Systems Administrator Resume Profile
MichigaN
SUMMARY
A Senior Information System Security Professional with extensive experience in the management, design and deployment of business aligned security solutions. Takes pride in developing relationships to create a shared vision of information security that is aligned with business objectives. Comprehensive knowledge of: security standards, frameworks and regulations.
PROFESSIONAL ACCOMPLISHMENTS
Confidential
Risk Analyst
- Perform application, software, and infrastructure risk reviews and evaluate controls
- Review exceptions to policy and standards
- Support Federal Exams and Audit inquiries
- Conduct Third Party Reviews
- Identify corresponding risk and potential vulnerabilities related to numerous applications on various platforms, tools, software, and infrastructure
- Correct or mitigate vulnerabilities in a consulting role
- Review and complete system documentation as needed
Confidential
Security Project Engineer
Lead Technical liaison to the application teams for a major IAM CA SiteMinder project to upgrade more than 1,000 web agents at Chrysler Group. Managing the impact to the application end-users, resolving conflicts with other projects, and scheduling the migrations.
Confidential
Information Security Governance Analyst
- Supported business driven information security governance projects aligned to HIPAA, CMS and HITECH Privacy Laws. Participated in the development of a security framework. Co-author and Instructor for security awareness training
- Project Manager to develop and implement an online security framework attestation solution.
- Developed metrics and reports on compliance to policies and standards.
Confidential
Identity Management Security Architect
- Remote IAM architect for business aligned web authentication solutions using CA SiteMinder to prevent unauthorized access, modification and related security vulnerabilities.
- Provided project subject matter expertise for single sign-on web authentication.
- Architected configurations to address many of the OWASP top ten vulnerabilities.
- Provided first level support for non-production CA SiteMinder web agent installations in the Windows IIS and Linux IHS Apache web server environment.
- Utilized log entries and analysis tools to resolve authentication issues resulting from load balancer, firewall and proxy misconfigurations.
Confidential
Identity Management Security Architect
- Designed and supported secure single sign-on SSO authentication and authorization solutions using CA SiteMinder, Ping Federate, and other solutions for the global Business-to-Dealer and Business-to-Field Office web portals supporting more than 8,000 dealers with more than 500 applications.
- Designed complex SQL configurations to support role-based authorizations.
- Investigated security vulnerabilities and recommended solutions aligned to business objectives.
- Resolved SSL certificate issues, both self-signed and third-party.
- Architected federated authentication to enable secure authentication to cloud-based solutions.
Confidential
Security and Control Engineer
- Managed the operational and physical security of a major IT infrastructure which encompassed more than 140 applications and 192 servers in multiple facilities aligned to ISO 17999 and COBIT.
- Performed application security control assessments for compliance to Sarbanes Oxley, SOX, control requirements.
- Developed and validated Disaster Recovery documentation, successfully executing two annual full recovery tests.
Project Manager
- Managed a project team to design and implement an outsourced web-based data exchange portal using asymmetric key encryption.
- Achieved more than 800,000 in direct annual operational savings and indirect annual savings of over 1million in network charges.
- More than 10,000 users transitioned to the new solution in the first 16 months of deployment.
Supplier Deployment Analyst
- Consultant to the global supplier community on approved methods for secure data management and transport. Co-supervised contract staff and budget development.
- Developed and deployed a supplier assessment program to evaluate the information security controls implemented at proxy data exchange service providers in Confidential
Systems Administrator
- Managed a distributed client-server Computer-Aided-Engineering infrastructure. Maintained the budget, oversaw daily operations and supervised systems operators.
- Improved the infrastructure utilization and the removed outdated hardware over a two year period which reduced annual maintenance costs by more than 200,000.