
Information Security and Privacy "Swiss Army Knife" (CISSP-ISSAP / ISSEP / ISSMP ● CISA / CISM ● GCFW / GSEC / GISP)
Dallas/Fort Worth Area

Information Security and Privacy "Swiss Army Knife" (CISSP-ISSAP / ISSEP / ISSMP ● CISA / CISM ● GCFW / GSEC / GISP)
Dallas/Fort Worth Area
Open Networker / LION / Toplinked.com -- Im always looking for new INFOSEC contacts to exchange security knowledge and opportunities
<<<<- ->>>>
Dynamic Customer Service oriented IT security specialist with a myriad of notable success designing, building, auditing, managing and the advanced troubleshooting of a broad range of security technology initiatives in a multi-customer corporate security environment.
-- Ennea-Certified Security Professional with 12+ years of extensive hands-on experience leading all stages of security system development efforts throughout the entire SDLC (including requirements definition, audit/risk assessment, design architecture, implementation/testing, certification/accreditation, ongoing support, and final disposal.)
-- In-depth technical knowledge with the ability to troubleshoot and diagnose creative solutions to unique problems and customer business and technical requirements.
-- Real world working experience with meeting and exceeding internal security controls, industry best practices, SOX, PCI, HIPAA security, ISO9001 quality compliance standards, and global privacy laws.
-- Practical experience in the definition, development and direction of information security strategy, policy, and programs guiding processes and people.
-- Self starting performer with excellent written, verbal and collaborative communication skills.
-- Outstanding leadership abilities; able to coordinate and direct all phases of project-based efforts while managing, motivating, and leading project teams.
-- As of 12/2008 – out of 60,000 CISSP’s in the world, 1 of only 20 who possess all three advanced ISC2 Concentration Certifications for Security Architecture (ISSAP), Security Engineering (ISSEP), and Security Management (ISSMP).
-- Open to new purposeful opportunities on a cohesive team with a solid success through employee growth, a ‘first time right’ focus, and a sense of tangible accomplishment at the end of the work day.
Core Security Business Competencies Include: Security Management, Architecture & Infrastructure Design, Change & Configuration Control, Problem & Root Cause Management, Risk Management, Strategic & Tactical Planning, Disaster Recovery & Business Continuity, Legal & Regulatory Compliance, and Audit Compliance throughout the entire SDLC.
Core Security Technical Competencies Include: Network, Firewall, Desktop/Server, DLP/Content Monitoring, IDS, Antivirus, SIEM (among many other technologies)
(Public Company; Hospital & Health Care industry)
March 2009 — Present (9 months)
Expert for all things Information Security and Privacy within the USPI Organization. Routinely developing, maintaining and leading enhancements to the USPI Information Security infrastructure. Performing monthly and quarterly compliance control audits. Continually developing, maintaining and enhancing internal security policies while balancing the needs of HIPAA, SOX, PCI, JCI, RedFlag and other legislative requirements. Providing business and in-depth expert security advice on information security trends, issues, and risks. Risk Assessment, Review, and Certification of new/existing applications and services.
(Civic & Social Organization industry)
January 2005 — Present (4 years 11 months)
When I hear of a just cause that needs something done, I lend a hand. Simple as that.
(Public Company; HPQ; Information Technology and Services industry)
July 2006 — March 2009 (2 years 9 months)
Security solution engineering, implementation, and ongoing support of new ESEM (SIEM) customers and sites for PCI, HIPAA, SOX and internal security control audit compliance. (From the firewall, network and server perspectives)
(Non-Profit Organization Management industry)
January 2005 — February 2008 (3 years 2 months)
(Public Company; 10,001 or more employees; HP; Information Technology and Services industry)
July 2006 — October 2007 (1 year 4 months)
In a parallel role with my regular duties, was recruited to perform an 18 site enterprisewide firewall security risk audit and lockdown of a ‘Billion Dollar’ European Financial Customer's network perimeter.
(Public Company; 10,001 or more employees; HP; Information Technology and Services industry)
July 2005 — July 2006 (1 year 1 month)
Recruited to help architect a Data Leak Protection/Content Monitoring and Management (DLP/CMM) managed service offering to be sold to both internal and external customers. Integrated DLP/CMM offering to existing Threat and Vulnerability Management (TVM) team offerings for automated alert management, incident investigation, and escalation. For long-term lifecycle support of future DLP/CMM offering solutions, developed key support processes and training plans. Provided DLP/CMM consulting for customer solutions required prior to release of an internal EDS solution.
(Public Company; 10,001 or more employees; HP; Information Technology and Services industry)
November 2000 — July 2005 (4 years 9 months)
Tapped to provide full firewall security solution engineering, enterprise risk assessing and support for both internal and external customers. Also routinely provided on-call third level troubleshooting for firewall, VPN, network devices, and all applications utilized across secured connections. As Team Technical lead, tasked with reviewing/approving solutions from other engineers on team and security engineering of high profile/high-risk solutions requiring unique attention. Performed security audits and ‘phased lockdowns’ of legacy ‘open’ perimeter customer network connections.
(Public Company; 10,001 or more employees; HP; Information Technology and Services industry)
May 1998 — November 2000 (2 years 7 months)
Recruited to provide second level advanced desktop/server support for both internal and external customers. Daily troubleshooting duties included RAS/VPN service clients and security network infrastructure, as well as all user applications utilized across active connections. Team Technical lead, providing training and third level advanced diagnostic troubleshooting on unique customer impacting problems whether they were RAS/VPN related or not.
(Public Company; 10,001 or more employees; HP; Information Technology and Services industry)
January 1997 — May 1998 (1 year 5 months)
This was my ground floor opportunity within EDS. While initially providing processing of print outputs for various customers, position quickly grew to also include quality control and technical support responsibilities.
Criminal Justice 1992 — 1993
2009
Traveling, Volunteering, Music, Animals, Psychology and Philosophy of Why People Do Things, Movies, Just about Anything Outdoors, Photography
ISC2
ISACA
ISSA
SANS/GIAC
(CISSP) Certified Information Systems Security Professional, Certification 97309
(ISSAP) Information Systems Security Architecture Professional, Certification 97309
(ISSEP) Information Systems Security Engineering Professional, Certification 97309
(ISSMP) Information Systems Security Management Professional, Certification 97309
(CISA) Certified Information Systems Auditor, Certification 758300
(CISM) Certified Information Systems Manager, Certification 808996
(GCFW) GIAC Certified Firewall Analyst, Certification 2628
(GSEC) GIAC Security Essentials Certification, Certification 16548
(GISP) GIAC Information Security Professional, Certification 768