Compliance Resume Profile
TarrytowN
Summary
- Dynamic communicator who empowers diverse - disparate teams to collaborate and optimize performance.
- Astute problem-solver whose troubleshooting skills help eliminate unsolvable challenges inherent in conventional methods.
- Coopers Lybrand professional IT Audit Staff Staff Trainer when there still was a Big 8
- Extensive track record for focused identifying, evaluating and reporting on complex, technical IT related risks and controls, according to professional standards and methodologies, recommending control issues corrections, implementing IT controls in world-class environments: financial, manufacturing, health. Highly skilled in organizational security, compliance, risk/control self assessments, governance, infrastructure architecture controls, business continuity, security awareness, multi-site operations, program/project management, turnarounds, mentoring and team leadership COBIT, COSO SOX 404, EuroSOX - Basel II, GLBA, HIPAA, SEC, OCC Federal Reserve, FFIEC, ITIL, FISMA, FERPA, Patriot Act, Cyber Security Privacy Acts, NIST, ISO, PCI 3 .
CORE COMPETENCIES
- Quantitative IT Risk Assessment, RoC,
- SAQ
- Project Management, PMO, and Corporate IT governance
- SDLC, RAD, Application development
- Web Security 2.0, Websphere, OWASP, Cloud Computing
- Identity Access Management, SSO,
- System process work flow diagrams / narratives and controls analysis
- Business Continuity Planning/DR
- Strategic Tactical IT Security/Audit planning budgeting management
- Role Based Access Control Provisioning Data Security Sec Stds Definition
- PCI/DSS Email Exchange Compliance Regulations
- Security Architecture-all layers: Networks, O/S and Applications
- Security Awareness: IT Technical and Business views
- Mentoring and Team building
- E-commerce and EDI controls
- Policy and Procedures: assessment, development, standards, frameworks: COBIT, ISO 27002/17799, FISMA, NIST 800, ITIL, CMMI/ISO15504
- Control risk/modeling analysis/ assessments SOX, SAS70, GLBA, FFIEC to Risk Mgt Plan/Framework Liaise w/ key stakeholders: Users IT
- Vulnerability assessments with security packages, CAATs, Pen tests viruses, worms, malware
- Vendor Mgmt Negotiations
SELECTED ACCOMPLISHMENTS
- Directed Bank of China's OCC compliance projects gained 100 Fed approval of systems security controls framework.
- Turned around troubled SOX review- IT governance project for Steve Madden, completing process in days, not weeks.
- Led security implementation for IBJ-Mizuho Bank, building fully-secure distributed system for 5000 users.
- Established a Fleet Brokerage CIRT by documenting cyber invasion processes and designating contingency personnel.
EXPERIENCE SUMMARY
Permanent employee and independent consulting comprise the course of my career my consulting company is
BEATRICE BLOCK ENTERPRISES, INC
Confidential
Compliance/Governance
- Conducted Performed multiple IT security/audit reviews risk assessments to world class organizations Identified threats/vulnerabilities and mitigated security risks inherent in new technology, products and external vendor relationships verified controls, addressed logical user privileges, authentication, authorization, infrastructure controls architecture, and interface application integration with other systems developed enterprise security policies and procedures for C-Level IT Steering Committee remediated outstanding audit findings/exposures remediated risk review findings developed overall risk controls framework based on NIST 39, COBIT, etc. knowledge of FERPA 1974 US Privacy Act Developed PMI project plans/schedules for security/compliance/risk projects monitored timing and budget constraints flowed data, systems and processes for internal business/IT units outsourced vendors. Presented regular project status reports to senior leaders and key stakeholders.
- Completed Regulator IT Risk initiatives SOX 404 and IT audits for Citibank, Confidential, AIG, Bank One, Fleet Bank, Provident Bank Evaluated/recommended IT infrastructure/application controls compliance per regulatory requirements assessments for financial, insurance, medical, manufacturing and government institutions to discover emerging risks and potential impact on organization. Reviewed security control gaps, quantified/qualified risks and recommended corrective controls activities, reduced risk and strategically improved business performance, with emphasis on customer data leveraged Coopers Lybrand project management experience to refocus teams towards tactical objectives completed projects in 6 weeks modified enterprise wide business users after troubleshooting problems in team environment.
PROFESSIONAL EXPERIENCE to Present
Confidential
- Remediate IT Audit findings regarding Access Management Group Access. Worked with international auditees in real time.
- Provide guidance to business decision-makers with development of mitigation strategies.
- Ensure that adequate and effective security processes and controls are followed.
Confidential
Developed Policies, Standards, Framework documents contributed also by using knowledge of general business, insurance and accounting frameworks.
Developed written communications for the organization's executives, department heads, and end users regarding pertinent IT activities.
Confidential
ISSO, Consultant 8/ /2013
IT Security Project Manager: Reorganize IT Security organization, Develop Policies, IT Risk framework, Manage personnel security architecture, Develop BCP/DR, Enforce Privacy via FERPA HIPAA
Produced reports presenting risk circumstances and responded to recommended changes.
Developed a sustainable security compliance program, which included all legal, privacy and regulatory requirements according to NIST, FIPS and FERPA.
Conducted assessments to identify non-compliance and worked with engineering leads and architects to implement tools and processes to monitor and report on security compliance.
Reviewed business continuity and disaster recovery plans and tests.
Managed Information Security staffing, including recruitment, supervision, scheduling, development, evaluation, and disciplinary actions.
Applied general knowledge of applicable data privacy practices and laws, and project management principles.
Confidential
Vendor Controls Assessment Reviews including infrastructure: O/S, LAN segments, VPN, firewalls IPS Identity Access Management: A/D, SSO MS Email Exchange, etc. Provided advisory services to ensure compliance and governance requirements were met.
Identified and analyzed areas of risk to information and infrastructure assets and provided appropriate recommendations for mitigation.
IT Audit for various Non-profits providing government disability benefits, Volunteer
Confidential
Developed IT Security Awareness Framework and Implemented Program.
Aligned SA program to deliver compliance with security policy and regulatory requirements.
Provided guidance to decision-makers on issues and development of SA and Learning Management System strategies.
Confidential
Developed IT Security Awareness Framework, Security Awareness foundation database, project plan for automated learning management system Moodle and strategic plan to implemented SA Program in 32 Districts, 1500 schools, 50 offices including Central Administration in Brooklyn for 1.2 million students, their parents and 40,000 employees in 5 NYC boroughs.
Established standardized processes and procedures for SA dissemination and assessment of risk mitigation.
Confidential
IT Security Head / Director
Hired as part of OCC mandate to improve information security, IT risk management, and mitigate IT risk: vulnerability/threat id, monitor suspicious activity via IPS/IDS, patch management, secure data transfer, service delivery, 2-factor authentication
Inherited Global 500 banking IT security environment facing OCC order to close Bank and aggressive regulatory penalties.
Eliminated completely OCC Consent Order line item re: IT Security BCP by redesigning/testing new Business Continuity Plans/DR for US operations of BOC revised BIA system database based on FFIEC NIST established ongoing communications with OCC.
Managed Information Security Department and advised/mentored Internal Audit. Reported to Chief Risk Officer, General Manager. Developed and maintained risk management systems and processes. Developed and maintained policies, processes and standards to reduce risk, minimizing business disruption
Designed and implemented an IS program initiated risk assessments, instituted best practices of 10 security domains to support executive strategic goals and meet IT corporate governance objectives.
Beatrice Block, CISA, CISSP, CISM, CIA, CGEIT, CRISC, CBM 914.564. 4.631.1993 H
Identified and addressed security exposures to accidental and intentional information destruction, disclosure, modification or interruption. Assessed application/technology infrastructure for compliance of policies with federal, state and local regulations as well as industry generally accepted IS control standards followed FFIEC Basel II and NIST corporate governance guidelines.
Coordinated security awareness training programs with respect to data security and recovery planning Mentored techs and business personnel re: logical access privileges and controls for GLBA, HIPAA customer data for system processing and data transmission.
Partnered with external auditors, regulators, business units, vendors and clients to address security concerns and compliance issues.
Confidential
Hired to address risk-vulnerabilities-threats for division of New England's largest bank 9th largest in the US at the time . Supervised consulting projects to ensure timely and effective completion of project components.
Performed security/network gap assessments/analysis risk assessments to satisfy GLBA: vulnerability scanning and pen-test, application, infrastructure/ operating systems, general controls, patch mgmt, email Exchange, security risk exposure to IDS, TCP/IP, SSL, Kerberos, PKI and smart cards. Worked with PMO ensuring evaluated controls and uncovered vulnerabilities, developed in SDLC and CM processes and implemented. Compliance focus: encryption, email archival, threat vulnerability assessment fortification, BCP/DR, identity/ access mgmt directory mgmt - LDAP, SSO, logging-monitoring-auditing, network OS security architecture, data security for customer employee data in storage transmission logical physical, policies-procedures-processes, web security. Also served as the Audit liaison for both internal and external reviews.
Contributed security documentation to corporate strategy. Developed and maintained security policies, controls and their compliance- followed COBIT, ITIL, NIST, FFIEC, and ISO. Reviewed vendors and managed, negotiated contracts, e.g. Symantec, True Secure.
Managed risk events for Computer Incident Response Team CIRT, especially in relation to Web based applications.
Confidential
Information Security Officer
Directed implementation of security controls for online financial systems. Reported to CIO/General Manager about strategic results.
Redeveloped policies and procedures to align rigorous controls with IT business stakeholders monitored compliance.
Protected resources by certifying logical access privileges of users and vendors. Designed paperless security administration system.
Mitigated security exposures in International Bank of Japan's migration of legacy systems to client-server.
Coordinated with IT Dept and IT Audit to initiate and/or improve IT controls that were adequate for the new configuration post mainframe legacy systems.
Confidential
Vice President, Corporate Audit/Technical Security Support Research
Performed risk assessments/ threat analyses for multiple systems in bank IT environments. Responsible for all aspects of IT audits.
Conducted operational controls and application audits -data center, OS MS Windows, Unix networks, client-server /mainframes, trading, HR-HIPAA: data classification, mgmt, backup, disposal, logical access IDM application/user provisioning/SSO, vendor mgmt 3rd party review, patch mgmt, logging, encryption, config chg mgmt SDLC, compliance, vulnerability, BCP/DR, facilities, personnel.
Led audits of security services and architecture including authentication, authorization, access control, and end-to-end security, non-repudiation of services, common layer APIs and public key technology. Participated in customer data privacy audits PCI DSS
Mentored staff about risk-based auditing and integration with financial audits. Promote cooperation and information sharing.
Traveled extensively worldwide to troubleshoot audit/security issues and design solutions for multiple environments/platforms.
Built managed IT Security Audit Tech network lab for development and test of security controls on networks, hdw sftw.
Managed and led compliance reviews to ascertain business assurance and attestation to controls adherence.
OTHER RELEVANT EXPERIENCE
Subject Matter Expert highly respected voice of integrity and transparency. Able to quickly build relationships of trust.
Supported, participated, lead-managed regulatory reviews SOX IT reviews reviewed credit card security in 1990s now PCI DSS .
Able to discern areas of concern that may need an in depth review. Able to communicate risk concepts to business and IT managers.
Framed Security Awareness methodologies and delivery mechanisms for diverse organizations including a European global investment organization and the largest school system in the world NYC Dept of Ed . Organized IT controls/governance strategy for several national organizations. Framed Security Awareness program for foreign financial management firm for techs business.
Developed IT Security Standards/Policies for new IT technologies for several companies and influenced professionals with presentations on security controls and audit for professional organizations including data warehouse, policy content, cyber terrorism and security awareness ISACA, ISSA, IIA, etc. . Advised and mentored C-Level managers.
Adjunct professor at NYU developed curriculum taught for graduate Certificate of Information Systems Auditing and Security. Approach communicated included statistical sampling and quantitative methods.
Authored books and published articles on IT auditing security in leading technical journals and industry newsletters.
Beatrice Block, CISA, CISSP, CISM, CIA, CGEIT, CRISC, CBM
Projects Performed Permanent Positions
Updated 8/5/14
Tarrytown,NY
Time Frame
Organization
Relationship
Role/Title
Summary
Confidential
Contractor Consultant
IT Security Access Management
Remediate IT Audit findings regarding Access Management Group Access
Confidential
Contractor Consultant
Senior IS Officer
Policies, Standards, Framework
8/ /2013
Confidential
Sub-Contractor C2C
IT Security Project Manager, aka ISSO
Reorganize IT Security organization, Policies, IT Risk framework security architecture, BCP/DR, Privacy
Confidential
Sub-Contractor C2C
IT Audit Reviewer
Controls Assessment Reviews for vendors to TDA: infras,IAD,Exch email, firewalls
Confidential
Volunteer
IT Audit Reviewer
Reviewed procedures, provided pre-audit compliance guidance
Confidential
Sub-Contractor C2C
IT Security Project Manager
Develop IT Security Awareness Framework. Implement Program
Confidential
Sub-Contractor C2C
IT Security Project Manager
Develop IT Security Awareness Framework. Implement Program
Confidential
Direct W2 Employee
Head of IT Security Division
Reorganize IT Security organization, Policies, IT Risk, BCP/DR, IDM provisioning
6/
Confidential
Sub-Contractor C2C
IT Security Project Participant
Identity Access Legacy Management - IDM
Confidential
Sub-Contractor C2C
IT Security Project Participant
Identity Access Legacy Management
Confidential
Sub-Contractor -W2
IT Security Project Participant
ITIL Configuration Management
Confidential
Sub-Contractor C2C
IT Auditor
SOX 404 IT Compliance Governance
Confidential
Sub-Contractor C2C
IT Auditor
SOX 404 IT Compliance Governance, IDM
Confidential
Sub-Contractor C2C
IT Auditor
SOX 404 IT Compliance Governance
Confidential
Direct - C2C
IT Security Project Manager
IT Security Architecture IT Processes
Confidential
Sub-Contractor C2C
IT Auditor
SOX 404 IT Compliance Governance
Confidential
Sub-Contractor C2C
IT Auditor
SOX 404 IT Compliance Governance
Confidential
Sub-Contractor C2C
IT Auditor
SOX 404 IT Compliance Governance
Confidential
Sub-Contractor C2C
Audit Mgr Lead
SOX 404 IT Compliance Governance
Confidential
Sub-Contractor C2C
IT Auditor
SOX 404 IT Compliance Governance
Confidential
Sub-Contractor C2C
IT Auditor
SOX 404 IT Compliance Governance
Confidential
Employee W2
IT Auditor
IT Security Risk - Risk, Audit, SDLC, IDM, BCP/DR, P P, Pen Testg, monitrng
Confidential
Sub-Contractor C2C
IT Auditor
IT Audit various MS functions: AD, Exch, Registr,Comm, gen'l infras archit
Confidential
Sub-Contractor C2C
IT Auditor
IT Audit various MS functions: AD, Exch, Registr,Comm, gen'l infras archit
9
Confidential
Sub-Contractor C2C
IT Auditor
IT Network Infrastructure Audit
9
Confidential
Sub-Contractor C2C
IT Security Project Manager
IT Audit Risk User Provisioning, SDLC RAD, Waterfall, Infras archit
Confidential
Employee W2
IT Audit Security Risk Manager
IT Audit, VP IDM, ext. vendor mgmt, email, MS Exch AD mgmt, Cr Cards
Confidential
Employee W2
IT Audit Risk Manager
Lead manage IT Audits for NYC Local government NYC Board of Education Building Unit
Confidential
Employee W2
IT Audit Supervisor
Lead manage IT Audits for NYC organization for bank brokerage
