We provide IT Staff Augmentation Services!

Information Security Executive Resume

2.00/5 (Submit Your Rating)

Corporation, NY

SUMMARY

  • Seeking a challenging position in a respected company that can use my experience and talent to help drive business goals and strategies forward. A natural leader able to supervise and motivate multifaceted teams to achieve business objectives. I have extensive experience in technology risk management, information security, implemented a wide scale of technologies, managed people; can communicate with C - level executives as well as hands on personnel.
  • Information Systems executive with 20 years of experience, 15 years in Information security and 8 years of Risk management experience.
  • Extensive experience in Enterprise Risk, Governance, Compliance, CyberSecurity, Information Security, Technology Audit, Risk review and Risk Remediation.
  • Extensive experience in Incident management, forensics and large scale active threat mitigation efforts.
  • Expertise in Program, Project and Service delivery management.
  • Expertise in team and program development. Experienced in Client and Vendor management.
  • Experienced in System Architecture, Integration, Engineering, Operations, Virtualization, Capacity Planning, Monitoring, Performance Analysis, System Tuning and Gap analysis.

PROFESSIONAL EXPERIENCE

Confidential, Corporation, NY

Information Security Executive

Responsibilities:

  • Leading CyberSecurity incident investigations and response. Successful detection and remediation of large scale DDOS & APT threats.
  • Engineering and deployment of log management and SIEM service based on Splunk platform.
  • Managing threat intelligence, penetration test and vulnerability management programs.
  • Engineering and management of firewalls, proxy servers, load balancer, DNS, IPS, VPNs, NAC, DLP, endpoint encryption, PKI, enterprise vault and other security infrastructure components.
  • Participated in Identity and Access management process reengineering, user access re-certification, single sign on and SAML federated projects.
  • Participated in Internal and vendor security risk assessment, audit review and GAP remediation.
  • Embedding Information Security in SDLC programs, initiated security training and awareness program.
  • Participated in creating Enterprise Risk Frame work, Risk Registry, Technology Policies, Standards and Infosec governance program.
  • Maturing information security and risk management program to be complaint with ISO 27001/27002, COBIT, SOX, PCI & other industry standards.
  • Security services delivery management and process improvement.
  • Information security program and team development

Confidential, NY

Deputy CSO

Responsibilities:

  • Established Risk management program to address audit findings and to make systems compliant with HIPAA and PCI regulations.
  • Kick started vulnerability management program. This includes establishing the process, issuing security advisory to internal groups, identifying vulnerabilities and tracking remediation.
  • Streamlining Identity and Access management process and periodic user access re-certification for applications and platforms.
  • Kick started Data loss prevention initiatives and re-engineering of Web Security Gateway.
  • Audit of Juniper firewall configuration and intrusion prevention systems and management of those devices.
  • Security logs were consolidated and performed security analytics.
  • Internal application security review and penetration testing of applications using Core Impact.

Confidential, NY

VP, IT Risk Management

Responsibilities:

  • Analyzing heritage security monitoring program, business requirements gathering from various teams, building consensus among various groups, creating necessary business case and project documentation.
  • Short listing of vendors and services available in security monitoring and compliance monitoring space. Participation in RFI and RFP process for this effort, evaluating vendor solutions and making recommendations to the management team.
  • Leading a Technical team for SIM solution selection, architecture, engineering, deployment and support efforts on a global basis.
  • Successful Integration of various infrastructure components and custom applications into SIEM on a global basis, establishing security event baseline and event correlation across various platforms (Mainframe, Midrange, Unix/Linux, Windows, Firewall, IDS, various network and security products, Peregrine, Single Sign-On to name a few)
  • Delivering security monitoring services to meet our service level agreement.
  • Achieving Operational efficiency by automating SIEM monitoring, alert handling and other routine tasks.
  • Implementing various LOB specific compliance reports.
  • Building two internal Security Management Centers to manage security events on a global basis.
  • Established Technology policies, standards and periodic audit for compliance.
  • Internal and Vendor security risk assessment, audit review and GAP remediation.
  • Training and mentoring team members on various security tools and various initiatives.
  • Managed vulnerability assessment and management program on a global basis using ISS and other tools.

Confidential, NY

Information Security Consultant

Responsibilities:

  • Managing Confidential network services such as firewalls (Checkpoint/Cisco Pix/Gauntlet), routers, switches, load balancers, VPN gateways, DNS/BIND and mail gateways on a global basis.
  • Manage and lead perimeter network gap remediation program, which includes network compliancy check, firewall migration, firewalls rule set recertification, firewall log monitoring and IDS deployment (Cisco Secure IDS and Enterasys Dragon) efforts on a global basis to reduce overall IT risk to Confidential . Assisted CSIRT in Computer Security investigations.
  • Established Security baseline for various technology components (Windows, Solaris, Linux, AIX, firewalls, databases, web servers and other applications)
  • Security baseline configuration compliance measurement using Symantec ESM.
  • Engineering, certification, build management and installation of various packages (such as Checkpoint/Gauntlet firewalls, BIND, SSH, Gated, Sudo, SeOS, Stonebeat, Entrust PKI packages and Solaris/ RedHat Linux OS to name a few). Keeping up to date with vendor patches and troubleshooting any issues.
  • Solaris & Red Hat Linux system administration, monitoring and auditing the operating system.
  • Installing and supporting ECN, Market Data, Internet and other vendor services.
  • Manage regional professionals and external security monitoring vendor.
  • Operational support and extensive troubleshooting in large complex environments
  • Product management for firewalls/ids, which includes budgeting, billing, and product offering to various LOBs.
  • Vendor and product life cycle management.

We'd love your feedback!