We provide IT Staff Augmentation Services!

Security Risk & Compliance Manager Resume

4.00/5 (Submit Your Rating)

PROFESSIONAL EXPERIENCE

Confidential

Security Risk & Compliance Manager

Responsibilities:

  • Oversaw, managed and developed the delivery of strategic, leading edge security and compliance programs while mitigating risks and liabilities to government and commercial IT projects.
  • Responsible for Security on platforms involving cloud systems and applications including AWS, Azure, Google Cloud etc.
  • Developed SecOps strategy aligning Security, IT and DevOps.
  • Provided leadership and overall direction regarding key security and compliance remediation.
  • Reviewed security and privacy aspects of Cloud customer contracts and inquiries.
  • Validated DISA Security Technical Implementation Guides (STIGs), DISA Security Requirements Guides (SRGs) and applied understanding and validation of NIST 800 - 53 Security Controls and overlays to reduce project security risks.
  • Consulted in various industry segments and worked with multiple Project Engineering teams to plan, execute and implement the Risk Management Framework (RMF), Information Assurance (IA) and FedRamp for GovCloud, NERC for ICS/BES Systems, FMI, HIPAA etc.
  • Researched and developed CDN concepts, policies, and strategies.
  • Performed computer security incident response activities.
  • Monitored and analyzed Intrusion Detection Systems (IDS) to identify security issues for remediation.

Confidential

Senior IT Architect

Responsibilities:

  • Managed the development of strategies, multiple and/or sizeable projects and ensured proper support services to meet IT Infrastructure goals and objectives.
  • Hired, Coached, mentored, delegated, and provided technical leadership to administrators, engineers and developers to facilitate their development.
  • Met Confidential Command mission goals, objectives and business needs by using IT methodologies to ensure appropriate solutions were implemented.
  • Maintained “Best Practices” policies/procedures for the technical implementation developed within various enterprises. Developed high-level architectures and design documents to facilitate integration of in-house development projects and/or vendor-based solutions that work within the existing enterprise architecture.
  • Worked with Project, Program Managers and coordinated cross-functional IT departments to resolve issues.

Confidential

Application Development Branch Manager

Responsibilities:

  • Hired and managed developers, administrators, analysts and network engineers necessary to fulfill the K-BOSSS Performance Work Statement (PWS) and applied technologies to assure K-BOSSS services are updated, readily available and met Information Assurance (IA) measures.
  • Delivered services as directed by the Confidential Contracting Office Representative (COR).
  • Gathered departmental system requirements engaged resources and implemented solutions with a clear understanding of the EAM systems.
  • Maintained system updates and met all audit requirements throughout the entire assignment.

Confidential

Senior Systems Architect

Responsibilities:

  • Accountable for the design of full Identity Management Lifecycle IDM, ADFS, Forefront Identity Manager, Oracle Identity Manager and eventually SaaS Cloud connectivity for the State of Florida.
  • Designed and implemented two factor authentications, single sign-on, directory services (AD, LDAP) using best practices.
  • Designed access control policies and implemented robust API access control systems using trust models such as SAML, WS-Trust, Oauth, OpenID, XACML, WS-Federation, etc.
  • Integrated Oracle Identity Cloud Service with WebLogic Server using SAML 2.0.
  • Utilized knowledge of existing Federal/Commercial Trust Frameworks, NIST, HIPPA specification to manage risk, compliance and assurance.
  • Planned and conducted security authorization reviews and audits.

Confidential

Senior Systems Architect

Responsibilities:

  • Lead for the Sales, Service Call Centers (SSC) initiative -- added new call centers, upgraded corporate wide TDM to VOIP to total and selective recording with analytics.
  • Gathered requirements, estimated costs, prepared and presented solution to architecture review boards.
  • Designed architecture for centrally managed multi-site recording using NICE Perform 3.5 application and Avaya 8700 using SIP, DMCC, TSAPI. Managed, coordinated network assets, NOC, vendors, development and implementation, upgrades for the Avaya S8700 systems for call recording analytics, surveys, IVR’s and off premise hosting solutions.
  • Ordered, staged equipment, upgraded, connected and configured systems. Lead department project initiatives involving customizing on-net customer solutions for leveraging newly implemented systems and CTI data.
  • Lead initiative to deploy and administer systems utilizing VMWare ESX 3.5 with Virtual Center Version 2.5 and VDI using VDM Connection Broker ver 2.

We'd love your feedback!