
Senior Security Consultant at BT
Greater New York City Area

Senior Security Consultant at BT
Greater New York City Area
Talented and accomplished security professional with passionate and innovative future-oriented vision, focusing on developing security and risk management as both an internal asset as well as a competitive advantage. Career incorporates complementary corporate and consulting roles, securing IT assets at domestic Fortune 1000 and global FT 2000 companies.
Proven track record of thoroughly analyzing security requirements and synthesizing the results into a set of initiatives and projects designed to protect company assets, facilitate business opportunities and maximize revenue in alignment with corporate goals.
As a QSA, recent experience includes significant work with PCI. In Dec. 2009, I will be helping a diversified health care company with their PCI DSS compliance effort.
Specializing in the financial services and aviation/airline sectors.
Author - Computer Security - 20 Things Every Employee Should Know (McGraw-Hill)
Contributing author - Network Security: The Complete Reference (Osborne)
Contributing author - The Handbook of Information Security Management (Auerbach)
I write a monthly security book review for Security Management magazine and Slashdot, and am a former columnist for Information Security, Unix Review and Solutions Integrator magazines.
Member of the InformationShield ‘Information Security Policy Expert Panel’ and Founding Member of the Cloud Security Alliance..
Professional affiliations: ISACA, New York Wings Club, ASIS, Technology Managers Forum, New York Metro & New Jersey InfraGard, CSI.
Frequent speaker at industry conferences, such as CSI, RSA, MISTI, NetSec and ISACA.
Current industry certifications: CISSP, PCI QSA, CISM, CISA, CCO, SITA, CGEIT
Expired certifications of years past include: MCP, CNE, CCSE, CCSA.
Information security, risk management, privacy, regulatory compliance, aviation, airline, Internet, firewalls, cryptography, PCI, CISSP, firewalls, risk assessment and mitigation, privacy, CISM, security policy, security processes.
(Public Company; BT.A; Telecommunications industry)
November 2006 — Present (3 years 2 months)
Currently on a security application assessment project at an international bank.
Waiting to start a project for a medical device manufacturer on the security of their remote patient devices.
Spoke at RSA 2009 in April. Scheduled to give a talk on Building a SOC at RSA Europe - October 2009.
Past projects:
International Food Manufacturer
Security policy & process creation
PCI remediation
Fine arts business
Wrote formal set of global infosec policies across 10 different domains. Worked with executives ensuring policies accurately met organizations goals & risks.
Healthcare provider
Security assessment & framework - Performed information security assessment. Created security framework & roadmap for creation of formal infosec program
Motion picture exhibitor - PCI compliance
Designed incident response plan & created remediation plans for PCI compliance
Braintree Payment Solutions
Wrote white paper - Smart Approach to PCI DSS Compliance
Lumension Security
Wrote white papers ‘The Best PCI Audit of Your Life: Are You Ready?’ & ‘HIPAA and Beyond: How to Effectively Safeguard Electronic Protected Health Information’
Baseball, aviation, marathon and long distance running.
ISACA, New York Wings Club, ASIS, Technology Managers Forum, New York Metro & New Jersey InfraGard, CSI.