Project Manager Resume Profile
SUMMARY
Information Security Chief, Manager Data Network Security, Senior Information Security Analyst. Security Generalist. Lead Security Architect, PCI IT security vulnerability management A self-starter - built information security from the ground up PCI/SOX IT audit compliance - remediation Business Continuity Disaster Recovery Plan /BCP coordinator. Interpretation/development/enforcement of corporate policy managed incidence response and mitigation Windows/UNIX/Operations manager studying Pen-Testing and CISM for certification.
PROFESSIONAL EXPERIENCE
Confidential
Consulting project Security Analyst Email RSA DLP project on Email PCI DSS, HIPAA/HITECH
IronPort ESA SDLC documentation - DLP policy implementation DLP violations, compliance monitoring Metrics Modulo Risk Management SaaS Admin.
Confidential
Consulting project at Oriental Trading Company - PCI DSS IT security.
- Providing PCI IT application/network vulnerability management recommended PCI Scan Vendor transition, brought in and initiated contract talks executed installation of system IPs and setup system scan schedules documented methodology needed for future system inclusions, scan reports interpretation and communication to system administrators provided knowledge transfer to interim scan system administrator.
- Review system security configuration standards for PCI compliance, Qualys, McAfee SECURE, McAfee Foundstone scanning, scan interpretation, remediation follow up streamline PCI compliance scan requirements, SME services.
Confidential
Information Security Chief, Senior Information Systems Security Analyst, Lead Security Architect, and ISM Professional autonomous security focal
Improved and ensured outsourced IT IBM compliance to SOX/PCI requirements and corporate/best practice policies and procedures:
- Create/updated IT Security policies/procedures to meet current and changing needs Managed SOX/PCI requirements/security remediation and audit support Compliance to ISM Information Security Management , the parent company corporate security efforts Project manager for MEI parent company and Corporate security initiatives US representative to ISM security forum in Japan.. Oversee security tools configuration changes managed system patching to all environments trained and certified in SafeBoot PC encryption security tool.
- Reviewed and updated security policies/controls and procedures.
- Accomplished compliance to PCI DSS requirements.
- Enterprise liaison to outsourced CIRT team.
- Process owner - remediated SOX security related deficits.
- Liaison to IBM for Panasonic's outsourced IT and security interests, SOX and PCI DSS compliance.
- Ensured security architect met Panasonic requirements.
- Served as security lead to IBM's SOC during incident responses.
- Lead WAN group to modify IDS/IPS signatures to proactively detect unauthorized HTTP GET/PUT web application change attempts.
- Made adhoc requests to modify firewall rules and terminate suspicious connections.
- Chaired system update meetings to ensure timely changes and patching to LAN/WAN hardware.
- Became interim Security Chief based on incidence response and incident remediation efforts.
Confidential
Manager of Data Network Security
- Manager of Application and Operations Information Security. Maintained, updated and tested the Business Continuity/Disaster Recovery Plan. Administrated Check Point Firewalls and Netscape Mailhost/SMTP servers. Researched, recommended and promoted security related strategies, tools and best practice policies.
- Built security from the ground up. Ensured that the bottom line would not be affected, due to security issues.
- Developed Security policies/controls and procedures.
- Successfully managed projects in: Business Continuity/Disaster Recovery planning, Intruder Detection implementation, Network assessment, Security Audits/Penetration studies, external audit.
- Formed and chaired first Security and Change Management Operations Committees.
- Interim Operations Manager and HP Unix Manager.
- Developed ERP PeopleSoft security Identity Management
- Administered Websense product.
- When staff was reduced, worked under matrix/umbrella concept where messaging, firewall, Websense and LAN/WAN groups were made available to me for security administration. At that point I went back to performing my own technical work with messaging, Websense and LAN products.
Confidential
Director IS Department
- Database and Systems Administrator Selected and acquired software, hardware, maintenance contracts and consultants Managed department budget Determine the company's future computer systems direction Database applications report programmer.
- By migrating the company away from a Novell to a Microsoft network, was able to provide a faster responding system from which to store and retrieve data more efficiently and therefore more productively.
- Migrated Windows 3.1 and Novell 3.12 client/server to Windows 95 and Windows NT network system.
- Installed UNIX resident SYMIX accounting system. Created remote access for field reps.
