We provide IT Staff Augmentation Services!

Information Security Business Consultant Resume

3.00/5 (Submit Your Rating)

Senior Security Specialist
Information Security Business Consultant

Accomplished Information Security/Business Continuity Manager and Information Systems Auditor. Over 33 years in Information Technology, with 29 of those years in the Security/Auditing environment. Main experience in CONFIDENTIAL large-scale mainframes, as well as AS/400 systems, RS/6000 systems, Novell networks and Windows NT networks. Strong background in technical systems, audits and security protocols including operating systems (z/OS). Strong background in a variety of security systems, including RACF, CA-ACF2 and CA-Top Secret. Well versed in a number of fourth generation mainframe languages. Strong background in project planning and execution, particularly relating to controls, security, planning, testing and execution. Background in SDLC protocols. Background in Sarbanes-Oxley requirements, FDIC regulations, Comptroller regulations, UK Information Security Act, UK Privacy Act and ISO17799, Role-Based Access Controls (RBAC), and DIACAP/NIACAP analysis and remediation.

Strong verbal and written communication skills, having successfully conducted Security and Disaster Recovery seminars. Published author and speaker on the topics of Information Security, Physical Security IT Audit, Disaster Recovery and Year 2000 issues. Also strong background in technical writing on RACF issues.

CORE COMPETENCIES

  • Insurance, Banking, Financial, Retail, IT and Technology Firms
  • SOX, HIPAA, PCI Regulatory and Best Practice Methodologies, DIACAP/NIACAP
  • Published author and speaker on the topics of Information Security, Physical Security IT Audit, Disaster Recovery and Year 2000 issues
  • Strong background in technical writing on RACF issues, CICS security, z/OS security
  • Mainframe CA Software Installation and Knowledge Transfer

TECHNICAL PROFICIENCIES

  • Software: RACF, CA-ACF2, CA-Top Secret, CA-Cleanup, CA-Auditor, Vanguard Suite, Consul
  • Database: IMS, CICS, DB2
  • Language: COBOL, SQL, Easytrieve, BAL, JCL
  • Utilities: ISPF, TSO, SDSF, PanValet, Librarian, Xpediter, Endevor
  • Platforms: z/OS, VM/VSE, UNIX, Windows XP
  • Networking: TCP/IP, SNMP/E, FTP
  • Tools: CONFIDENTIAL Utilities, VSAM, FileAid, TLMS, Changeman
  • Microsoft: Word, Excel, Access, PowerPoint, Outlook, Project, Visio

TRAINING COURSES/WEBCASTS

  • Transaction Segregation and Security for CONFIDENTIAL-Supplied CICS Transactions, September 2009
    • 2 Webcasts, in conjunction with NewEra Software
  • CICS Command Security, May 2008
    • KOIRUG (Kentucky/Ohio/Indiana RACF User Group) Meeting

WORK HISTORY:

  • Confidential: Senior Security Specialist, Fort Wayne, IN
  • Confidential: Member, Security Advisory Board
  • Confidential: RACF Security Analyst, Lakeland, FL
  • Confidential: Security Consultant (RACF), Tokyo, Japan
  • Confidential: Security Consultant (RACF), Bloomington, IL
  • Confidential: Project Manager SOX Assessment, Southfield, MI
  • Confidential: Sr Security Consultant, Westfield Centre, OH
  • Confidential: Sr Security/Business Continuity Manager, Doha, Qatar
  • Confidential: Sr Info Systems Security Analyst, Riyadh, Saudi Arabia
  • Confidential: Sr Computer Auditor, London, UK
  • Confidential: Sr EDP Auditor, Arlington, VA
  • Confidential: Data Security Administrator / EDP Auditor, Centreville, VA
  • Confidential: Senior EDP Auditor, Alexandria, VA
  • Confidential: EDP Auditor, Fort Wayne, IN
  • Confidential: Computer Operator, Fort Wayne, IN

PROFESSIONAL EXPERIENCE

  • Developed a new security infrastructure to comply with regulatory requirements (SOX, HIPAA, PCI, GLBA, and Banking regulations) and best business practices.
  • Technical project design and direction including development of security task lists, work lists, schedules and assignment, staffing, and execution, security implementation and remediation.
  • Performed an in-depth DIACAP analysis and remediation project for a large insurance concern, completing and clearing 157 issues on the mainframe system ahead of schedule and under budget. Directed the work of three colleagues, generated the DoD-required documentation and evidentiary materials, kept schedules and updates, and communicated with the client and the assessment firm.
  • Development of RBAC Documentation and Implementation for a large insurance concern.
  • Performed detailed analysis of mainframe security settings.
  • Developed detailed audit process for z/OS security
  • Developed detailed remediation process for multiple mainframe system.
  • Developed highly detailed project plan for application testing.
  • Remediation on security issues discovered via RACF assessment
  • Worked on major RACF database clean up and restructuring assignments, the remediation of z/OS security issues outside of RACF, development of operating system-level change control processes, Kerberos implementation and policy development, integration of secured mainframe communications into a Macintosh network.
  • Investigation, installation, and assessment of add-on security auditing products to assist in RACF maintenance and clean-up.
  • Assisted staff in security policy development
  • Provided project management and direction on specific technical projects and assignments including security migration from native CICS/TS to RACF, native DB2 to RACF, native IMS to RACF, etc.
  • Created a shared mainframe knowledge library, z/OS security audits, creation of a segregated mainframe LPAR for security testing, and other technical assignments as requested by management.
  • Investigation of add-on security reporting products to assist in RACF maintenance and clean-up.
  • Development of a standardized RACF region creation structure and procedure for new CICS regions, ensuring adequate transaction segregation and security monitoring
  • Developed comprehensive audit programs for z/OS systems.
  • Development of specific Sarbanes-Oxley audit tests to provide control assurance of several large-scale application systems
  • Created and led the execution of over 400 discrete application tests, covering over 500 control requirements.
  • Assisted with SAS70 assessments for related service supplier
  • Develop a ground floor security project, providing development of Project Plans, complete detailed task lists, high-level policies and detailed job specifications for security project staff.
  • Developed highly detailed project plan for security implementation based on Sarbanes-Oxley, FDIC/Comptroller, ISO17799 and other guidelines. Task list contained over 2100 specific line items.
  • Developed high-level Information Security and Physical Security policy documents
  • Assisted in the development of selection processes and requirements for internal/eternal network penetration/vulnerability testing
  • Created the Security and Business Continuity Department, hiring a staff of 3.
  • Began a security centralization process across over 30 separate computer systems and applications.
  • Prepared emergency contingency/recovery plans prior to the Iraq war, including business recovery site.
  • Performed analysis and administration of OS/390 v2.6 security with RACF v2.6.
  • Performed analysis and administration of upgrade of OS/390 and RACF to v2.8.
  • Developed a wide variety of Information Security Policies, Procedures, Standards and forms on a wide range of subjects, including an Corporate Information Security Policy, Internet, Networks, Data Classification and Ownership, LAN and PC Security, Anti-Virus, Encryption, etc
  • Trained several Saudi IS Security Administrators on the use of RACF, as well as training them on networks, Internet security and other technical subjects
  • Performed audits, control reviews and security/efficiency standards tests on all aspects of the computer environments, including mainframe, LAN/WAN and communications systems
  • Developed a sophisticated audit work paper automation system, which used hypertext to allow for efficient cross-referencing of documents. Allowed for a paper-less audit to be performed.
  • Published an article in February 1997 issue of Computing Magazine included interview with me on Year 2000 and Economic and Monetary Union (EMU) planning.
  • Spoke at Compsec \'94, \'95 and \'96, as well as other smaller conferences, on IT Audit Security and Control issues.
  • Designed and implemented audit programs for examination of technical systems, including in-depth examinations of CA-Top Secret and OS/MVS, as well as Disaster Recovery Planning and Testing.
  • Aided in the development of the EDP Audit function for a multi-billion dollar life insurance firm for U.S. military service personnel

We'd love your feedback!