Vice President, Application Security Specialist/information Security Officer Resume
5.00/5 (Submit Your Rating)
Irving, TX
PROFESSIONAL EXPERIENCE:
Confidential, Irving, TX
Vice President, Application Security Specialist/Information Security Officer
- Serve as an Application Security Advisor to Confidential ’s business groups
Confidential, San Antonio, TX
Assistant Vice President, Application Security Team Leader
- Implement and manage the Application Security program at Frost
- Lead and mentor the Application Security team
- In corporate security into all phases of software development (Agile, Waterfall), including Requirements Gathering, Coding/Implementation, Testing, and Deployment/Maintenance
- Chair the application risk assessment committee
- Manage third - party SAST and DAST activities, validate results, oversee risk remediation and mitigation
- Approve/devise remediation plans for vulnerabilities identified in SAST, DAST, and penetration tests
- Devise and communicate application security metrics to stakeholders
- Assist development groups and business owners with understanding application vulnerabilities and remediation options
- Research and manage research of security solutions for existing software architectures
- Research and develop an App Sec training plan for developers and contractors
- Engage with groups throughout the organization to enhance App Sec initiatives
Confidential, Malvern, PA
Information Security Analyst (Application Security)
- Manage security assessments of business applications, working with external consultants when needed
- Conduct manual security testing of external websites
- Participate in architectural reviews of applications
- Communicate results to the application teams
- Generate and communicate quarterly App Sec metrics
Confidential, Columbia, SC
Information Security Intern
- Authored a tool for the analysis of files on Apache Web Server for the presence of any malicious code, supporting both *Nix and Windows environment (Python)
- Authored Report Analysis Engine for Trend Micro Configuration Manager (PostgreSQL, shell script)
- Performed vulnerability scans and compliance checks on Windows & Unix (Nessus)
- Implementation of Windows policy enforcement, malware detection, log monitoring, and integrity checking using Open Source Security (OSSEC)
Research Assistant
Confidential
- Researched - Understanding the human vulnerability to cyber attacks
- Studied the factors that make some humans more vulnerable to computer based attacks
Confidential
Technical Support Executive
- Generated monthly reports for the sale of Windows XP operating systems under the ACP
SKILL:
Secure Software Development: Agile, Waterfall
Application Security: Security Testing, Secure Coding, Secure Design, Security Requirements, OWASP
Scripting: Python, JavaScript, VBScript, shell scripting
Security Tools: Burp Suite, Fortify SCA, HP WebInspect