Experienced Information Security Professional, Writer, and Blogger
Greater New York City Area
Experienced Information Security Professional, Writer, and Blogger
Greater New York City Area
(Privately Held; Management Consulting industry)
June 2009 — Present (6 months)
(Public Company; Publishing industry)
October 2007 — Present (2 years 2 months)
Author papers, featured articles, and blogs on information security, risk management, and technology. Topics include web application security, cloud computing, data loss prevention (DLP), and encryption. Samples:
Bulletproof Apps: State Of Software Protection Today
http://informationweekanalytics.com/index.asp?PageAction=VIEWPROD&ProdID=58
How To Assess Offshore Data Security
http://www.informationweek.com/news/services/outsourcing/showArticle.jhtml?articleID=208400731
A How-To Guide To Cloud Computing
http://www.informationweek.com/news/services/storage/showArticle.jhtml?articleID=212201920
(Public Company; DIS; Information Technology and Services industry)
July 2008 — June 2009 (1 year )
Operated as the interim-CTO of a new Walt Disney venture overseeing all aspects of technology and advertisement serving for an online property including:
- Development
- Systems Engineering
- Ad Operations
- Information Security and Risk Management
In this role, I successfully integrated an acquired company into Walt Disney while stabilizing and expanding upon the technology. I acted as the primary technology decision maker, product architect, and was hands on in leading the team while implementing new technologies such as:
- Content management system
- Email service provider
- Upgraded ad serving platform
- Collaboration tools
- Complete refresh of all IT and Technology assets from end user systems to data center equipment
(Privately Held; Information Technology and Services industry)
September 2007 — September 2008 (1 year 1 month)
Provide industry knowledge and insights to benefit Tiburon Enterprises and clients. Met with senior management to discuss service offerings and how to best serve the needs of the Tiburon's clients while growing the organization.
(Public Company; DIS; Information Technology and Services industry)
October 2007 — July 2008 (10 months)
Tasked with maturing the Information Security Operations department and implementing application security for the Walt Disney Interactive Media Group (formerly known as the Walt Disney Internet Group or WDIG).
While in this position, I mentored staff, streamlined departmental operations, and improved integration of information security tasks and processes with other departments within the company.
Key achievements:
- Managed technical assessment and remediation of PCI directives
- Led the incident response team
- Implemented application security functions including source code auditing and web application vulnerability scanning
- Implemented a vulnerability management program which accounts for environmental factors and risk justifications
- Automated key departmental processes
Worked with legal and compliance on various compliance and regulations including:
- PCI
- SOX
- IAB
- COPA
- Safe Harbor/EU Data Protection Directive
(Public Company; TRXI; Information Technology and Services industry)
October 2006 — September 2007 (1 year )
About TRX:
TRX is a leader in data processing and fulfillment services. Notable clients included Expedia, American Express, Hotwire, and Citi.
Under the shared direction of the COO, CFO, and CTO, I led information security and risk management activities globally including operations in the United States, Germany, United Kingdom, and India.
During this time, I developed and implemented a strategic roadmap for information security, routinely worked closely with clients, and clients of clients, to ensure data security met client requirements, and worked with clients, vendors, auditors, and other concerned parties to meet compliance standards and regulations including:
- PCI
- HIPAA
- Safe Harbor/EU Data Protection Directive
- Sarbanes Oxley
- ISO 27001
- ARC
Additionally, I managed, mentored, and developed staff, provided organization awareness and "internal sales" of the importance of a risk based and balanced and successful information security program, and often presented to executive management on the state of compliance, risk management, and information security.
(Automotive industry)
December 2005 — May 2007 (1 year 6 months)
Investor in a leading online Mitsubishi Evolution community focused on collaboration of owners, enhancing automotive innovation, and connecting vendors and consumers of Evolution automotive merchandise. Advised the company on:
- User acquisition and retention strategy
- Strategic partnerships with vendors, resellers, and similar properties
- Technology
- Revenue strategy and growth
- Exit strategy
EVOwned was acquired in May 2007.
(Public Company; TRXI; Information Technology and Services industry)
March 2000 — October 2006 (6 years 8 months)
Created the Information Security team and served as the lead until being promoted to Manager.
Accomplishments:
- Implemented technical controls such as IDS, IPS, file encryption, SIEM, secure file transfer technologies, log monitoring, web filtering, custom applications to monitor CCTV and door access systems
- Developed a third party security assessment process
- Developed and led implemention of security policies, guidelines, and standards
- Performed network and application penetration tests
- Performed vulnerability assessments
- Performed source code audits
- Developed and delivered secure coding training to developers
- Developed and delivered security testing training to QA staff
- Led incident response and technology fraud investigations
(Privately Held; 1-10 employees; Information Technology and Services industry)
November 2001 — July 2006 (4 years 9 months)
MBA ,