We provide IT Staff Augmentation Services!

Senior Manager Resume Profile

2.00/5 (Submit Your Rating)

Dallas, TX

SUMMARY OF EXPERIENCE:

Network TCP/IP, Network and Host Based Intrusion Detection, Enterprise Security Monitoring, Information Security Policy Development, System Access Controls, Network Vulnerability and System Assessment, Security Metrics and Capability Maturity Model Development, Security Risk and Business Impact Analysis, Security Event Management Digital Forensic Investigation Acquisition Analysis, Windows and UNIX Operating System Security Baselines, Information Security Awareness Training , Security Incident Response Handling, and Experienced: Information Technology Adjunct Instructor with Strong interpersonal, verbal, communication, presentation and organizational skills An Information Security Professional that Understands Security as a Business Enabler, -- Ability to Leverage People, Technology, and Processes. Familiar with Banking Financial Sector Regulatory Guidelines Such As: Federal Financial Institutions Examination Council's FFIEC , Gramm-Leach-Bliley Act GLBA , and Sarbanes - Oxley SOX

INFORMATION SECURITY BUSINESS HISTORY:

Confidential

Manager

  • Manager Team of 8 Security Administrators and 1 Forensic Security Engineer
  • Coordinate and provide enforcement of security access controls for 13 critical business applications
  • Act as primary project liaison for all access control enterprise single sign on solution ESSO initiatives
  • Created and Coordinated Entitlement Review Processes and service level agreements
  • Drafted and implemented security access control plan and enforced data classification policies

Confidential

Manager

  • Respond to client fraud activity by creating organizational incident response and forensic security program
  • Member of organizational cross functional Client Asset Protection Team and Client Information Incident Response Team responsible for providing detailed incident data to chief executive's general council office
  • Created, implemented and currently managing 'Forensic Investigation Live Cycle
  • Enhanced forensics acquisition and analysis capabilities through training and hardware/software procurement
  • Provide forensic support for all internet abuse, compliance violation, internal hackers, intellectual property theft, and ediscover
  • Coordinate Information gathering and reporting suspicious activities to senior management
  • Adopt security technology that help automate key processes while enhancing overall management and control across the IT environment
  • Measure information security performance according to security standards and leading practices articulated by business analysts and associates
  • Utilize network based evidence tools to investigate and analyze security events of interest

Confidential

Senior Manager

  • Managed security staff of five security experts including: Technical Risk Analyst, Senior Forensic Investigator, Junior Forensics Investigator, Intrusion Detection Analyst, and Security Administrator.
  • Responsible for ensuring that all technical risk assessments and security reviews are performed in and efficient and through manner for all new projects introduced into the organization's System Development Life Cycle costing between 100,000.00 and 1,000,000.00.
  • Identified all threats, vulnerabilities and recommend appropriate operational, administrative and technical controls to addresses all known risk, ensuring all residual risk are reported to stakeholders in a sustainable and repeatable manner.
  • Ensured that infrastructure's technical risks were identified and assessed in a manner that represented business impact to through close collaboration with Project Managers and Subject Matter Experts in support of 45 projects.
  • Applied techniques used in training and development courses Managing Flexibility and current participation in Managing TD Waterhouse .
  • Provided weekly Security Posture Briefs to the Chief Security Officer CSO and Chief Information Officer CIO .
  • Attended Carnegie Mellon University's Creating and Managing Computer Emergency Response Team and developed organization process for incident detection, triage, and response.
  • Facilitated Risk Assessment Sessions focusing on Active Directory deployment ensuring Security Principles were adhered to.
  • Developed and applied Information Risk Assessment quantitative and qualitative risk factorization method.
  • Planned, designed, developed, and currently implementing information security requirements into the Firm's business processes in accordance with International Standards Organization 17799.
  • Designed and manages Intrusion detecting trending, metrics, and comparative analysis techniques.
  • Established and implemented internal vulnerability scanning process for identifying system and network level vulnerabilities applications and infrastructure.
  • Established Technical Risk Assessment Processes Integrated them into the System Development Live Cycle, worked with numerous Project Managers to identify risks.
  • Managed the expansion of host base intrusion detection deployment in eBusiness environment.
  • Conducted intra office meeting to define strategic direction for Technical Risk Management
  • Ensured that various security disciplines within the depart work to gather synergistically, and integrate in a manner that supports the business objectives of organization.
  • Developed awareness training and communicating Technical Risk Management Security Principles.

Confidential

Manager, Business Continuity Service

  • Developed training curriculum for Business Continuity Process Assessment training class, and conducted two-day workshops, resulting in producing 15 Certified Business Continuity Assessors.
  • Drafted Business Continuity Center Strategic plan and provided direction for newly established service department, directly contributing to the completion of Business Continuity ending database.
  • Responsible for creating, analyzing and updating the assessment benchmark analysis database used for comparative analysis metrics and trending.
  • Collaborated and drafted organizational policy, procedure, and workflow diagrams for the Enterprise.

Confidential

Manager, Enterprise Information Security

  • Managed staff of three security professionals.
  • Provided guidance for information security strategy and policy for 242 locations spanning the globe, balanced security needs with business requirements.
  • Implemented Virtual Private Network VPN access controls for over 3500 remote users and enhanced the security posture by preventing unauthorized access to the networked systems.
  • Established and facilitated 18 member cross-functional Information Security Forum and increased information security awareness throughout the Enterprise.
  • Established standard, centrally managed anti-virus, personal firewall, and threat assessment capability for 3700 desktop and laptop users.
  • Designed the training manual used to train 3500 VPN users and 30 VPN administrators, enhanced users adaptability to new access controls with minimal interruption to normal business operations.
  • Trained Help desk staff in procedures and methods of remote access authentication support and troubleshooting, enhanced customer support capabilities.
  • Developed the Security metrics process utilized measure, monitor, and report on the effectiveness and compliance of security policy and controls in accordance with National Institute of Standards and Technology NIST guidelines.

Confidential

Director Service Development Security

  • Served as Subject Matter Expert on Intrusion Detect System Design and Implementation, resulting in developing sound process, methodology and procedure for system implementation and on-going operational customer support.
  • Advised Chief Technology Officer in the development of information security service offerings resulting in the Technical Service Delivery model for network and host vulnerability assessment.
  • Performed network and host vulnerability assessment for Healthcare and financial service clients.
  • Drafted ISO 17799, GLB, and HIPPA Compliant General Organizational Information Security Policy, resulted in the establishment of regulatory complaint information security framework.

Confidential

Associate Director, Network Security

  • Managed staff of 5 security experts.
  • Developed procedures for identifying an analyzing security events of interest, this provided the network management team with a security operations capability.
  • Developed and implemented administrative security process and procedures, reduced the number of know vulnerabilities by 27 .
  • Directed and supported security testing and evaluation, resulted in the selection and subsequent deployment of first-ever network intrusion monitoring device.
  • Managed information security monitoring and compliance process testing.

Confidential

Retired Master Sergeant

  • Managed Staff of ten security professionals.
  • Led the planning, development, and operational support of the critically needed Network security section and compiled the Air Force's Combat Information Transportation System and Base Information Protection Program three months earlier than required.
  • Effectively implemented cutting-edge automated network security tools, providing the center with the first intrusion detection capability for the 3.500 computer node, 200-server infrastructure, worth over 2 million dollars, this capability provided senior or leadership with the ability to identify and respond to unauthorized and suspicious network activity.
  • Instituted and Managed the Center's remote dial-in computer access infrastructure supporting 400 worldwide external customers, resulting in providing senior leadership the ability to access critical personnel data in a secure and timely fashion.
  • Facilitated the necessary coordination to ensure information security policy aligned with business objectives this resulted in a well managed operations for firewall and intrusion detection systems.
  • Performed periodic and on-demand network security vulnerability assessments, and enhanced overall information security posture of the organization.
  • Developed a continuous risk management process and provided repeatable methodology for identifying and reducing information security risk within the network infrastructure to an acceptable level.

We'd love your feedback!