Cloud Implementation And Security Architect Resume
Boston, MA
SUMMARY:
- Resourceful, results driven information technology (IT) professional with extensive experience in financial sector IT solutions, cloud architecture, and security.
- Hands on experience in planning, delivering, and supporting a broad range of IT solutions in high pressure environments.
- Thrive on continuous challenge with a proven track record of successfully learning and implementing new technology and standards.
- Excellent communication skills with the ability to effectively connect with both technical and non - technical (business) audiences. Can capably work autonomously or as part of a larger team.
TECHNICAL SKILLS
Leadership and Management: Effective team lead with strong capacity for rational and timely decision making. Successfully lead domestic and offshore teams across numerous roles in both direct and matrixed capacities. Ability to foster long term professional relationships and develop talent yielding continuous collaboration benefits.
Relationship Building and Partnerships: Proven history of effectively fostering and leveraging relationships across business and technology teams to achieve business objectives. Work with domestic and offshore resources on a variety of projects to determine requirements and build effective support networks to implement business-critical solutions.
Communication: Effective communicator, with proven ability to bridge language and lexicon gaps, and facilitate collaboration between business and technology teams.
Process Improvement: Continual emphasis on process efficiency. This mindset enables the implementation of business support processes focused on the reduction of operational risk and improved customer support.
Compliance and Governance: Extensive experience supporting audit and compliance process related to business-critical applications. Skilled in review of in-scope data to ensure compliance with appropriate standards.
Adaptability and Flexibility: Proven ability to deliver results in high pressure environments. Strong track record of implementing new technology solutions and ensuring compliance with existing environment and standards.
Technology: Microsoft Solutions (Windows, Server, Office, Teams), Unix/Linux (Solaris/RHEL), Oracle DB, DevSecOps (Bitbucket, Git, Jenkins, Black Duck), Cloud (AWS, Azure), and ServiceNow.
PROFESSIONAL EXPERIENCE:
Confidential, Boston MA
Cloud Implementation and Security Architect
Responsibilities:
- Assisted with technology review and implementation of initial Amazon Web Services (AWS) Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) based public cloud application projects. This included use of AWS EC2, SNS, SQS, Lambda, Aurora DB and Redshift DB solutions.
- Advised project team on hybrid cloud security requirements and technical solutions required to conform to State Street NIST SP800-53 framework-based information security controls.
- Aided project team with open-source component review, CTO sign-off and DevSecOps/CICD implementation using Black Duck SCA tool.
- Led Privacy Impact Assessment (PIA) process for review of in scope business data, in conjunction with business and application teams. This resulted in a data privacy clean bill of health and project signoff from State Street Privacy teams.
- Directed Data Governance effort for project, working with Business Controls unit to ensure that Data Governance role owners were identified and engaged, and that business data was classified appropriately.
- Guided project adherence to State Street information security standards, NIST CSF, SOX, GDPR and other applicable data privacy and regulatory requirements. Collaborated with internal teams to ensure cloud application solutions were engineered to secure in-scope data and comply with all relevant regulatory, security, privacy, and data governance standards.
Confidential
Information Technology Manager
Responsibilities:
- Managed support of the business critical SSGA AWD application and associated infrastructure, handling monthly business transactions totaling upwards of $50B. Ensured consistent environment health and availability via alert-based monitoring tools.
- Implemented AWD data processing and transaction integrity monitoring, and managed transaction error and resolution reporting activities impacting business operations teams. Oversaw data security within application realm.
- Facilitated AWD account provisioning requests via internally developed role-based access provisioning tool. Assisted with account review tasks as part of ongoing security review process and to satisfy audit requests.
- Served as business continuity planning and disaster recovery (BCP/DR) IT team lead for SSGA AWD application, and drove AWD application recovery strategy, engineering, and execution tasks. Managed DR documentation process to handle application recovery tasks at failover sites. Participated in BCP testing, DR planning meetings (structured walkthrough), and full interruption DR test exercises in conjunction with infrastructure and business teams.
- Directed AWD infrastructure patch testing and checkout activities in development (DEV), user acceptance testing (UAT), and production environments.
- Gathered business requirements, coordinated engineering activities, and managed approval, testing, and deployment of AWD software updates in accordance with company defined change and release management processes.
- Collaborated with risk and audit teams to facilitate internal audit activities relating to the AWD application and correct findings. Engaged with the corporate information security (CIS) and risk teams to periodically review and update the AWD information security risk management profile (ISRMP) based on changing company security policies as well as new regulatory requirements.
Confidential
Information Technology Manager
Responsibilities:
- Engineered, maintained, and supported business critical instance of Remedy ticketing application and associated infrastructure for SSGA organization.
- Updated application forms and logic using BMC development tools in accordance with company defined change and release management processes.
- Assisted with Remedy identity and role setup and/management tasks and assisted with account related issues.
- Implemented and administered Remedy based Firecall (elevated privilege) ticket request process for SSGA. Created reports to facilitate management and risk team tracking of Firecall ticket metrics, and worked with risk team to reconcile requests, approvals, and activities.
- Served as BCP/DR IT team lead for SSGA Remedy instance and oversaw application recovery strategy, engineering, and execution tasks. Created DR recovery documentation to handle application recovery tasks at failover sites. Participated in DR planning meetings (structured walkthrough) and full interruption DR test exercises. Assisted with DR related ticket tracking metrics and issue tracking activities.
