Manager - Enterprise Security Resume
4.00/5 (Submit Your Rating)
SUMMARY
- Highly organized, innovative, & results - driven professional offering over 25 years of experience in the information technology industry, with emphasis on information security, architecture, engineering & consulting.
- Dedicated leader driving change & transformation, recognized for strategic & proactive management approach in identifying complex solutions, directing & coordinating team efforts toward the attainment of business & operational goals.
- Known for thought leadership, expertise in managing overall aspects of information security functions including strategy planning & implementation, policy development & execution, & objective conceptualization leveraging People, Process & Technology.
- Managing & driving Enterprise IT Security Portfolio, Architecture & Engineering, Operations, Security & Threat Intelligence, Event & Incident Response, Governance, Risk & Compliance, Policies & Standards. Armed with excellent oral & written communication skills; with strong interpersonal, problem-solving, & critical thinking aptitudes.
- Effective at collaborating & establishing positive working relationships with clients, key leaderships, stakeholders, & upper management, partners & vendors within global & local Fortune 500 companies.
PROFESSIONAL EXPERIENCE
Confidential
Manager - Enterprise Security
Responsibilities:
- Provide leadership & direction to overall aspects of global security practice, services, & operations while managing security architecture & engineering. Provide supervision, guidance, mentoring, & coaching to security team.
- Build & drive enterprise security practice, deliver business value, design & implement security solutions. Provide leadership, enterprise vision, strategy, direction, roadmap, guidance, service framework & support to the organization.
- Propose & lead IT change & transformation efforts & processes, continuous growth & maturity, development of business cases, CBA, total cost of ownership (TCO), & return on investment (ROI) to drive company change.
- Perform business unit planning for budgets, resources, security program & projects, key goals & objectives
- Hold responsibility in deploying security services, support, operations, & business services delivery models for security tools, cloud technologies, network, infrastructure, data & application security, risk & vulnerability management, identity & access management, Global Security Operations Center (GSOC), EDR, incident response, & forensics.
- Contribute in DevOps efforts, secure SDLC & establish business direction, objectives, projects & programs. Drive Enterprise Architecture & Design Reviews. Drive defense-in-depth strategy for cyber security & privacy.
- Build Enterprise Security Practice & Team responsible for 24/7 services & security operations, SLAs, Metrics, & Reports
- Create & lead security information & event management (SIEM) & GSOC functions, correlation rules, artificial intelligence, business use cases, playbooks, log source integration, cybersecurity, threat intelligence, evidence collection, incident response, network security, vulnerability management, IAM practice, security testing, application & infrastructure scans, & tools for EDR, cloud, data (at-rest & in-motion, PII, PHI, PCI & business critical, sensitive data etc.) & application security, & endpoint security.
- Overseeing various key functions which include:
- Global security incidents, offenses & events of interest, triage, threats & mitigation, VM Scans, vulnerabilities & risk management, Prioritization, Remediation, incident response management, APTs, DDOS attacks, Malicious Payloads, Virus, & Malware, IAM solutions, SSO, user access controls, privileged user accounts etc.
- Security services engagement with local/offshore partners; set business priorities, delegation of tasks/activities;
- Governance, risk & compliance (GRC) & audit requirements, process, controls, review, analysis, & updates;
- Enterprise Security & Network Architecture & Design, Perimeter Security, Firewalls, Rules Management, Intrusion Analysis & Prevention, SSL Decryption, URL Filtering, WildFire & Malware Analysis & Management, Global Protect, Mobile & VPN Security, Network Changes, Upgrades, Migrations, & Consolidations
- Enterprise security portfolio budgets & resources planning, forecasting, projects, & programs;
- Tools & technologies which involve product lifecycle management, upgrades, patch management, migrations, consolidations, portfolio rationalization, onboarding new tools, & new services development; &
- Business Communications, Resource Planning & Management, Skills & Competency Development, Training & Development, Business Services Delivery, Project & Program Management, Collaboration & Partnership with IT Infrastructure, Technology, Applications & Business Teams, Stakeholders, Executive Management;
- Design & enforce organizational security policies, standards (PCI DSS, SOX, NIST, CIS, SANS, ISO 2700x, HIPPA, & GDPR etc.) & controls, processes & procedures, work in-take process, execution models, process improvement, reports, & knowledge base. Manage Risk, Compliance & Audit issues, Problem, Change & Release Management.
Confidential
Senior Enterprise Architect
Responsibilities:
- Worked with IT & business leadership while driving enterprise’s IT strategy & architecture & engineering initiatives for security & privacy, Infrastructure, application & data, cloud & mobile computing, IAM solutions & services, SSO/FSSO.
- Spearheaded initiatives in reducing cost & complexity, optimizing IT infrastructure & resources, & identifying key areas for quality improvement. Perform current state & target state analysis. Lead, drive & guide business units.
- Established plans for financial & business goals, budgets, resources, service improvement programs, & IT & security transformation to build an efficient IT organization.
- Solely supervised new & existing business capabilities, processes, & services, risk & gap analysis.
- Provided leadership, direction, guidance, solutions in alignment with the overall architecture & engineering strategy.
- Displayed competency in successfully managing the following:
- Major & complex enterprise global & local projects for business, technology roadmaps, IT operations, security & privacy, governance, risk & compliance, enterprise security policy, standards, process & procedures;
- Enterprise security risk appetite, residual & inherent risk, posture, risk/threat assessment & mitigations, audits, & awareness programs, & management of enterprise security for network, application & data, IAM, SAP, cloud etc.
- Infrastructure foundations for servers, storage, network, data, & applications to analyze & recommend improvements on IT projects & processes in native, cloud & mobile models.
- Coordinated with leadership & business owners to contribute to the conceptualization & implementation of enterprise architecture communication plans, business initiatives, risk management, DR/BCP,
- Organized datacenter consolidation & migration as well as developed service catalogs for provision, virtualization, scalability, flexibility, adaptability, security, network, storage, replication, service management, service level agreements (SLA), monitoring, & reporting.
- Managed enterprise business capabilities in cloud & mobile computing technology/services with private & public cloud, master data management (MDM), master data services (MDS), BYOD, & mobile applications development.
