Security Architect Resume
Rhode, IslanD
Experience
2008 – Present
Confidential,Rhode Island.
Security Architect
Responsible for all aspects of information systems security for Blue Cross to ensure the protection of information processed, stored or transmitted. Evaluate security products and tools for enterprise implementation and develops technical security configurations. Approve security architecture/designs, plans, controls processes, standards, policies and procedures to align with standards and security strategy. Direct and develop techniques and procedures for conducting security assessments and compliance audits and the evaluation of hardware, firmware and software for possible impact on security systems. Investigation and resolution of security incidents and the development of a comprehensive SIRT (Security Incident Response Team). Development and regular updating of procedures and requirements for security incident response based on technology risks and business requirements. Development of SIRT testing methodology and participate in periodic incident response tests.
Advise superiors on security effectiveness and recommends enhancements. Allocate appropriate resources to ensure that projects are completed within committed time and budget and are integrated with administrative and support protocols.
Develop, maintain, and communicate information protection security policy, standards, and procedures, including mandatory requirements, to support consistent and effective implementation of information protection for specific area(s) of expertise (i.e. distributed, mainframe etc.) across Business Units and IT.
Review and recommend security safeguards and configurations in a highly complex system infrastructure with demonstrated ability to recognize and appropriately incorporate layered security safeguards from the network perimeter, network, application, and data layers.
Define security requirements and coordinate application of IT security products to provide reliable and cost-effective information protection solutions to meet defined business requirements for specific area(s) of expertise (i.e. distributed, mainframe etc.) across Business Units and IT.
Research and provide technical expertise and assessment of new security products for specific area(s) of expertise. Work on project teams; lead the evaluation of emerging technologies and the associated security implications, potential infrastructure impact and solutions. Provide security engineering and standards and security subject matter expertise established by IT to ensure security standards, procedures and products, and technical engineering safeguards remain current and applicable.
2007 – 2008
Confidential,Ct.
Security Architect
Tasked to implement an 802.1x enabled environment based on data classification in order to facilitate a corporate wide project to segment the network. Through behavior modeling, separate applications into domains based on the data classification value and allow only users and processes to access the applications approved by management and corporate policies. NBA (Network Behavior Analysis) will be used to create Access Control Lists at pivotal points in the network as well as investigative and forensic discovery tools for the Information Protection Groups within CIGNA.
2005 – 2007
Confidential,Ct.
Security Architect
Responsible for the design, implementation, management, documentation and support of the information security infrastructure oWebster’s banking network. As Information Security Architect, reporting directly to the CISO, responsible for the development of an information security policy and the implementation of the network and support structure to support policy. This includes high-performance firewalls, Intrusion Detection (IDS) and SSL Virtual Private Networks, identity management, access management, etc. Support all aspects of administrative operations, as well as staying abreast of emerging technologies and solutions to continually improve the quality and effectiveness of information security. In addition, this role is responsible for reporting potential threats as well as measuring the effectiveness of current systems and policies. Constant review of federal regulations for HIPAA, SOX, GLBA and bank specific regulations such as BSA/AML, with implementation of framework based upon CoBit and 17799 standards and best practices. Serve as technical advisor for all information system security related issues. Assist the OCC (Office of the Comptroller of the Currency) in audits performed on the bank as well as internal audits. ITIL certification received 4/07.
2002 – 2005
Confidential,Ct.
Manager Infrastructure Security
Managing a staff of 7, responsibilities include the implementation and management of the security infrastructure at Oxford Health Plans. Installed 15 Firewalls (Checkpoint/Nokia) and 14 IDS (Intrusion Detection System) Dragon Sensors and Management Server. HIDS (Host intrusion Detections Systems) installed on 50 critical servers. Revised all security policies and related HIPAA documentation and involved in all business decisions regarding Internet access and internal security related issues. Attended many management courses, Nokia, Checkpoint-NG and Dragon training. Building LDAP servers for deployment of SSO (Single Sign On) and consolidated security access using 2 Factor authentication (RSA ACE server for tokens). Manage and perform remediation for audits and security assessments, for both HIPAA and internal initiatives.
2000 – 2002
Confidential,Ct.
Manager - Information Systems Security
Managed the internal and external security infrastructure of Warnaco’s worldwide network. Responsible for the implementation and installation of IDS (Intrusion Detection Systems), port scanning and vulnerability exposure reporting systems. Traveled extensively to sites in England, France and the Netherlands performing security audits for these major hub sites. Deployed virus scanning and detecting software as well as designing the international VPN network. Inspected and hardened firewalls and NT servers. Uncovered weaknesses in various platforms as well as drafting policy for all users pertaining to use of the corporations network and Internet. Performed penetration testing in order to exploit problems with inadequate system protection, and corrected many of these deficiencies. Due to financial difficulties within the corporation, I was asked to produce a plan to reduce costs with the data/voice network. This plan included the re-negotiation of telco contracts and to address the complex variety of retail businesses included under the Warnaco umbrella and to produce an all-inclusive network of voice/data/video within the worldwide organization. Security using Multi-Factor authentication was built into the design.
1999 - 2000
Confidential,Ct.
Senior Systems Network Designer
Upon consolidation of all subsidiaries within Pitney Bowes, my role encompassed network consolidation and planning of generic platforms for the entire 10,000 user base. This included replacement/upgrades to existing hardware within the data infrastructure and voice network. Consolidation of redundant T-1’s, voice over IP where applicable and elimination of redundant facilities were addressed in the plan. Consolidated messaging, operating systems and mid-frame to mainframe platforms were also incorporated. Project planning and in depth analysis of business processes led to the in process plan in effect today.
1996 - 1999
Confidential,Ct.
Manager Networks/Communications
Managing a staff of 18 people, reporting to the Director of Information Technologies, responsibilities include the dependability of the corporate data network in a 7x24 environment. The network consisting of 27 Novell file servers, 21 NT servers, Cisco routers connecting 8 remote sites, with a node count of over 800. Mainframe/midframe includes a Unisys 2200 and 7 HP Unix 9000 computers which all reside on a 10/100 switched ethernet network. Hands on management is required because of the size and diversity of applications required by the business. Staff includes Help Desk which reports via Remedy and Spectrum generated ticketing. Tech support 5 (includes myself) are responsible for NT, Novell, Cisco’s, VLAN’s, Notes, RSA ACE Server, etc. Uptime has been 100% for over 5 years with a 92% user problem resolution rate within 24 hours. Wide area consists of frame relay backed up with ISDN. Remote sales forces (laptop users) are handled through an Ascend 4000 for analog and ISDN dial-up requirements. I have implemented these solutions to consolidate “Shiva” type modem pools and provide a more integrated solution for access. Installed and support Firewall-1 for Internet access along with content filtering and virus protection. Received several awards over the years for outstanding performance and a member of the exclusive “Presidents Club”. Designed, implemented, and successfully performed the move of the Credit Corporation from Norwalk, Connecticut to Shelton, Connecticut over a period of 4 weeks providing 100% uptime during this transition. Managed many other projects to meet or exceed business objectives with the time and budget appropriated.
Software/Protocols
Novell 2.15 thru 4.11, NT 3.51 thru 4.0, Cisco IOS, Cobol, Microsoft, UNIX, Linux CSU/DSU’s, IMUX’s, TCP/IP, IPX/SPX, Ethernet, Frame Relay, Asynchronous/Synchronous communications, SNMP, OSPF, RIP, RMON, SMTP, VLAN, etc.
Education
Checkpoint-NG Firewall Installation and Support
Checkpoint Firewall 4.0 Installation and Support
Nokia IP530/IPSC Installation and Support
Enterasys Dragon Intrusion Detection System Installation and Support
Cisco - Advanced router configuration, Cisco Internetwork troubleshooting
RSA ACE Sever configuration and support
NT 3.15 system administration, TCP/IP for NT 3.15, NT Networks and Design
Communications Design (generic)
Attended many SPERRY/UNISYS schools while working for this vendor.
Novell (2.15) system installation, Novell (3.12) installation and support Novell (4.10) system administration, various other Novell courses
Timeplex router configuration
HP Openview - Support, Cabletron Spectrum - Configuration and support
Many other schools mainly pertaining to communications and networks
Seminars and trade shows, (Networld, Interop, SAN’s etc.)
Security education/seminars through Security Solutions (NY Consulting firm)
