Information Security at Northwestern Mutual
Greater Milwaukee Area
Information Security at Northwestern Mutual
Greater Milwaukee Area
I help clients understand and improve the security of their information systems so they can better protect their data and meet regulatory, contractual, and audit requirements.
* Information Security
* Information Assurance
* Risk Assessment
* Policies and Procedures
* IT Audit
* HIPAA
* SOX
* GLBA
* Title 21 CFR Part 11
* Penetration Testing
* Vulnerability Scanning
* Disaster Recover and Business Continuity Planning
* Computer Forensics
* Data Recovery
* Python
* Lisp
* Malware Investigations
* Security Awareness and Training
* ISO 17799, 27001, 27002
* Emacs and Elisp
(Privately Held; 10,001 or more employees; Financial Services industry)
June 2007 — Present (2 years 2 months)
In this position I provide Information Risk Management (IRM) consulting services, generally at the IS project level. Since June 2007 I have worked to: develop our IRM consulting process; conduct risk assessments and provide risk treatment recommendations; develop our information protection policies and standards; and much more.
(Computer & Network Security industry)
January 2007 — June 2007 (6 months)
Founder and president of a Glendale, Wisconsin, based information technology consultancy with a focus on security testing, IT audit and regulatory compliance.
(Partnership; 501-1000 employees; Accounting industry)
November 2005 — August 2006 (10 months)
Consulting - Technology Risk Services
(Government Agency; 10,001 or more employees; Military industry)
February 1981 — May 2005 (24 years 4 months)
Various roles in the U.S. Army Reserve over a 23+ year career, including Drill Sergeant (15 years) and Information Operations Analyst (3+ years).
(Public Company; 5001-10,000 employees; CBZ; Insurance industry)
July 2002 — January 2005 (2 years 7 months)
(Public Company; Insurance industry)
July 2002 — January 2005 (2 years 7 months)
(Computer & Network Security industry)
1982 — 2005 (23 years)
(Public Company; 1001-5000 employees; Insurance industry)
July 2002 — January 2004 (1 year 7 months)
Information Security Manger
(Public Company; 501-1000 employees; Computer & Network Security industry)
May 2001 — July 2002 (1 year 3 months)
Information Security Practice Lead
(Public Company; 501-1000 employees; Computer & Network Security industry)
January 2001 — May 2001 (5 months)
Information Security Practice Lead
(Partnership; 5001-10,000 employees; Management Consulting industry)
September 1998 — January 2001 (2 years 5 months)
Manager - Audit - Technology Risk Consulting (TRC), formerly called "Computer Risk Management" (CRM)
(Public Company; 501-1000 employees; Information Technology and Services industry)
1993 — 1995 (2 years)
Senior Consultant
(Computer & Network Security industry)
1992 — 1994 (2 years)
(Partnership; 5001-10,000 employees; Information Technology and Services industry)
1989 — 1992 (3 years)
Staff Consultant
(Privately Held; 11-50 employees; Information Technology and Services industry)
1986 — 1989 (3 years)
Sales Consultant
(Public Company; 11-50 employees; Computer Software industry)
1984 — 1986 (2 years)
National Sales of ExperLisp
(Computer & Network Security industry)
1980 — 1981 (1 year)
CISSP, ISSA, ISACA, Infragard