We provide IT Staff Augmentation Services!

Security Architect Resume

2.00/5 (Submit Your Rating)

OH

SUMMARY

  • Visualize, implement and oversee long term strategies of Cybersecurity Programs and Infrastructures
  • Manage IT Governance, Risk and Compliance functions (NIST, ISO2700x, COBIT, SOX, ITIL)
  • Develop and implement risk and control assessments - internal, Cloud, and 3rd party
  • Talent acquisition and development, providing goals, performance feedback, & coaching
  • Partner wif lines of business, driving awareness of existing and emerging threats and vulnerabilities
  • Build and lead onsite and distributed diverse teams in a large, multinational environment
  • Provide vision to securely apply IT and Process solutions to achieve business goals
  • Incident & Emergency response team orchestration, action, communication, & post event improvement
  • Excellent presentation skills to communicate complex IT and Security concepts to End User, Executives, & Board
  • Understanding of government regulations, audit compliance reporting, plan and execute remediations
  • Review and audit of provider contracts and SLA’s, and creation of Master Services Agreement
  • Maximize decision analysis methods to evaluate, and implement the latest technologies and techniques
  • Develop procedures for the timely and accurate preservation/production of data for eDiscovery
  • Core Member for Change Management Board, Architecture Review Board, Confidentiality Committee, Emergency Management Team, Corporate Risk Review Committee, Regional SIRT

PROFESSIONAL EXPERIENCE

Confidential OH

Security Architect

Responsibilities:

  • Develop and Launch an information security evaluation process for enterprise projects; developed a complete security evaluation process based on the NIST-CSF framework, wif security scoring metrics for project, from intake to final Executive Risk Acceptance report. Utilized for assessment wif internal development, 3rd party, and cloud applications. Created security assessment survey initially in Excel, then moved to the OneTrust platform. Published SharePoint Web Portal for promotion of the evaluation process. Coordinated wif PMO to implement into SDLC flow.
  • Drive information security risk reduction; Evaluate and score security assessment survey responses, SOC2 reports, and DPIA privacy/GDPR responses. Evaluator and approver in Architecture Review Board for information security. Updated Security Architecture Guidelines, reference architecture, and security tool map. Utilized decision analysis for security product selection, and time collection system replacement.
  • Build secure enterprise projects - security architect for; endpoint protection - USB Control, Next Gen A/V, DLP, encryption; Risk Registry supporting GRC; PAM solutions; CASB; Data Classification, Protection and Compliance solutions; and Proof of Concept labs. Some key projects were - enterprise program for Oracle Cloud peripheral integrations (CEMLI), full Zscaler implementation, and Proofpoint wif Security Awareness Training/Phishing.

Confidential

Cybersecurity Management

Responsibilities:

  • Visualize and promote the 5 year and 10 year security direction; ensured the organization was equipped wif the long-term strategies to prevent, detect, and respond to intrusions, incidents, and unauthorized access, while minimizing user impact. Prepare business case for initiatives. Develop and manage department budget.
  • Governance, risk, and compliance functions, processes, systems, and controls; Audit, test, document and report the control effectiveness in compliance wif SOX requirements, and “Honda Corporate Governance”. Update policies and standards to strengthen controls, if they were deemed to not have the desired effectiveness. Create and track remediation projects for identified deficiencies. Consult wif business unit leadership to identify, manage, promote, and update IT related risks on the corporate risk register. Review Service Now GRC module, to replace current Excel based tracking.
  • Create internal policies, standards and procedures; supporting incident response, compliance and best practices for information security frameworks
  • Expand cybersecurity effectiveness; consulting on global security team wif direct reporting to the North American Director/VP, activities to generate safety and security awareness, simulated phishing, and maximized use of a managed security service to strengthen incident detection and response.
  • Perform internal and external security compliance audit and monitoring activities; internal, 3rd party and cloud security risk assessments, IT control audits, penetration testing and vulnerability scanning wif remediation planning and implementation
  • Lead cybersecurity investigations in tandem wif internal, external, and law enforcement stakeholders; internally, oversaw the Security Incident Response Team in performing root cause analysis, resolution, and reporting to Executives and Board of Directors
  • Source and manage top talent; focused on building a best-in-class information and cybersecurity team, and utilized third party consultancies to identify and install best practices-based systems and policies
  • Serve as a core member of the Confidentiality Committee, joined the Emergency Management Group, and sustained senior-level leadership for Risk, Compliance, Architecture, and Change Committees.
  • Infrastructure, IT Business Management / PMO, Risk & Operations Management (2010-2017): Grew and matured the Ohio-based IT organization to become the IT HQ for R&D in North America. Successfully led teams of Midwest, West Coast, and offshore personnel in supporting sites in the U.S., Canada, and Mexico. Developed and managed the budget of the IT division—consistently achieving wifin 1% of budgetary targets—presenting proposals to executive teams.
  • Drove risk management by proactively identifying, assessing, and mitigating risks across a global footprint of platforms, applications, and 3rd party services. Led client and server security hardening and the promotion of security awareness through education, collaboration, oversight, and performance transparency.
  • Governance, Risk and Compliance; Advanced compliance efforts wif SOX requirements, and “Honda Corporate Governance” - investigate and confirm the global and regional policies/standards, and processes dat support the controls, and test their effectiveness and compliance. Document evidence and result through self-assessment. Led creation of remediation plans/projects for identified deficiencies, and monitor progress to completion. Focus primarily for controls in IT Infrastructure, Access Controls, Development, and Information Security.

Confidential

Infrastructure, IT Business Management

Responsibilities:

  • O365 Global Design directors; member of the 12-person global team—representing 6 regions—optimizing the design, plan, test, and implementation of O365, as transition from Notes, for Global Honda Sales, Manufacturing, & R&D wif 100K+ associates
  • Advanced corporate cybersecurity posture; Delivered improved cybersecurity tools and processes including endpoint protection, firewall/proxy rules, web filtering, DLP, IDS/IPS, and remote access. Supported information security and IP protections for several joint ventures wif heavy R&D, and the IT environments of 3 organizations divesting from R&D.
  • Created and promoted Infrastructure strategic direction; presenting to executives for approval and funding, vendor selection of Infra Projects, including decision analysis matrix, POC, & implementation/support/hardening of hardware and general PC/Server O/S and software; Collaboration (Video Conf, Web Conf, VoIP/cell)
  • Engaged in numerous leadership roles; senior member of Risk, Confidentiality, Compliance, Architecture, and Change Committees, a division member of the Corporate Disaster Recovery and Business Continuity Development Team, and a regional liaison for the creation of Global IT Security Policies.
  • Led and developed a team of 50+ members during a period of rapid growth; optimized IT organization by creating new teams for application development, database administration, business management (division budget, purchasing, PMO), and regional service desk and operations functions, utilized ‘Great Place to Work’ survey to identify potential areas for job satisfaction improvements
  • Negotiated contingent services SOW and MSA for Operations and Service Desk; launched onshore and offshore Managed Service Operations teams to serve 13 IT service areas in the region, improving operational efficiencies and effectiveness through implementation of Notes-based Service Ticket system, later migrating to ServiceNow
  • Reduced hardware and operational expenses—by $5.3M over 3 years; leading the design and implementation team in deploying a Next-Generation Virtual CAD workstation environment
  • Designed and implemented the investigation, litigation hold and eDiscovery processes; managed Security Incident Response Teams, forensic (EnCase) investigations, and electronic hold and eDiscovery of electronically stored information—from identification through production
  • Advanced the IT infrastructure; expanded use of server and client virtualization, WAN/LAN optimization, networked storage, and initial Cloud adoptions, meeting four 9’s uptime target for critical systems
  • Creation of Regional DataCenter: scope, design, build and successful migration of server, WAN/LAN, and storage infrastructure for co-lo wif other Honda companies
  • Led a mission-critical infrastructure project to deploy Lotus Notes as the Regional Lead; drove numerous systems engineering initiatives involving selecting and implementing server, client, storage, and network hardware
  • Minimized security risks through heightened security and risk mitigation awareness, creating standards and procedures to elevate systems performance while achieving security and operational effectiveness
  • Developed and proposed a Security Roadmap wif guidelines for users and technicians, facilitated weekly security audits, recommended opportunities to raise awareness, and managed change control processes
  • Fostered collaborative and communicative relationships wif global stakeholders, working closely wif North America Manufacturing and Sales teams—and local and remote Japan staff—to drive R&D for Lotus Notes application development, fuel the planning processes, and manage implementation lifecycles

We'd love your feedback!