Senior Managing Consultant in the Security & Privacy Practice at IBM.
Greater Chicago Area
Senior Managing Consultant in the Security & Privacy Practice at IBM.
Greater Chicago Area
Privacy Services Competency Co-Lead at IBM
(Commercial Sector, NGOs, State/Local and non-US-Federal Governments)
I am a Certified Information Privacy Professional (CIPP) and an Attorney. Experienced in the compliance and process driven issues relating to data security, data privacy, process development, compliance and other data governance matters. I have significant experience across many industries including, but not limited to, Legal, Finance, Healthcare, Telecommunications, Data Aggregators, Public Sector, Aerospace, Technology, and Manufacturing. (e.g. GLBA, HIPAA, SOX, COPPA, FERPA, ITAR, State Privacy Requirements, EU Data Protection Act, Safe Harbor, data related vendor management issues as well as cross-border data transfer). I have also assisted in the negotiation and/or evaluation of data security and privacy contracts.
I am also an attorney. This experience, combined with my consulting background, provides a unique perspective on the details of compliance, process and governance. It allows me to work with clients to not only explain statutory requirements, but also to help implement requirements from a functional perspective.
(Public Company; IBM; Information Technology and Services industry)
December 2000 — Present (8 years 8 months)
Work with corporate law departments to address data privacy, data transfer and other compliance requirements. Assist in contractual negotiations around data security, privacy, vendor management and international data transfer requirements.
Expertise working with clients to assist with development of both internal and external strategies in order to achieve compliance, privacy, security and data governance goals.
Manage projects ranging in size from two to 250+ personnel. Met sales goals.
Assist with data related vendor management and outsourcing risk management; help organizations comply with privacy and security requirements while leveraging outsourcing/global-sourcing/off-shoring.
Liaison between business units required to complete privacy related activities such as IT, Legal, and Compliance. Assist organizations build their privacy and compliance teams.
Develop training and other educational materials for all staff levels (Senior Management to new hires)
2008 Top Ranked Performer at IBM
(Law Practice industry)
1992 — 2009 (17 years)
My experience is primarily as a litigation attorney practicing in the insurance defense, contracts and commercial law areas.
I have litigated several jury trials and arbitrations (200+) and negotiated multiple contracts and settlement agreements. I have managed a caseload of over 250 cases. In addition to my trial experience, I have completed extensive compliance, negotiations and contractual work. I can provide details upon request.
(Public Company; 1001-5000 employees; NCI; Management Consulting industry)
May 2005 — May 2006 (1 year 1 month)
Discovery Services Practice
Special adviser to the Chief Privacy Officer of large telecommunications company.
Assisted with development of Navigant’s internal data governance, privacy, eRisk and compliance practice offerings.
Managed large scale records inventory project. Inventory was being collected from 12 sites in multiple states. Assisted large telecommunications company in the creation of their records management department.
Worked with large multinational corporations to address their data governance and compliance issues
(Partnership; 10,001 or more employees; Management Consulting industry)
1998 — 2000 (2 years)
Senior Consultant in the Legal Business Services Practice. Worked with corporate law departments and law firms in order to address their needs in the areas of product selection, technology process controls and merger strategy.
JD , Law
B.A. , Psychology
Some of the areas in which I have worked/have experience include: Privacy, Data Protection, Information Protection, Security, Information Assurance, Applied Cryptography, Security, RFID, Data Governance, Compliance (including PCI, SOX, HIPAA, GLBA, FCRA, PIPEDA, FERPA, EU Data Protection Directive, Safe Harbor) Security Frameworks and Standards (including ISO 17799/21001-2, COBIT, NIST) Vendor/Outsourcing, Risk Management, Data Masking, Data De-Identification, Data Anonymization, Enterprise Security Architecture, Wireless Technologies, Intellectual Capital Protection and Web-based Technologies
- Illinois State Bar
- Federal Bar
- Federal Trial Bar (Let lapse due to current responsibilities, can renew at anytime)
- Editorial Board, Privacy and Data Security Law Journal
- Appointed to the Illinois State Bar Association's Technology Committee, Chairman of the Legislative Review subcommittee, also Committee Board Member.
- Certified Information Privacy Professional (CIPP) from the International Association of Privacy Professionals (IAPP)
- Two patents
- 40+ published articles (List is available upon request)
- Numerous speaking engagements
- Recognized expert at IBM in the area of privacy, compliance, and crossborder data transfer and data related vendor management
- Multiple IBM Awards