Senior Compliance - Primary Lead in managing and administering IAVM Information Assurance Vulnerability Management on the Operation Compliance Team.
- Planned and implemented technical security controls e.g. access management, antivirus, patch management, vulnerability scanning, log management, etc. .
- Project Planning, Management, and Administration of major software and agent deployments, upgrades, and maintenance cycles to over 1500 servers, including life-cycle management of systems and applications via automation.
- Ensured audit findings and evidence are collected, reviewed, remediated, and presented in a clear and concise manner.
- Documented audit procedures, make recommendations, and follow-up to validate implementations.
- Identified and evaluated business and technology risks, internal controls which mitigate risks, and related opportunities for internal control improvement.
- Tailored and Migrated approaches, methods, and tools to support service offering.
- Identified and evaluated business and technology risks, internal controls which mitigate risks, and related opportunities for internal control improvement.
- Facilitated use of technology-based tools or methodologies to review, design, and/or implement reviews e.g. Symantec Altiris, Symantec Norton, IBM Tivoli Endpoint Manager, McAfee EPO, CA, PGD, Retina, Nessus, etc .
- Performed security risk assessments.
- Technical Advisor to Systems Administrators, Engineers, and Architects.
- Planned and Implemented technical security controls e.g. access management, antivirus, patch management, vulnerability scanning, log management, etc. .
- Experienced with major security frameworks e.g. PCI DSS, HIPAA, DISA STIG, IAVM, NIST, FISMA, etc. .
- Evaluated audits of IT systems and evaluate against technical controls and operating procedures.
- Manage and administered Automation of Security Patches in support of Regulatory Compliance through the use of IBM Tivoli Endpoint Manager TEM for approximately 70 of the company's servers including Exchange, Clusters, SQL, and Management Servers.
- Maintain Operational Compliance Efficiency, Effectiveness, and Success Rate of 97/98
- Conducted Oversight and Managed vulnerabilities of over 4,000 servers throughout a systems life cycle from initial build/deployment, production, to decommission while strictly adhering to Quality Control of Content and Change Control.
- Track, catalog, correlate, monitor, analyze on a daily basis: vulnerabilities CVE information from various sources: US Cert, NIST, Vendor's, MITRE, etc. , findings Tenable Nessus, Retina, PGD , and patches Vendor Security Patches .
- Create maintain weekly on a daily basis vulnerability patch remediation baselines within the current remediation tool IBM TEM.
- Analyze and Communicated defective/deficient audit finding codes and patches
- Maintain TEM Deployment baseline to reflect the operational requirements real-time for new Deployment Projects ensuring accuracy, consistency, and minimizing unnecessary work for missed audit findings.
- Maintain patch approvals in WSUS for the primary use by other departments and teams.
- Schedule and Execute Automation via TEM with respect to predefined maintenance windows time parameter minimizing system outages to ensure high availability.
- Track, monitor, maintain server status and their respective maintenance window to ensure no unwarranted changes to configuration has been made
- Communicate any anomalies or deficiencies detected during Analysis/Assessment process to vendors Oracle, Microsoft, Adobe, Nessus, etc. for resolution.
- Coordinate and Plan with multiple teams any potential delayed releases for further research, testing, and validation minimizing risk to the entire organizational infrastructure.
- Conducted and Mentored Oversight of Testing.
- Delivered Quarterly and Yearly Reports to Executive Management.
- Reported Vulnerability/Configuration Posture/Status/Trends weekly or where needed Compliance Assessment/Recommendation to supervisor.
- Documented Case studies for internal Knowledge Base and Training.
- Analyzed/ Requested IBM to re-engineer TEM for proprietary enhancements and changes conducive to the company's business need and requirements.
|