We provide IT Staff Augmentation Services!

Information Assurance Officer Resume Profile

3.00/5 (Submit Your Rating)

OBJECTIVE:

Desire a security, audit, and/or compliance position with a top firm that would utilize my security knowledge, risk management skills and technical expertise in the development and support of the business as it relates to information security.

SUMMARY

Hands on information security leader with director level expertise in information security, regulatory compliance, audit management, risk management, project management, security controls management, and personnel management. A multi-disciplined professional with a solid portfolio of accomplishment utilizing innovative technology and sound project management strategies. Proactive team player with strong leadership, problem solving and interpersonal skills.

PROFESSIONAL

Confidential

EXPERIENCE

Director Level Manager, Data Security Governance left due to workforce reduction

  • Provided senior level consulting to OptumInsight's various lines of business ensuring that all business segments were in alignment with industry and company best practices as it related to information security and data governance.
  • Led various audits and internal assessments to ensure regulatory compliance with the Payment Card industry Data Security Standard PCI-DSS , National Institute of Standards control framework NIST 800-53 , HIPPA, HiTECH, Sarbanes Oxley SOX , SSAE-16 formerly SAS 70 , UnitedHealth Group's internal control framework, and various industry certifications.
  • Collaborated across various businesses within UnitedHealth Group to ensure each entity not only met but also exceeded security best practices and developed various frameworks for audit and assessment management, vulnerability management, incident response and penetration testing which drastically reduced the period of acquisition integration from years to only a few months.
  • Developed the company's first metric reporting system for the senior executive team that conveyed on the status of audits and their associated remediation efforts, the status of mergers and acquisitions, and provided a risk ranking for potential areas that may fall outside of the defined tolerance level.

Confidential

Information Security Officer

  • Quickly earned the trust of Department of Justice executive team, allowing for a cohesive approach to initiating a robust and comprehensive information security program while demonstrating the value added by the Hewlett-Packard contract.
  • Developed the Field Office's first information security management program by instituting the NIST control framework, created and governed the implementation of security policies and procedures, implemented a risk management framework, and oversaw the offices first inventory of systems and applications.
  • Successfully Managed the certification and accreditation of all the FBI New York City Field Office networks, systems and applications in accordance with the National Institute of Standards frameworks, FBI mandates and Department of Justice policies.

Confidential

Information Assurance Officer

  • Provided executive level information security management in support of the Department of Defense, the Chairman of the Joint Chiefs of Staff and various intelligence agencies.
  • Developed automated account control processes utilizing the pre-existing public key infrastructure which reduced the time from account application to creation by over 50 additionally using automated processes allowed for auditing and oversight of system and application accounts while reducing the use of paper forms.
  • Championed the incorporation and managed the installation of an Enterprise Governance Risk and Compliance eGRC to replace the outdated word documents and spreadsheets used for tracking regulatory compliance, ongoing audits and assessments, certification of systems and applications, and risk management.
  • Due to the sensitive nature of work being performed in various offices within the pentagon, and the rampant use of mobile devices, instituted a mobile device policy and the installation and management of a wireless intrusion detection system.
  • In the role of Information Assurance Officer for Top Secret networks, successfully governed the assessment and certification of 11 enterprise level networks in accordance with various government regulations to include: the Defense Information Assurance Certification and Accreditation DIACAP , NIST 800-53, and the Federal Information Security ACT FISMA .

Confidential

Information Systems Security Officer

  • Developed risk assessments, assessed project plans, and consulted on system development life cycle controls, methodologies and procedures used for the various radar-assisted systems developed at the facility in accordance with the National Industrial Security Program Operating Manual NISPOM .
  • Performed periodic assessments and random security spot checks of all information systems located at the facility.
  • Developed the company's first risk assessment procedure for non-Windows based operating systems LINUX and Sun Solaris
  • Created and enforced security policies and procedures for all information systems and networks located at the facility.
  • Performed random physical security assessments to ensure that physical access countermeasures were operating properly and that surveillance cameras were located and placed correctly.

Confidential

Information Security Manager

  • Over the course of a 10-year career in the United States Navy, successfully managed the certification and accreditation of over 100 information systems supervised and trained nearly 300 junior sailors, and managed budgets ranging from 40,000 to over 500,000.
  • Received numerous awards during this timespan for superior service to include: the Joint Service Commendation Medal, three Navy Achievement Medals, Iraq and Afghanistan Campaign Medals and numerous letters of commendation.

We'd love your feedback!