We provide IT Staff Augmentation Services!

Network Security Architect Resume Profile

3.00/5 (Submit Your Rating)

TX

Experience

Confidential

Network Security Architect

  • Provide project management leadership, architectural, risk and compliance expertise to a cross-functional team charged with deploying a host of business internal, partner, and customer-related applications and data for cloud based Internet access Big Data, Hadoop, Cassandra , retention, recovery, physical cyber-security. Develop and support the document stores using Extract, Transform and Load ETL methodologies including, extract data from outside sources Instruction in traditional waterfall development and agile SCRUM methodologies.
  • Transform the data to fit business needs including verification and cleansing Load into the data warehouse or schemaless document stores MapReduce, NoSQL Databases and assure scalability, consistency, and availability.
  • Documentation and implementation of various compliance frameworks COSO, COBIT, ITIL, NIST, AGA, NERC Regulatory, NERC CIP v3, NRC, PCI, CFR as well as reviews of current operating frameworks as well as pending framework upgrade requirements. Worked with firewalls such as Cisco Confidential

Shell Security Compliance

  • Function as the Regulatory Compliance Lead for Houston downstream business. Provide regulatory expertise in the areas of compliance covering internal Shell based control frameworks ISO, NERC, NIST, SOX and Confidential Export Compliance. Contribute to recommendations and the design of ongoing extensions and improvements to the data warehouse to improve its capacity for delivering effective business intelligence.
  • Evaluate and assure import/export compliance of Gas, Oil, and chemical products with numerous transport methods pipeline truck . Document and evaluate application, encryption, disaster recovery, and business critical processes to document and submit periodic reporting both internally and externally. Develop and implement business process automations where possible and appropriate across

Confidential

Project Professional

  • Harris County Toll Road Authority HCTRA
  • Provide risk and compliance expertise ISO, COBIT, PCI to evaluate and document critical business application requirements and evaluate against existing infrastructure and future growth expectations. Identify and document gaps and prepare recommendations to address existing network obsolescence and deficiencies combined with identification and recommendation for future infrastructure expansion and upgrade in accordance with best practice business continuity, record classification and retention, and disaster recovery capabilities to meet and/or exceed business requirements.

Confidential

Senior IT Auditor

  • Design and Implement continuous monitoring program for IT general controls based on a unified model
  • of COSO, COBIT, and ISO 27001/27002 frameworks. Evaluate and recommend tool selection as well as assist IT project implementations for compliance with internal control frameworks, Disaster Recovery and regular IT based audit activities.

Confidential

Senior Risk Compliance Consultant

  • NRG/RRI
  • IT Application and General Control testing and remediation recommendation in preparation
  • for external audit.

Confidential

.Net Web Developer

Analyze, Re-Design, Develop and Deploy a web application for managing underwriting requests from disparate processors nationwide. Update security and functionality to handle multiple parallel requests per loan as well as secure for public internet usage.

Confidential

Shell Trading

  • Provide information asset risk management and compliance expertise relating to oil and gas product shipment, IT, general risk and control activities critical to annual compliance efforts ISO, NERC, FERC, SOX, COBIT, PCI . Interact with business operations and management personnel to facilitate periodic compliance assurance reporting activities including pipeline, ship, railway and trucking deliveries
  • Serve as the North American project lead for implementation of an energy trading risk based control and compliance initiative based on the ISO 27001/27002 frameworks. Liaise with Shell Group information risk management on overall design, implementation, training, and documentation efforts aligned with the ISO implementation and related gas and chemical projects. Facilitate and lead the identification of risks associated with the power and liquids trading applications and design/implement control structures to mitigate the identified risk aligned with the ISO 27002 implementation.
  • Facilitate annual SOX related application control reviews and risk assessment reviews with Service Delivery Managers SDMs both in the US London to assure annual risk mitigation activities are performed based on oil and gas chemical imports and exports. Participate in cross-functional discussions of risk and control related activities and projects for US, Canada, and UK operations.

Confidential

Senior Independent Compliance Specialist

  • Aegix Consulting
  • Senior NERC Compliance Consultant Director NERC Compliance Project Services
  • Design, Development, Project Management and Delivery of multiple NERC Reliability Standard 693 Critical Infrastructure Protections CIP based compliance projects for multiple clients including gas turbine, hydroelectric, geothermal and wind based generation. These projects involved managing and training multiple teams, developing and performing risk based assessments RBA as well as designing the risk based methodology specific to each client.
  • Designing and implementing Internal Compliance Programs ICP , Evaluating Critical and Cyber Assets,
  • Interfacing with client management, regional and governmental agencies, designing and implementing mitigation plans, design and negotiate sanction and fine reduction and mitigation plans. Design and perform training programs for NERC clients to increase awareness of compliance programs and reporting requirements.

Confidential

Senior IT Security Compliance/Internal Audit Consultant

  • Shell Trading
  • Design, Develop, Implement and Pilot a prototype SharePoint WSSv3.0 MOSS 2007 web-portal based application utilizing automated workflow and the Windows Workflow Foundation WWF to automate and enable user self-service of critical end user computing EUC applications spreadsheets including the inventory of EUCs, risk based assessment, change control, approval collection and control structures.
  • Review and re-design the Shell Trading End User Computing Policy to encompass a risk-based approach to evaluate EUC applications End user spreadsheets, databases, queries, etc. critical to Shell Trading operations expanding the scope of the policy to the global business including EUCs critical to all levels of the value chain as well as financial reporting SOX . Design Develop and Implement required Segregation of Duties SOD matrix and automated system to report exceptions for multiple trading systems.
  • Review and perform testing for change control and security for North American Trading operations. Re-design, operate and maintain the control structure for the periodic assessment of critical end-user applications including the security and change management of these applications. Perform end-user training on the control register as well as embed the controls into line operations.

Confidential

  • Review and perform SOX related Point in Time testing for Q4 2005 as well as 2006 SOX round 1 control testing for locations in Houston, Maryland, and Brazil. Interface with process owners and management to identify complimentary and mitigating controls as well as discuss deficiency analysis and overall testing strategy and impact in preparation for annual SOX 404 assertion.
  • Sirius Online Survey
  • Design, test, and implement Microsoft SQL Server reporting services and reports to support an online survey application for Corporate Culture, Tone at the Top, SOX 404, SOX 302 assessments as well as customized client surveys including periodic update and reminder automated reports to numerous external clients.
  • BJ Services
  • Evaluate client frameworks and develop and execute test plans including remediation and remediation testing specific to hazardous and chemical materials. Interface with process owners and management to identify complimentary and mitigating controls as well as discuss deficiency analysis and overall testing strategy and impact in preparation for annual SOX 404 assertion. Interface with both internal and external audit teams as well as staff development and deployment in the execution of designed testing plans as well as go forward control design and implementation strategies to align with best practices and COSO/COBIT models.

Confidential

Internal Audit/Sarbanes-Oxley IT Consultant

  • Design, test, remediate and document semi-automated and automated systems and operational controls for corporate and global field locations hazardous material deliveries in compliance with 404 reporting.
  • Perform risk assessment and business continuity evaluation and consultation advisory services. Assist in the development, loading and deployment of MS Access database use in chemical reporting. Distribute and evaluate control self-assessment CSA . Interview trucking and transport personnel and document high-level business processes to design, test and document workflows and control points for individual applications and interfaces with financial and procurement systems. Perform pre-implementation audit of financial systems prior in preparation for deployment in accordance with COSO and COBIT guidelines.

Confidential

Senior Security Analyst/Project Manager Midstream M A

  • Enterprise Reporting, Data Warehousing, Document Management Sarbanes-Oxley Compliance SOX IT Risk Assessment Mitigation
  • Evaluation, analysis, quality assurance, security, internal control, compliance and implementation of hardware and software to provide and maintain business continuity as Dynegy expanded midstream operations by acquiring multiple pipelines and gathering systems of oil and gas based pipelines. Minimize risk exposure of unified data warehouse/reporting environment using customized interfaces to Crystal Enterprise, Crystal Reports, and Crystal Analysis Professional Team selection and project management budget forecasting and staffing Software selection and maintenance Acting as liaison between chemical business operations, users and IT.

Sarbanes-Oxley SOX Process Design

Design, document and implement processes and controls to remain in strict compliance with current SOX legislation requirements including process design and documentation, change control, approval, SOD and exception process management for IT systems regarding energy liquids trading, division order, and settlement.

Plant Allocation Automation and Delivery using Documentum

Analysis/design/customization/implementation of Documentum document management software package along with custom coding via the supplied API to interface with production plant accounting systems providing an automated report archiving and delivery model for all externally delivered required reporting. The primary goal of this project is to standardize and automate both the generation and delivery of chemicals contractually required for all parties and to provide a solid audit trail in compliance with legislation.

DMS Data Warehouse

Analysis/design/implementation of multidimensional data models, conformance with data warehousing best practices, and ETL processes to expand the existing DMS Data Mart architecture to include all aspects of the liquids delivery value chain. This includes gas gathering and refining, liquids trading, transportation, plant maintenance systems, and geographic information systems GIS . Creation and implementation of custom Crystal Reports and workflow interfaces tied to the Crystal Enterprise architecture for enterprise reporting.

DMS Data Mart

Evaluation/selection/implementation of software and hardware requirements creating a foundation architecture for a unified database. This included analysis of existing data structures, conversion of existing reporting environment to Crystal Reports utilizing the Crystal Enterprise delivery framework, Evaluation of Extraction/Transform/Load tools ETL , creation and testing of unified multidimensional data models in conformance with data warehousing best practices, design and implementation of ETL processes.

DMS Web Reporting

Evaluation/selection/implementation of software and hardware to create a web based reporting environment using Crystal Reports, providing scheduled, parameterized demand, and ad-hoc custom interface reporting to local and remote internal users as well as external users.

Unified Contract Management

Evaluation/selection/implementation of software and hardware to combine information from disparate contract management, gas plant accounting, commercial contract, and land management systems into a single, web delivered management application. This included design of business rules, user training program, and documentation.

Land and Right of Way

Analysis/design/development/implementation of a client/server application to integrate information from disparate database systems acquired into the Dynegy back-office systems to monitor and maintain contractual obligations and chemical/hazardous material obligations

We'd love your feedback!