We provide IT Staff Augmentation Services!

Director Resume

5.00/5 (Submit Your Rating)

SUMMARY:

  • Senior Cloud Executive with 10+ years of experiences with Confidential and 10 years of Application/Network Security.Experience within the Information Systems/Assurance and Cyber and Cloud Security arena and a total of 20 years of Software and Hardware Systems Engineering coupled
  • Experience with managing cross - matrix teams spanning five countries.

TECHNOLOGIES:

Cloud Technologies: Amazon Web Services (EC2, S3, VPC, IAM, SES, SNS, CloudWatch, CloudFormation, Google Cloud Platform, Azure, VMware, vCloud, Orchestrator, HyperV, IaaS, PaaS, SaaS, private cloud detail design, implementation and deployment, monitoring with SPLUNK and Stackdriver and CloudWatch. Federation with Google, Facebook, and Azure for authentication and web service security,OpenStack, CloudFoundry, OpenShift, IaaS, PaaS, SaaS. UML, Scrum, Agile methodologies,IDE Tools Eclipse, Rational Rose UML.

IDM: SUN IdM v4-v5, SUN DS 5.2, Tivoli Identity Manager 6.1 and Access Manager v3.9-v6.1, WebSEALCA-IdM v8, CA-eTRUST (eWAC) and CA-SSO v8, CA-TopSecret, SailPoint, IdentityIQ and CyberArk

Security: DSML, SAML, SPML, SSL, SSH, SHA, MD5, TLS, L2TP, JAAS, JCE, CAPI.

Protocols: ATM, BGP4, EIGRP, HSRP, LDAP, POP3, MPLS, NCP, NAT, OSPF, SNA, SNMP, SIP and VoIP.

Databases: NOSQL, HBase, Dynamo DB, MariaDB, MySQL, DB2, Oracle, MS-SQL, and Sybase.

Networking: ATM, Ethernet, ISDN, SONET, Gigabit, Wireless, Cable, Optical, Satellite, DWDM Cisco Catalyst Switches 6xxx, 5xxx, 4xxx,29xx, 19xx Routers 7200, 4000, 3600, 3000(VPN), 2600 Configuration, Subnetting; Switching (Layers 1, 2, 3, 4, 7); VLANs, ARP, VPN, RIPv1/2, OSPF, BGP4, MPLS, CIDR, VRRP, HSRP, IP Multicast, IGMPv2, UDP, DHCP, DNS, FTP, NFS, & SMTP..

Enterprise Storage: SAN & NAS design/ EMC (Symmetrix, DMX, CLARIION, Celerra), Brocade, NetApp and F5.

Architecture Frameworks: DoDAF (Formerly C4ISR), FEA, IAM, JTA, TEA, TOGAF, UML, Zachman.

Cryptography: RSA-ACE, ECC, 3DES, IDEA, AES256/1024, QC, SEAL, TEA, SkipJack, Blowfish, Serpent, PRNG.

Military Standards: COMSEC, COMINT, DII, DMS, ELINT, FISINT, IAM, INFOSEC, and SIGINT.

Best Practices: RUP, Six-Sigma, ITIL, CoBIT, OWASP, CIS Top 20, NIST, ISO 27001, SaaS, IaaS, PaaS.

Pen Testing & /Scanning Tools: Nessus, AppScan, Retina, OunceLabs, WebInspect, Burp, Security Content Automation Protocol (SCAP), Open Vulnerability Assessment Language (OVAL), and Common Vulnerability Enumeration (CVE), Common Vulnerability Scoring System (CVSS). LogRhythm, Splunk, and QRadar. Metasploit, Qualys, Matrioux.

PROFESSIONAL EXPERIENCE:

Director

Confidential

Responsibilities:

  • Work with CTO/CISO to establish the design, implementation and integration of AWS Cloud Security Infrastructure.
  • Responsible for establishing the long - term plan to build highly scalable projects in a cross-matrix environment.
  • Work with executive committee to help define the roadmap, budget & project plan. Steered Audit Committee for clients.
  • Establish and sustain AWS standards, process improvements, governance processes and performance metrics to ensure that processes and technology mitigate persistent threats and meet reliability standards to protect client s information assets in AWS.
  • Establish processes for monitoring cybersecurity strategies, policies, compliance controls to meet the client s business needs.
  • Identify Information Security needs and risks, and establish operational plans that align with client s vision, mission and objectives, and support long-term Information Security growth and sustainability.
  • Direct the assessment of business and technology risks to ensure such risks are appropriately identified and evaluated. Oversee the development and implementation of appropriate measures to identify risks associated with applications/business functions.
  • Provide management oversight to all activities related to technology compliance with regulatory as well as audit requirements, ensuring that technology best practices are being followed for Information Security and Disaster Recovery.
  • Define information security controls that support risk assessments and support the secure cloud-based architectures
  • Collaborate with technology architecture teams by performing security analysis of proposed architectures, providing risk assessment feedback, including security requirements.
  • Serve as the Security Lead in the design, implementation and integration phases of cloud-based solutions to meet client and firm security requirements, address enterprise risks and exposures in cloud-based solutions

Sr. Manager/Principal Architect

Confidential

Responsibilities:

  • Support the delivery of AWS offerings related to cloud security, including security governance (security policies and procedures), security strategy (security planning), risk (risk assessments and management), cloud data protection (classification, encryption, and KMS), cloud-based IdM, and technology/provider-specific cloud architecture.
  • Provide architectural leadership on Client’s engineered platforms, tech stacks and infrastructure that power our AWS, vendor and customer facing products and services
  • Connect AWS architecture to business needs of the company by working closely with stakeholders and partners.
  • Build and maintain the current-state and future-state systems architecture views for the enterprise.
  • Deliver various artifacts as part of the enterprise systems architecture, including systems/network/infrastructure diagrams, reference implementations, best practices, and roadmaps.
  • Design and socialize the architectural requirements needed to produce resilient, maintainable, scalable technology.
  • Collaborate with Program Directors across the organization on the details of the systems architecture/road-map.
  • Drive exemplar proofs-of-concept or pilots that leverage AWS technology and establish the path for projects.
  • Establish standards around systems technology stacks and mechanisms for governing cloud-based infrastructure.
  • Assist our security engineering and operations teams to ensure proper monitoring and metrics gathering are being instrumented into our systems and services.
  • Participate on the architecture council to provide governance and build processes to guide critical architectures.
  • Develop, document, and present recommendation proposals, including selection criteria, evaluation, analysis of options, tradeoffs, justifications, and final selections.
  • Design and implement EC2 services with ELB (On-Demand, Reserved Instances, Spot Instances) for global applications deployment utilizing Lambda and EC2 Container Services.
  • Implement the S3 & Glacier service for storage and archiving/backup in excess of 3 PB on Amazon Redshift.
  • Implement CloudFront for content delivery web services to distribute low-latency application in 14 countries.
  • Design highly scalable multiple Databases on Aurora, Oracle, MS-SQL, MariaDB, and DynaoDB with Redshift.
  • Design VPC on Route 53 (DNS Service) for custom Web-enabled Applications spanning 50 custom apps.
  • Manage and support CloudFormation for various Amazon related resources, provisioning and updating them in an orderly and predictable fashion to ensure reliability and availability for mission critical applications.
  • Chaired the Risk/Compliance Committee on Data Protection/Privacy and Regulatory/Compliance matters.
  • Implement AWS TrustedAdvisor to provision resources and improve performance, reliability and security issues.
  • Design AWS IAM for hybrid cloud security to ensure users, groups and permissions comply to security policies.
  • Deploy AWS Directory Service to connect to existing MS-ADFS spanning multiple Forests. Utilized Inspector to assess applications for vulnerability and security threats to on-premise and Cloud resources.
  • Implement AWS MachineLearning tools to detect fraudulent and suspicious financial transactions across multiple applications. This work was in conjunction with IAM utilizing fine-grained attributes and custom code.
  • Design the specifications for AWS MobileHub to add and configure features for apps including user authentication, data storage, back end logic, push notifications, content delivery and analytics.
  • Technical Advisor on Public/Private Cloud solutions from other providers, such as AWS IaaS, Azure etc.,
  • Explicit background in Governance, Policy Development and Enforcement.
  • Authored and Implemented several SOA and Cloud White Papers, Concepts for Emerging Technologies.
  • Designed from Concept to Production, Security Best Practices for specific Web Services and Cloud
  • Lead the growth, development and support junior cloud security resources in cross-matrix client environment.
  • Business development responsibilities around cloud security including origination and client engagements.
  • Translate technical cloud security requirements into business terms for executive stakeholders
  • Design cloud strategy, readiness and discovery assessments, security frameworks, compliance and operations.
  • Design cloud tools, technologies and services (VPC, EC2, EBS, S3, IAM, RDS, SQS, SNS, auto scaling, etc.)
  • Design application architectures, including networks, security models, data storage, data flows, and high availability.
  • Architect solutions for scaling applications, services and databases in a cloud environment

Confidential

Enterprise Security Architect

Responsibilities:

  • Develop the Identity/Access Management (IAM) practice and promote DOD methodologies and standards across Europe for all US Embassies. Lead global TS projects in PKI and IDM to ensure a secure integration with DoDAF, DII, DMS and JTA. Report to Br. General in DoD. Manage 48 Intelligence Officers on TS projects.
  • Initiate and develop the IAM, IDM, INFOSEC, RAMS and COMSEC programs to ensure US Embassy communications and infrastructures are JTA/DII/DMS compliant in Eastern Europe Region.
  • Design and implement military grade RBAC/LDAP infrastructure spanning 11 countries with 1M+ users by consolidating civilian, consular, diplomat, and military officer s credentials with Top Secret/ Classified data.
  • Experience with Enterprise - level provisioning systems (requirements analysis, design, integration, implementation, testing, and production support) with applications, portals, and AD/LDAP directories.
  • Identity Management experience in Single Sign-On, Enterprise Directory Architecture including directory schema, namespace and replication experience with Resource Provisioning, AAA & RBAC.
  • Design a policy and attribute based services to increase replication search/indexing.
  • Design plans for the Gateway, Control and Data Layer components of the LDAP.
  • Support 3M customers by splitting the DB into multi-master to increase performance and reduce failure.
  • Design CoS by groups and roles (managed, filtered, and nested) within LDAP. Consolidate LDAP suppliers and created replica hubs to push data to consumer. Architect Multi-Master Directory Infrastructure.
  • Implementation of Data Access with DSML over HTTP, Filtering, Indexing and Searching, and Replication.
  • Design, build and maintain Identity and Access Manager in the enterprise environment in alignment with the architectural roadmap with a variety of commercial products, custom applications to manage the identity life cycle.
  • Design, develop and document solutions for various IdM platforms (Oracle, IBM, CA)
  • Design a Sun Java System Identity Manager 7.1 full lifecycle implementation.
  • Develop provisioning workflows, physical architecture and design. Resources provisioned to AD, Vaau-RBACx.
  • Create Identity Management process, strategy, best practices and architecture documentation including Access Management, Password Management, LDAP Management, Provisioning, Delegated Administration, and Sponsor Lifecycle Management utilizing RUP and DoDAF Frameworks. Develop Access Management (Single Sign-on) projects (RSA Access Manager/ClearTrust, SiteMinder) workflow/data flow diagrams.
  • Develop identity management strategies, and project plans with - Oracle- OID(Oracle Internet Directory), OVD(Oracle Virtual Directory), OAM(Oracle Access Manager), ORM(Oracle Role Manager),OIM (Oracle Identity Manager).
  • Identity Management familiarity in Single Sign-On, Enterprise Directory Architecture & Design including the directory schema, namespace and replication experience, Resource Provisioning DAC, MAC, & RBAC.
  • Hands on design, implementation, configuration and deployment experience in the Oracle technologies focused on the 11g IdM/OAM platform: Oracle Identity Manager (OIM), Oracle Access Manager (OAM)
  • Knowledge of Oracle Enterprise Manager (OEM), Oracle Internet Directory LDAP (OID), as well all major LDAP directory services (Sun, IBM, Open-LDAP) including Microsoft AD and Oracle Identity Federation (OIF).
  • Coordinate, develop, business/project plan for the relocation of 4 data centers, while supporting the transition network during the relocation to ensure production was not interrupted.
  • Implement & manage multiple projects for 4 data centers, which included voice, data, video networks.
  • Designed new data center for 12 business units over 15 floors at new location using Layer 2/3 Switching.
  • Knowledge of TCP/IP,Switching (VLANs, STP, RSTP, VTP, 802.1x, VCP),Routing(EIGRP, BGP, redistribution, summarization), IP (subnets, CIDR, NAT, ACLs, DNS, DHCP, WINS),VoIP, multicast protocols (PIM, IGMP, CGMP), QoS Cisco IOS, general knowledge around NTP, SNMP, Netflow, CEF, Security Protocols, network management packages: CiscoWorks, NetQoS, QIP. Technical knowledge of T1, T3, MPLS, CWDM and DWDM
  • Architect/design large global enterprises with ATM, TCP/IP, and SONET.
  • Design network security services, network architecture, systems engineering, risk management, policies and procedures.
  • Develop solutions for authentication, authorization, confidentiality, non - repudiation, and security management.
  • Evaluate & Test F5 BIG-IP Network with VIPRION TMOS for Rate Shaping and SSL Acceleration.
  • Perform Site Survey and Protocol Analyzer captures at ten representative sites.
  • Design Public Key Enablement (PKE) of appropriate computer-based applications/ systems supported within the MNF-I/MNC-I so that systems utilize DOD PKI as their method of authenticating access to systems.
  • Implement PKI/PKE architecture that can be operated in accordance with, the current DoD, SIPRNET, INFOSEC, COMSEC and CENTCOM technical guidance and policies, such as the DISA, DoD and DA technical standards and implementation guidance and direction messages, DA 25-1, MNF-I/MNC-I security directives.
  • Analytical abilities to define problem statements identify options and recommend technical courses of action related to development and maintenance of architectural and implementation plans in support of large-scale PKE of enterprise-wide applications and systems.
  • Knowledge in the full integration of PKI/PKE within the current MNF-I/MNC-I environment, and migration strategies for future security initiatives and technologies to enable PKI/PKE technologies with CAC.

We'd love your feedback!