Confidential required processes including Multi-Factor Authentication (MFA), Access Controls, IR planning, and Security Roadmap planning.
- Implementing security software, tools, and controls required for Confidential .
- Manage and implemented security awareness training and phish testing using the KnowBe4 software.
Confidential, Cincinnati, Ohio
Data Security Analyst
Responsibilities:
- Designed an intrusion prevention process (IPS) in 2013 using Python scripting, OSSIM platform, and Cisco Firewall. The IPS process uses Snort events as input and is capable of whitelisting by IP address and Snort SID. The function of the IPS system was made to be similar to the Sourcefire Next-Gen Firewall system.
- Created a vulnerability management process by modifying the source for the open source OSSIM product to use Nessus to run scans and generate a report to feed the data into a ticketing system.
- Programmed an anomaly detection process in 2013 to identify anomalous IP traffic using Python scripting and Netflow data.
- Provided oversite for Websense programs for content filtering and DLP use.
- Run penetration tests for web applications using Kali, HP, and Burp Suite.
- Performed firewall configuration review.
- Performed intrusion analysis using OSSIM SIEM and packet analysis.
- Installed, tested, and proposed a virtual malware analysis process.
- Participated in PCI audit compliance.
- Performed incident response for intrusion and other events.
Confidential, Cincinnati, Ohio
Database Administrator
Responsibilities:
- SQL server administration at client named ‘ Confidential ’.
Confidential, Hebron, Kentucky
Database Administrator
Responsibilities:
- Managed all SQL server administration and SQL development activities.
Confidential, Aurora, Indiana
Small Business Owner
Responsibilities:
- Owned and operated a state licensed automobile dealership.
- Personally set up the business, including all requirements for the license and business operations.
Confidential, New Kensington, Pennsylvania
Confidential Application Developer
Responsibilities:
- Developed and maintained Visual Basic applications.
- Planned, determined specifications, purchased, installed, tested, and implemented servers during a full system upgrade.
Confidential, Cincinnati, Ohio
Database Administrator
Responsibilities:
- Performed daily administrative tasks of installing, backup, restore, monitoring and troubleshooting.
Confidential, Cincinnati, Ohio
Developer / IT Manager
Responsibilities:
- Managed all IT systems in a small financial company.
- Managed and planned a database conversion from Access to SQL Server 7 including VB development.
