
Enterprise Security Architect at NAG
Glasgow, United Kingdom

Enterprise Security Architect at NAG
Glasgow, United Kingdom
I have over 17 years of IT experience in Financial Services and currently serve as National Australia Group's Enterprise Security Architect. Working closely with key Business & Technology stakeholders, I have overall responsibility for defining the security architecture for NAG's UK business units as well as setting the strategic direction of common IT services delivered to staff & customers. I also provide security education and leadership to NAG's IT development & delivery teams within the UK.
I previously served as NAG UK's Technology Security Manager with responsibility for the management of security threats across our UK business units. By building and running a small focussed team of skilled technicians, I introduced robust security incident management & threat assessment processes & toolsets to deliver exponential reduction in Business downtime as a result of security threats.
I am a proven people manager, IT technician, IT security professional and IT architect with real world experience in a financial organisation that thrives on new & difficult challenges.
I have a proven track record delivering valued engagement between business & IT stakeholders at executive (C-level) and below.
I recently addressed the IDM2009 conference in London, delivering a case study on successful Single Sign-On within NAG UK to critical acclaim. Martin Veitch of CIO magazine posted an article discussing the conference, highlighting my address in particular (http://www.cio.co.uk/opinion/veitch/2009/11/05/identity-management-still-seeking-a-sense-of-identity/)
Information Security Policy, Operational Risk & Regulatory Compliance, Security Threat Management, Security Management Technologies (IDS, Firewalls, Vulnerability Assessment, SIEM etc), IT Audit, Identity Management (including Directory Management, User Provisioning, Identity Lifecycle Management, PKI & Authentication), Fraud Management, IT Security Architecture (including definition of strategic principles, policies, guidelines & standards)
(Public Company; 10,001 or more employees; Financial Services industry)
June 2007 — Present (2 years 6 months)
(Public Company; 10,001 or more employees; Banking industry)
November 2006 — June 2007 (8 months)
I am responsible for two teams of people, totalling 9 individuals. The two teams are i) Security Administration and ii) Technical Security. These teams provide a number of important services to NAG UK, including management of Firewalls, IDS systems, Privileged User Admin, Security Monitoring, Threat Management, Certificate Management and much more.
(Public Company; 10,001 or more employees; Banking industry)
January 2004 — November 2006 (2 years 11 months)
I was responsible for managing a team of people who co-ordinated the Risk, Compliance, Audit and Threat Management activities for NAG UK Technology.
(Public Company; 10,001 or more employees; Banking industry)
October 1999 — December 2003 (4 years 3 months)
(Public Company; 10,001 or more employees; Banking industry)
April 1997 — October 1999 (2 years 7 months)
(Public Company; 10,001 or more employees; Banking industry)
April 1994 — April 1997 (3 years 1 month)
(Public Company; 10,001 or more employees; Banking industry)
September 1992 — April 1994 (1 year 8 months)
B.Sc.Hons , Computing Science , 1988 — 1992