We provide IT Staff Augmentation Services!

Security Engineer,resume Profile

4.00/5 (Submit Your Rating)

AshburN

BACKGROUND

A thought leader strategic advisor and astute problem solver with a proven record of driving initiatives to lead and develop teams capture business manage costs and solve problems by fostering creativity and innovation. Success in performing a broad range of complex projects across multiple industry segments. Extensive experience assessing enterprise business security and IT processes evaluating controls and mitigating risk.

CORE COMPETENCIES

Information Assurance

Data Security Privacy

Critical Infrastructure Protection

Risk Management

Value Proposition

Cybersecurity Engineering

Regulatory Compliance

Enterprise Governance

Business Development

EMPLOYMENT EXPERIENCE

confidential

Senior Managing Consultant Service Area Manager

Understand HR policies and procedures provide constructive coaching and feedback align strategy and execution and recognize business challenges and opportunities for a team of 20 consultants.

Work with account teams to identify track and capture business opportunities.

Develop innovative effective and efficient solutions within the organization and for our clients. Interface with the C-level management of our clients and across IBM.

IBM Federal Cybersecurity Assessment Response CSAR Team Lead October 2013 Present

Built a new capability for US Public Sector programs focused on assessing operational risk and providing targeted incident response.

Developed a Data Security and Privacy program tailored to the business needs of the Army focused on providing client understanding and enforcement of key security and privacy issues risks exposures and vulnerabilities for a 20M annual program with 60 personnel and 800K end users. Designed developed implemented and managed security and privacy controls to include workplace security user ID administration and access control separation of duties program on/off-boarding risk management and security awareness training. Led continuous monitoring activities to include STIG Compliance Audit Log Review eRetina Vulnerability Scans etc for the GoArmyEd.com portal and supporting infrastructure. Other accomplishments included

Transitioned the solution from a non-IBM commercial data center into a new IBM hosted Federal Data Center and achieved the first DIACAP ATO for a system within the new environment.

Created a working group to identify and mitigate web vulnerabilities with the use of Rational AppScan and modify the program s SDLC to incorporate Rational Appscan code reviews into the build process.

confidential

Grew a series of single year .5M contracts to a 5 year 3.3M award totaling 6M in account signings. Managed account financials forecasts and reporting to include a 3.5M budget over the contract period. PM for team of 4 CIP/Mission Assurance/Supply Chain SMEs focused on establishing policy and

responsibility within the DCIP to include the identification prioritization assessment and assurance of Defense Critical Infrastructure DCI . Other responsibilities included

o Integrating the team into multiple communities working groups and tiger teams across the DOD. o Manage the SDLC and accreditation of a SQL database and .NET application on the SIPRNET.

o Develop and maintain an accreditation package to reflect the security controls required by the Defense Security Service DSS to achieve accreditation of a secure processing facility.

IRS Modernized e-File Lead Security Advisor March 2011 Present

Implemented IBM s Data Security Privacy program for a 25M annual program with 90 staff. As a SME tasked with guiding the program through a series of Contractor Site Reviews with IRS OCIO/Cybersecurity to ensure FISMA compliance mainly NIST SP 800-53 implementation across the account.

IBM Corporate Service Corps CSC Security SME June 2010 November 2010

Led a community-driven economic development project working at the intersection of business technology and society to identify and implement an enterprise governance model based on ISO 27001.

Federal Bureau of Prisons TRULINCS Penetration Testing Project Manager February 2009 June 2009 Managed a 250K budget and oversaw 2 FTEs responsible for performing physical and technical penetration testing with Backtrack and Metasploit on a GOTS application within the federal prison system.

USCIS TOMIS- FISMA Compliance Team Lead April 2007 September 2008

Responsible for a team of 8 FTEs and a 2.1M budget while also leading a field team charged with bringing USCIS into compliance with FISMA and performing individual C A packages for 50 systems concurrently.

U.S. Navy NMCI Server Consolidation IT Specialist April 2005 September 2005

Reduced CNI s O M costs by consolidating legacy systems applications and hardware onto NMCI.

RI Economic Development Council RI-WINs Project Manager January 2005 March 2005 Performed a technical feasibility study focused implementing a statewide broadband wireless network.

U.S.P.S. Wireless Infrastructure Implementation Deputy Project Manager August 2004 August 2005 Reduced cost and overhead as the PMO for an enterprise wireless infrastructure implementation.

confidential

Partner Managing Instructor

Developed and delivered course content for CISSP CISA CISM and ITIL evening and weekend boot camps. Created marketing materials delivered sales presentations and managed P L for security based offerings.

confidential

l

Security Engineer

Led commercial vendors through the Common Criteria process responsibilities included documentation of vendor configuration management process product designs and functional specifications secure delivery and operation plans development of security policy models and performing product testing and vulnerability analysis.

SPEAKING ENGAGEMENTS

National Conference of State Legislatures NCSL December 10 2009

Topic The National Infrastructure Protection Plan for the Information Technology Sector

We'd love your feedback!