Integration Architect/ Program Manager Resume
SUMMARY:
- More than 15 years of increasing responsibility in information technology, most recently as an Enterprise Architect and Program Manager.
- Confidential Infrastructure Architect - Designed/defended/implemented print server architecture for 12,000 print servers Wintel/Unix.
- During my tenure we achieved ATO at 8 space-flight centers.
- Confidential built and maintained Entrust 6.x CA, registration authority, and Profile Servers,and Identity Management solution for approximately 25,000 providers.
- Identity and Service Provider solution architecture/design - ForgeRock, Ping, NetIQ, Radiant Logic, WSO2 Identity Server. Federated Authentication/Authorization, XACML, OAUTH, OpenID Connect, UMA, API implementation /Security, role mining, engineering, LDAP, HIPAA, HiTech, PCI, DSS, NIST, FISMA.
- Enterprise Web service integration strategy/and optimization.
- Responsible for Security Incident Response Team implementation and team management
- Enterprise Web service integration strategy/and optimization.
- Deep understanding of IAAS, PAAS, xAAS architecture, Container technology (Docker/LXC/CoreOS)
- Deep understanding of Dev Ops practices
TECHNICAL SKILLS:
HYPERVISORS: ESXi, Hyper-V
PKI Platforms: Windows 2K8/2K12 CA, AD-RMS, Entrust 5-6x, Net IQ eDirectory Certificate Server, XKMS, Keytool, OpenSSL
LDAP Platforms: Radiant Logic, AD, OpenDJ
CLOUD UTILITIES: Openstack, AWS, Apache StratosARCHITECTURE/OPERATIONAL FRAMEWORKS AND TOOLS Togaf, Zachman, ITIL, RUP, LEAN SDLC, Rational Software Architect, BizzDesign, Sparx EA, Windows Azure - MOF, ATAM, IASA COBIT
APPLICATION SERVERS: Tomcat 6.x/7.x, WAS 7, WSO2 ASMONITORING UTILITIES Tivoli Enterprise Monitor, Oracle Enterprise Manager, V-Cops, WebSense
HEALTH CARE APPLICATIONS: NextGen Confidential /EPM, EPIC, Facets, Pega BPM (Clinical Outreach and Continuum of Care).
SAN/SAN UTILITIES: NetApp Filers, Snap Vault/Snap Mirror, VMWare Storage Virtual Appliance, SVSAN Storage Virtual Machine Manager, ybernetics NAS Appliances
DATABASES AND DATA MGT UTILS: MySQL 5.x, Access, MS SQL Server 2000-2008, Active Directory, Oracle 10/11g, Toad, Crystal Reports, Cognos Metric, Query, Report Studios, SSRS, Crystal Reports.
TELEPHONY: IVR, CTI integration (AD/J2EE Application/MS Lync), XMPP
PROJECT MANAGEMENT/BA TOOLS: MS Project, SharePoint 2010/2007, MS Excel, Visio, Serlio Software, MAVEN 3.x CASECOMPLETE, Borland Caliber, Rational Requisite ProPROGRAMMING LANGUAGES/TOOLS Visual Studio 20xx, Sharepoint Designer, Powershell 2.0/3.0, Java 6/7 (intermediate), C# (intermediate), bash (intermediate)
CLOUD UTILITIES: vCloud, AWS, Apache Stratos, jClouds
IAM Tools: WSO2 Identity Manager, Ping, OpenSAML, Shibboleth, ForgeRock OpenAM, NetIQ
EXPERIENCE:
Confidential
Integration Architect/ Program Manager
Responsibilities:
- SSO Implementation for Ncompass/Pega BPM Suite. Implement
- Configure BPM Suite to use Integrated SAML/LDAP (eDirectory) Authentication
- Configure Pega/Ncompass Application as Service Provider to Internal IDP WSO2 Identity Server
- Draft Enterprise application assessment for SSO readiness. Included integration level of effort and resource requirements.
- Drafted Web Service security strategy document.
- Participated in SOC 2 compliance activities
- Configure internal IDP imitated SSO for PEGA/Ncompass, SharePoint, and internal Web Applications
- Configure attribute exchange with External Partner IDP's to facilitate Federated SSO
- Connect IDP (WSO2 Identity Server) to multiple User Stores LDAP/AD, database and custom user stores.
- Define Signing/Encryption requirements for Federated transactions.
- Draft WAM strategy /roadmap including candidate products for Privileged IDM, MFA, Oauth/API security,
- Customize SAML Request/Response parameters. Make changes to SAML endpoints in response to infrastructure changes.
- Create Additional attributes in eDirectory to support passthrough ZOS (mainframe) authentication.
- Restful API Implementation for legacy soap services using ESB proxy services.
- Design data service tier to support Pega applications.
- Manage multiple Web service remediation projects including membership services, claims services, and Member/Subscriber privacy web services.
- Draft AuthN/AuthZ process flow diagrams.
- Participate in IT governance process including Security Process/Usability forum, Infrastructure Access Management working group
Confidential
Program Manager/Enterprise Architect
Responsibilities:
- Define trust architecture with corp partners.
- Define structure of intermediate CA’s and application dependencies.
- Hybrid Cloud Implementation:
- Identify application workload candidates for AWS migration
- Define/customize cloud formation templates for on/off prem XenApp Implementation
- Create AWS IAM profiles for aplications and cloud administrators
- Perform Key mgt functions in AWS
- Create VPC’s, subnets, IG’s Interfaces as needed for AWS environment.
- Enterprise Integration Program:
- Led the implementation of WSO2 ESB (Apache Axis2/Synapse) including:
- Initial Custom API architecture (Create Data WSO2 Data Services Web Services; Implement proxy service security and mediation)
- WSO2 ESB implementation (Endpoint definition/requirements; Built services to support 834 and 837 EDI transaction status lookups, patient transportation request confirmation and cancellation, and BPM patient status verification)
- Built Data Web Service tier to enable SharePoint and Custom .Net applications to consume Facets and EHR data.
- Built initial BPM infrastructure- PEGA (PRPC) 6.3
- Defined Data architecture for BPM to support patient Outreach and Continuum of Care Events
- Install/ Configure POC PEGA frame works BIX, CPM, CPMHC
- Configure and manage Tomcat 7.x Application servers
- Coordinated Dev/Test/Stage/Prod development cycle with offshore team
- Managed Realization process
- Architecture Competency Development: Created standard sets of architecture artifacts for Infrastructure, Data, and Application architecture engagements.
- Evangelized the concept of architectural vision and implemented requirements lifecycle management to support the ADM.
- Development and coordination of Technical Recovery Guides for core infrastructure systems, Application Recovery Guides, and Business Recovery Guides.
- Recovery team coordination and DR process design.
- Ground up incident response team procedure development.
- Developed program roadmap including infrastructure table top exercise coordination.
Confidential
Infrastructure Architect
Responsibilities:
- Responsible for Agency Print Server Architecture, Print Fleet Management, Platform Security, Service Design, and Deployment.
- Built the first vSphere ESXi 5.0 clusters to house print servers at 10 Confidential agency centers.
- Implemented Microsoft Intermediate CA to issue/manage certificates for output devices (MFP/MFD/Scanner/Plotter) .
- Review and adhere to DISA STIG documentation.
- Personally wrote powershell, bash/korn shell scripts to migrate and manage print queues on sun and Windows platforms.
- Managed the project team responsible for migration and steady state management of 34,000 print queues and 11,000 physical printers.
- Team consisted of 4 Senior Confidential IT Operations Managers, approximately 13 vendor technicians with dotted line reporting to me and the Kyocera field manager, 2 output management consultants and a varying amount of HP Enterprise Services Data Center infrastructure engineers, 3 contract project managers.
- Implemented Federated Print Services (via AD RMS) across multiple Confidential sites and between Confidential and various Federal and Private Entities.
- Defined and defended (at Confidential HQ in Washington DC) a print server architecture that met Confidential 's security, audit, availability, and procedural requirements.
- Configured NFS/ISCSI storage for vCenter hosts per requirements.
- Created Master Project schedule for all server migration activities, service initiation/retirement activities
- Managed the sun setting of hundreds of legacy file and print servers using secure disposal methods.
- Use PM techniques to determine budget and schedule variance.
- Initiated Change/Service requests in response to project work information.
- Managed most project coordination SharePoint task lists and document repositories. Maintain project SharePoint website.
- IPsec - connect print servers at all agency data centers to central agency data center using IPsec.
- Implemented single pane server and print queue monitoring solution.
- Integrated legacy and incumbent print infrastructure components with new ESXi print server clusters.
- Configured Unix/Wintel server instances and MFD's in accordance with DISA SPAN STIGs (DOD IT - SPAN - Security Tech Integration Guides)
- Involved in the creation/implementation of hardened Print Server platform in accordance with CIS benchmarks and guidelines
- Configured Solaris Print servers to use AD authentication services
- System Security Control identification and mapping based on NIST-853
- Automation of core system functions user management, print queue creation, log analysis, OS installation, and patching using shell scripts and PowerShell.
- Participated in agency infrastructure security policy setting forums as needed.
- Acted as first responder for investigative and audit activities.
- Created a prototype forensic process for automating audit and print server investigations.
Confidential
IT Consultant
Responsibilities:
- Data Analyst/Project Manager for Pharmaceutical Supply Chain Data Warehouse upgrade
- Pharmaceutical product line analysis in support of Enterprise Supply Chain application re-architecture
- Defined Data domains/Dictionaries and quality standards for Vascular Products
- Worked to refine Data and Information Architecture in the Clinical Product space to support FDA and patient reporting guidelines.
- Worked with senior business leadership to define
- Drafted architecture for
- Managed team of 3 business analysts and 1 intermediate Project Manager responsible for the elicitation of business and technical requirements.
- Extensive work "sanitizing" data for consumption by downstream enterprise systems such as SAP/Peoplesoft
- Hands on data management to include report consolidation
- Cycle Count inventory application design:
- Co-developed and application using Access/Excel to pre-process approximately 12000 inventory items daily that were located in incorrect Kaizen locations.
- Reviewed/Refined existing schemas. Define/Develop KPI's using Cognos tools
- Streamlined application architecture. Optimize data architecture across multiple domains.
- Participated in Data Governance process
- Provided status across multiple levels of management and stakeholders
- Refined task lists; scheduled activities; identified and mitigated risks associated with constrained resources in a matrixed environment..
Confidential
IT Consultant
Responsibilities:
- Consulted and Refined project delivery process for Print Re Architecture Program which included Print Server Platform design for approximately 1400 print servers.
- Designed Enterprise automated document factory using. Built POC environment created bash and powershell scripts to automate print stream transformation and document delivery.
- Provide consultative support to technical leads regarding system optimization, service optimization, and Wintel platform re-architecture.
- Provide overall estimates for budgeting and capital purchases. Approve SOW’s ; perform Earned Value Analysis on work delivered relative to cost and time.
- Led matrixed, tiered project teams that span business silos and functions.
- Created technical documentation including Visio diagrams, requirements specifications, System and Data workflows, and Root Cause Summarization.
- Acquired contracted services through the process of RFP/RFI's, POC's, bidding conferences, and participating in contract negotiations.
Confidential
Solution Architect
Responsibilities:
- Pre-Sale Assessment of client environment including all data platforms, processes, and workflows.
- Drafted initial reference architecture documents including AS, Heat Map, System-Function-Data-Information Context Diagrams.
- Implemented Togaf based ADM at each engagement ensuring that Requirements and various architecture artifacts were in place
- MDM and Web service development for Mid-Size Manufacturing companies enabling data service consumption, and reporting. Confidential creation for processing of structured info sets between entities.
- Enterprise environment documentation including but not limited to data processing workflows drafted in Visio, Printer and SAN device support procedures, and configuration specs.
- Managed multiple project teams that were responsible for all aspects of Sage MAS 90/500 ERP package implementation including, use case and requirements analysis, HW and SW procurement, vendor/partner management. Manage end to end customer engagement from definition to project closeout.
- Ownership post project support and post- sale engineering activities which included sub project initiation.
- MDM and Web service development for manufacturing companies enabling data service consumption, and reporting.
- Confidential and Confidential creation for processing of structured info sets between entities.
- Enterprise environment documentation including but not limited to data processing workflows drafted in Visio, Printer
Confidential
Lead IT Security Engineer
Responsibilities:
- Provided administration and management of Entrust Public Key infrastructure environment for Confidential authentication.
- Including all PKI operations
- Maintained PKI registration authority and Identity Management solution for approximately 3000 providers
- Draft/Maintain CPS (Certificate Practice Statement)
- Security Incident Response Team implementation and team management
- Web application retrofit to enable SAML 1.0 assertion based credential passing in Confidential .
- Led KSIRT incident response team
