We provide IT Staff Augmentation Services!

Principal Security Architect Resume Profile

2.00/5 (Submit Your Rating)

Dayton, OH

OBJECTIVE:

Information CyberSecurity Expert with 15 years of information security experience looking for a challenging security project or role. Full time roles considered would be Chief Security Officer, Chief Information Security Officer, VPor Director of Information Security or Partner. As a consultant open to anyinformation security roleswith an acceptable rate that allow virtual work. Open to some travel.

SUMMARY:

  • Managed, architected, implemented, and administered security for networks of up to 200,000 users. Largest client- United States Department of the Treasury. Maintains advanced hands-on technical skills in information security and uses them constantly. Expert inarchitecting, implementing and administering managed security services for organizations of all sizes and types. Managed groups of up to 25 people who reported directly and groups of up to 75 in total. Managed Sr. Managers, Managers, Project Managers, Architects, Engineers, Developers, Analysts and Help Desk Personnel of all levels. Specialized in solving unsolvable security problems. Deep experience not only in virtual security but in administrative and physical security as well.Seessecurity as a whole and understands what it takes to integrate security into an organization so that security is an asset to the business and not a hindrance. Able to architect and implement a complete security program whichcombines all facets of security for maximum organizational effect.Experienced in architecting cloud security for a variety of enterprises most recently large medical equipment and healthcare organizations. Experienced in creating and managing Vulnerability and Threat Management Programs for small to large enterprises.Designed and built the security organizations of many corporations from the top down.Expert in findingroot cause of the organization's security problems in order to create stable, lasting, security solutions.
  • Worked in a variety of vertical markets, among them medical healthcare, government, non-profit and for profit including financial, telecommunications, construction, retail, wholesale, state federal government entities, and information technology businesses including hardware, software services based organizations.
  • Constantly works with individuals at every level of the organization from engineers to CEOs and has a detailed understanding of the unique needs and concerns of them all.Expert in adaptation within any group and in any situation. Can communicate to an executive in a concise fashion the security needs of the organization and how security will affect the bottom line. Significant experience in dealing with the security concerns of corporate mergers and expert in working with both sides to quickly achieve the desired level of security.
  • No problem is unsolvable. Expert in both strategic and tactical securityand knows when to focus on each. Proven veteran in the field of information security with 15 years of advanced security expertise. A fierce love of learning and of security. Trainsconstantly tomaintain security expertise. Flexibility and quick mastery of all challenges presented is an invaluable addition to any organization.

Solutions Experience:

Cisco Products: Routers from 1000 to 7000, Catalyst Switches Series from 1000 to 8000, Linksys All Products, Entire PIX 500 Firewall Series, Entire ASA Series, Cisco Local Directors, Cisco Security Agent, Cisco MARS, Cisco NAC, Cisco FWSM, CSS, RADIUS TACACS, CiscoWorks, Cisco IPS Devices, Cisco Secure ACS, Wireless Products etc. Routing protocol experience includes BGP, RIP, IGRP, EIGRP protocols.

Microsoft Products: 15 years experience with Microsoft Business Products including all versions of Windows Operating Systems for Business PCs Servers Standard Server and Small Business Server versions from Windows XP to Vista to Windows 7, Windows 8, Server 2003, Server 2008, Server 2012 All Versions of BackOffice from 2000 to 2013 products including all versions of MS SQL Server, Exchange Server, ISA Server, Proxy Server, IIS, etc. All products in all versions of Microsoft Office including Visio Sharepoint, Powerpoint, Access, Outlook, Excel, Project, etc up to version 2013.

Juniper Products: Entire Juniper NetScreen Series of Firewalls and other Security Products All versions of ScreenOS, Entire SSG Series of security devices Entire ISG Series SSL VPN Products IDP Devices, SRX Series, All NSM Versions, etc.

Checkpoint Products: Checkpoint Software and Nokia Hardware corresponding to these versions: VPN-1 Firewall-1 NG, NGX, R62and R65, Splat ISO.

Sonicwall Products: All Sonicwall Firewalls

UNIX Systems: AIX, HPUX, DGUX, All versions of Solaris.

Linux Systems: Red Hat,Ubuntu, Knoppix, Fedora, Debian

HP Products: Entire Series of HP PCs Servers for Windows, Some HP UNIX Servers, Switches,

Mcafee Products: Extensive experience with business security products, hardware and softwaresuch as the McAfee Mail Gateway Devices Sidewinder Firewalls, McAfee NSM Intrushield , MCAfee IDS Sensors, McAfee Endpoint Encryption.

RSA Products: RSA SecurID all versions both hard and soft tokens, RSA Ace Server

Symantec Products: All Security Products both Software and Hardware Business Products, also their Veritas Product Lines such as all versions of Backup Exec.Symantec Endpoint Encryption, SEP client and server software. Symantec Endpoint Protection

CA Products: Entire Security Product Suite, including Business Products such as CA Enterprise.

Arcsight Products: To include ESM, Logger, and Connectors

BlueCoat Products: The full series of Bluecoat devices and software including such products as BlueCoat Director, Reporter and the 800, 900, 8000 and 9000 Series of Bluecoat Devices

Websense Products: Supported Websense Software/Servers Web Security for Internet Security. Have integrated it with Juniper/Netscreen Security Devices.

Veritas Products: Ten years of experience working with Veritas Products including Backup Exec, Veritas Volume Manager, Veritas NetBackup and several other Veritas / Seagate products.

Ten years of experience designing, implementing and supporting storage and backup systems.

Misc Security Products/Tools : A few of them are eeyeRetina, Tenable's Nessus, Wireshark, Ethereal, GFI LanGuard, Snort, Metasploit, Hping2, TCPDUMP, Nikto, OpenSHH, Putty, NetFilter, NetStumbler, AirCrack, Solarwinds Engineers Toolkit, Solarwinds Orion Suite of Products, Intellitactics, EM7, Splunk, MBSA, Tripwire, NMAP, RKHunter, Ophcrack, BackTrack, OWASP Tools, etc.

IBM Products: ISS Products, Tivoli Products, Proventia Products

Security Domain Expertise: Information Security Management Security Architecture and Models Access Control Systems and Methodology Applications and Systems Development Operations Security Cryptography Physical Security Telecommunications, Network and Internet Security Business Continuity Planning and Law, Investigations Digital Rights Management, and Ethics

Government and International Regulations Standards:ST E, DIACAP, NERC CIP Standards CIP-002-CIP-009 , FIPS 140 Compliance 140-1,140-2 new 140-3 , FIPS 199 High, DCMA, DISA, C A, FISMA, NIST 800 series standards including NIST 800-53, 800-37. DOD 8570.01 Certified. HIPAA HITECH, HITRUST CSF, SOX, GLBA, PCI, ISO 27001, ISO 27002, ISO 17799, BS 7799, NIST 2013 Cyber Security Framework

Experienced implementing and auditing around Meaningful use Security Requirements and the CSF Keys associated with HITRUST for large healthcare systems.

Splunk: Design and support for Splunk for global enterprises

Secureworks: Experienced with support and operations of Dell SecureWorks Suite of Projects

Remedy: Experiencedwith using many versions of Remedy to build and manage tickets and projects

VMWARE: vSphere, vCenter, vShield, VSwitch, Hyper-Visor, High Availability, Data Protection, Fault Tolerance

Sophos UTM and Firewall Products

IPAM IP Address Management

nCircle Tripwire Architecture, administration and support expertise

AccelOps Adminstration expertise

LanguardGFI - Adminstration

Qualys Support and administration expertise

ITIL v3training and implementation experience

Professional Experience:

Confidential

Principal Security Architect

LionGuard is an Ohio Based company providing advanced security consulting to security conscious organizations of every size from state and federal government organizations to non-profits and the largest global corporations. Workingacross all security domains in order to provide complete security solutions to its customers. Whether the business has a specific tactical security need or the need to build a new security program LionGuard is the answer. GRC, Governance, Risk, Compliance, Audits, Penetration Testing, Vulnerability Management, BCP, DR etc.

Confidential

Security Officer Principal Security Architect

  • Supplied expertise in a consultant role as an Information Security Manager, Security Subject Matter Expert Security Architect for the physical, administrative and logical security for hundreds of companies. 15 years of overall Security experience, this includes Information Security Management Security Architecture and Models Access Control Systems and Methodology Applications and Systems Development Operations Security Cryptography Physical Security Telecommunications, Network and Internet Security Business Continuity Planning and Law, Investigations Digital Rights Management, and Ethics. Provide advanced design, implementation, administration and troubleshooting of information security systems, risk audits, and methodologies. Extensive experience with all aspects of Managed Security Services. Experienced in using IPS and IDS and other security mechanisms to prevent and detect all types of digital security attacks such as DOS, Man in the Middle, Teardrop, Brute Force, Dictionary etc. Experienced in both Symmetric and Asymmetric Encryption. Extensive experience in physical security technology including layered defense, fences, bollards, guard camera placement, mantraps, locks of all types, biometrics such as palm scanning and retina scanning.
  • Extensive experience in vulnerability tests assessments, penetration testing, security assessments and audits, disaster recovery and business continuity plans, contingency planning, secure messaging, security policy creation implementation, security awareness training, GLB compliance, OWASP, SOX compliance, HIPAA compliance, FIPS compliance, NIST compliance, INFOSEC governance, risk management and assessments, access controls, encryption systems, MSS managed security services , security awareness training to combat social engineering, malware protection, incident response, forensics, account management policies, acceptable use policy AUP Creation and enforcement, virtual physical and administrative information security, expertise in Juniper, Cisco Checkpoint/Nokia security hardware and software. Experienced with Nessus, Retina, NMAP, SNORT, Sourcefire Cisco IDS, Wireshark, and ISS Tools among others.
  • Worked extensively doing work associated with ST E, DIACAP, NERC CIP Standards CIP-002-CIP-009 , FIPS 140 Compliance 140-1,140-2 new 140-3 , FIPS High, DCMA, DISA, C A, FISMA, NIST 800 series standards including NIST 800-53. DOD 8570.01 Certified.
  • Experienced in managing groups of up to 25 developers designing and developing custom software using Visual Studio .NET, C , ASP, and JAVA. Experienced in securing distributed applications. Experienced using APIs to customize existing software.
  • As a Network Architect duties performed include advanced LAN/WAN, VPN design, installation and troubleshooting with a focus on Cisco hardware and software. 15 years of experience with the entire range of Cisco Switches including Layer2 Multi-Layer Switches and Routers. Routing protocol experience includes BGP, RIP RIP2, IGRP, IS-IS, EIGRP protocols.
  • Expert in wireless networks. Over 15 years of experience designing, implementing, administering and troubleshooting wireless networks for global organizations. Experienced with 802.11a,b,g, n wireless technology. Experienced with wireless hardware and software from many vendors to include Cisco Aironet, Orinoco, SMC, Apple, Linksys, Netgear, DLink etc. Experienced with WPA, WPA2, TKIP, AES WEP encryption models. Experienced with Cisco Wireless Security Suite and the Cisco Self-Defending Network methodology. BGP, RIP, IGRP, EIGRP, IPSEC VPNs
  • 12 Years experience in providing Sun Solaris 7, 8, 9 and 10 installation, administration and troubleshooting
  • Designed, Implemented and Supported Wide Area Networks and Security Systems that connect global corporations across the planet including ATT, Time Warner, FMC, MCI, Munich RE, and Verizon Business. 15 years of experience working with various types of telecommunications data WAN links including, DSL, T1, T3, DS1, DS3, OC-3, OC-12, OC-48 lines.
  • 15 years of experience working with various LAN/WAN topologies to include, Ethernet, Fast Ethernet, Gigabit Ethernet, Fibre-Channel, Token Ring, FDDI, ATM, Frame-Relay.
  • 8 years of experience designing, implementing and supporting Checkpoint Firewall-1 / VPN-1 Software on Nokia Hardware and Windows Software
  • 15 years of overall experience administering Windows Servers including Windows 2000 Server, Windows 2003 and 2008 and 2012, Windows Active Directory,LDAP, Windows XP, Vista, 7 8 experience.MS SQL Server all versions including SQL 2000, SQL 2005 and SQL 2008.
  • Wide range of experience in the government, financial, insurance, retail, healthcare, telecommunications, and construction vertical markets.
  • 15 years of project management experience utilizing 13 years of experience with Microsoft Project. Currently using Microsoft Project 2013.

Confidential

Information Security Management Consultant Architect

Contracted for a review and audit of the current state of information security at this Columbus Based State Retirement System in order to lay out a plan for them on how to improve and mature their entire information security program including all areas of virtual and administrative security. Reviewed and recommended sweeping improvements across the information technology program including architectural and development improvements for custom software applications, UNIX and Windows VMWare servers, SQL Servers, all Security tools including AccelOps and Qualys, and security devices including Sophos UTM and Firewalls, Network infrastructure including HP and Cisco routers and switches, security documentation including policies, standards, procedures and baselines, the security awareness program, Disaster Recovery and Backup Continuity Plans and site, designed a complete security program from the ground up tailored to the unique needs of the organization utilizing standards and regulations that include NIST 800-53, NIS 800-37, NIST Cyber Security Framework, COBIT, ISO, ITIL, ISACA, HIPAA, OWASP SANS Security Tools. Laid out a detailed roadmap for permanent strategic and tactical improvements to security across the entire organization prioritizing and ordering each piece by relative importance.

Confidential

Sr. Security Consultant

  • Contractedto work as the Security Services Delivery Manager role for Moody'sa global financial services company. Managed and coordinated all information security related incidents, changes, tasks and security projects across several company divisions and across multiple groups of engineers, architects, helpdesk personnel and senior management. Security Services Management was a significant part of this role but there was also dailyhands-on security engineering and architecture work as well. Vast improvements in efficiency and quality of service across all security teams and technologies achieved to save millions in operational expenses.The response and resolution time on support tickets wasimproved dramatically. Processes and procedures have been standardized and documented then enforced. Teams have been cross-trained and single points of failure across all teams have been eliminated so that no single individual presents a significant vulnerability to the organization. Significant reporting across all teams and is now delivered on a weekly and monthly basis. The reporting was discussed and actioned to achieve further improvement across the organization each month. The change management program and processes have been improved and streamlined so changes no longer represent significant risk to the organization. Created and LED the entire vulnerability management program including creation of all hardware and software solutions and authoring all standards and procedures.
  • The groups managed include Content Filtering, Firewall, Security Architecture, AV, Endpoint, ACS, TACACS, Security Administration, PeopleSoft Administration, Defender, Audit, The SOC and Compliance Vulnerability Management. The products my groups support include Microsoft Active Directory, PeopleSoft, Bluecoat, Juniper Security Products, McAfee Security Products, Secureworks Products, nCircle, Quest Defender, Quest Change Auditor, Remedy, andCisco Security Products. Hands on technical skills were practiced weekly for all of these products.
  • Product solutions architected,implemented supported throughout include Cisco IPS 4255s and 4260s,ACS/TACACS, NAC, ASA Firewalls, Juniper NSM, Firewalls SSLVPN, Quest Defender, Dell 600 Series Servers, Bluecoat Reporter, BCAAA EndPoint Client, Bluecoat Proxy Devices including 800s and 900s, Symantec Endpoint Protection or SEP McAfee Endpoint Encryption or MEEP, nCircle TripWireproducts including Profilers, IP360, SIH for Vulnerability Scanning and Reporting Secureworks Customer Portal and Suite of Products including IDS managed iSensors, Threat Intelligence etc. Microsoft SCCM Juniper NSM Remedy Ticketing System, McAfee Intrushield NSM used to manage McAfee IDS Sensors. Windows 2003 and 2008 Servers, Red Hat Linux, Remedy, McAfee Intrushield and NSM,
  • Led all security projects with the client from beginning to end.

Sr Information Security Architect

Confidential

  • Contracted by Blue Mountain Labs to design an information security framework for this large healthcare system in California based on the ISO 27002 Framework in addition to HIPAA HITECH, HITRUST, PCI, FISMA, Meaningful Use, ISO 27001 and several NIST 800 standards. The system had recently been through a Deloitte Audit but they wanted a second more detailed opinion to confirm Deloitte's findings as well as a plan to remediate the findings as quickly as possible prioritizing by the highest risk findings. Identified the root of their security problems and laid out a detailed plan explaining how to address them to avoid audit failures going forward. Addressed security issues in each of the 12 domains represented by ISO 27002 sorting the findings and recommendations by risk level. Project plan was built showing step by step what was needed, who needed to do it, and what it would cost in time and dollars. Detailed security recommendations were written for each of the high risks found. Laid out new organizational structure for the security teams, designed a security awareness program, a physical security plan with enhanced security measures, addressed Disaster Recovery and Backup Continuity, DataCenter Design and consolidation and much more.

We'd love your feedback!