Online Banking Application Service Provider Resume
0/5 (Submit Your Rating)
CaliforniA
SUMMARY:
- Seasoned Information and Cyber Security Professional and Technical Writer, with extensive experience in PCI, establishing IT Governance, Risk Management, Compliance, Business Continuity and in performing Information Security Assessments and Auditing.
- As Senior Principal Security Consultant I assess and remediate PCI DSS, implement BCP, write security policies and procedures, review the security posture of organizations and advise on enhancements, along with ensuring strict compliance with government regulations such as HIPAA, GLBA, GDRP & FFIEC CAT. Strong communications and presentation skills with Senior and Executive Management.
PROFESSIONAL EXPERIENCE:
Confidential
Responsibilities:
- Project managed the remediation of risks and Audit Findings exposed via Gap Assessments for various Dell SecureWorks corporate clients, using PCI DSS and other Frameworks.
- Advised on the implementation of ISMS that conforms to International Best Practices and established International Frameworks.
Confidential
Information Technology Consulting
Responsibilities:
- Participated in the development of the ISACA/IT Governance Institute, “Enterprise Risk: Identify, Govern and Manage IT Risk”, International Framework for managing Enterprise Risk.
Confidential, California
Online Banking Application Service Provider
Responsibilities:
- Risk Management: Ongoing review of all Security and Operational risks to determine relevance, severity and ownership. Briefed task owners and managers on roles and responsibilities relative to the identification and remediation of security risks. Project management of remediation efforts. Provided monthly status presentations to Senior and Executive Management.
- Risk Assessments: Evaluated levels of risk for findings cited by Regulatory Auditors and Federal Examiners. Assisted with Risk - mitigation vs. Risk-assumption decision-making.
- Compliance: Maintained regulatory compliance posture. Attended FFIEC Examiners’ interviews; distributed Examiners’ findings across resource owners; managed each finding to achieve resolution/mitigation; prepared final management responses.
- Regulatory Audits: Worked closely with Federal FFIEC Regulatory Banking Examiners, SAS 70 and SOX external Auditors.
- Information Security Policies and Awareness: Periodic review of Information Security policies. Developed and deployed content for annual security awareness and testing across the organization.
- Software Development Standards for web application security: Organized and re-published existing software development standards and incorporated into the SDLC. Developed and deployed web application security awareness and testing content targeted to the 150+ software development engineers.
Confidential, Kenilworth, New Jersey
Manager, Collaborative Technologies
Responsibilities:
- Managed a globally-dispersed Collaborative Technologies Suite of application platforms, with responsibility for Information Assurance and Security, along with SOX/HIPAA Review and Remediation. Participated in Regulatory Compliance, Business Continuity Planning/Disaster Recovery Planning. Achieved substantial Customer Service improvement through revamping of SLAs.
- BCP/DRP: Participated as a key member of the Business Continuation Planning/Disaster Recovery Planning Project Team and assisted in the development and testing of a well-structured and coherent Business Continuity Plan and a Disaster Recovery Program to enable quick recovery from a disaster or emergency. Prepared all required documentation and to support the BCP/DRP Plan.
- Improved Disaster Recovery readiness through the design of an Enterprise-Level Backup Strategy for the Collaborative Technology's Global Web-based platforms.
- Responsible for global Pharma roll-out of collaborative web applications ahead of schedule: - Microsoft Project Server and Confidential . Reduced the company's 'time-to-market' by allowing our research scientists around the world to collaborate effectively in real-time.
- Spearheaded Global email migration from cc:Mail to MS Exchange.
- Presented regularly to Senior and Executive Management to gain approvals from Governance Council for RFCs, Budget and Technology solutions aimed at increasing Information Security, efficiency and reducing costs.
Confidential, Parsippany, New Jersey
Project Manager; Network, LAN and Email Administrator
Responsibilities:
- Performed detailed Security review of network access and upgraded security . Project Leader for the implementation of IP Addressing Space, a new ATM LAN Emulation Network, and the provisioning of a new HPUX platform for a database application.