We provide IT Staff Augmentation Services!

Security Engineer Resume Profile

2.00/5 (Submit Your Rating)

TX

CAREER SUMMARY

An information security professional leader with 15 years of experience with an up-to-date skill set that will be utilized in improving your company's security posture. Who has led many types of projects to successful completion simply by paying attention to detail and not losing sight of the goal. Successful projects have included both internal and vendor risk assessments, commercial software development, networks, data center, and construction. One who has successfully managed the development of loyal teams that accomplish the tasks at hand. Actively communicates to all levels of management along with the people who are overseen. Very dependable, great people skills, gets the job done

WORK EXPERIENCE

Confidential

Distinguished Member of the Technical Staff

  • Corporate Information Security Governance, Risk and Compliance responsibilities included managing the enterprise security policy content, content review in the rewrite and annual review
  • Developed additional information security requirements, security standards documents and authored security awareness articles
  • Represented information security at the Verizon Information Security Council VISC and in various internal projects
  • Performed the Sarbanes Oxley SOX audit tests and information security policy interpretation for clients.
  • Conducted and escorted QSA for annual PCI DSS assessments in DFW area stores and call centers.
  • Conducted stakeholder meetings, compared the existing security policy against ISO 2700X, NIST 800 series documents, and generated the proposed draft.
  • Investigated and researched policies and proposed the base for the enterprise security policies utilizing Archer.
  • Managed the development and implementation of a policy exception process which conducts risk analysis, monitors and tracks recertification of requests.
  • Conducted state by state analysis on data breach laws as they pertain to sensitive information.
  • Coached the team in generating custom security requirements technical policy documents.
  • Performed risk analysis and security assessments primarily for internal project teams.
  • Strategically proposed the Security Advisor role for validating customer and vendor compliance.

Confidential

Senior Information Security Engineer

  • IT Security Governance ITSG responsible for providing technical information security engineering services to support and validate information security controls in place protecting Countrywide Financial Corporation CFC data from exposure. Matured 3rd party risk assessment process to attain COBIT level 4.
  • Consulted with CFC users on security requirements for data, applications and processes.
  • Developed the third party assessment process providing compliance with FISAP BITS and OTS.
  • Information security SME for several projects/systems making sure the security controls comply with CFC policy
  • Conducted information security reviews / risk assessments on both internal and external applications / projects.

Confidential

Vice President, Specialist

  • System Data Security Corporate Information Security responsible for planning and conducting supplier information security risk assessments, gap analysis, remediation and project leadership.
  • Verified controls based on corporate policy, VISA, BITS, PCI, HIPAA, GLBA, SOX, and ISO 17799 standards
  • Directed remediation of suppliers' and subcontractors' information security gaps.
  • Led project for Information Security Assessment of ten Latin America sites in seven countries.
  • Led project to improve and update the onsite assessment program included updates to standards.

Systems/Skills

Windows, UNIX, Linux, Citrix, Archer, VMware, Informix, MS Access, HP Open View, ISS, Check Point, SAN, NAS, VPN, LDAP, MS SQL, PCI, Oracle, HIPAA, SAP, Nmap, Nessus, VPN, TCP/IP, Cloud security, BYOD, Website security, ISO 2700x, COBIT, NIST

We'd love your feedback!