
Sr. Security Architect, Cardinal Health
Columbus, Ohio Area

Sr. Security Architect, Cardinal Health
Columbus, Ohio Area
CISSP CISM ISSAP RHCE SSCP CCP MBA CITP MBCS
Identity management/AAA, security architecture, Federated identity, third-party trust, trust modeling, certification & accreditation, cryptography, risk management, disappearing perimeter, future-state IDS/IPS, authentication modeling, BASEL 2
(Non-Profit; 11-50 employees; Internet industry)
January 2009 — Present (7 months)
Member, Board of Directors
(Public Company; 10,001 or more employees; CAH; Hospital & Health Care industry)
October 2007 — Present (1 year 10 months)
(Partnership; 1-10 employees; Renewables & Environment industry)
March 2006 — Present (3 years 5 months)
Focusing on renewable fuels, in particular, biodiesel. This includes:
¤ Enabling homebrew biodiesel
¤ Biodiesel education & clearinghouse
¤ Community support for biodiesel initiatives
¤ Enabling cooperative production & distribution of biofuels
¤ Biodiesel & renewable fuel lobbying and legislative support
http://midohiobio.com
(Non-Profit; 1-10 employees; Non-Profit Organization Management industry)
October 2000 — Present (8 years 10 months)
Various positions, including Director of Education, Vice President, and Treasurer.
Developed and lead successful CISSP training program, training hundreds of CISSPs in the Columbus area.
Principal Instructor, teaching:
¤ Cryptography
¤ Security Architecture
¤ Security Operations
¤ Network & Telecommunications
¤ Authentication & Access Management
¤ Privacy, Law & Ethics
¤ Business Continuity/Disaster Recovery.
Active role in the team that helped grow the chapter from 50 to 280 in 6 years.
Founded ISSA scholarship program
(Public Company; 10,001 or more employees; HBAN; Banking industry)
August 2006 — October 2007 (1 year 3 months)
(Public Company; 10,001 or more employees; Financial Services industry)
September 2005 — August 2006 (1 year)
· Design and operations of multiple SSO and federated identity SAML solutions using FIM and ClearTrust.
· Development of architecture and design deliverables for enterprise-class WAM, SSO and FIM platform.
· Risk management and operational readiness assessment lead.
(Public Company; 10,001 or more employees; NFS; Financial Services industry)
June 2000 — August 2005 (5 years 3 months)
· Certification & Accreditation of financial applications and infrastructure.
· Extensive risk analysis.
· Cryptographic analysis and implementation, cryptosystem design, cryptanalysis, key design and implementation, crypto RFP development & procurement, PRNG and RNG development, crypto consulting.
· Development of 5 patent-pending risk management technologies and protocols.
· Project management and consulting.
· Mentoring, training, and leadership roles.
(Non-Profit; 51-200 employees; Higher Education industry)
February 1999 — June 2000 (1 year 5 months)
· Responsible for complete infrastructure operations and engineering.
· Specified and directed major network redesign.
· Policy development & governance.
· CIRT, DRP, firewalls, etc.
(Privately Held; 201-500 employees; Financial Services industry)
December 1996 — February 1999 (2 years 3 months)
Many roles for BMWFS, including:
· Data Center operations lead and technician.
· Y2k project manager
· Software license compliance auditor
· Disaster recovery/CIRT lead
· QA testing/change control lead
· Development & training in variety of technical and business skills areas
(Public Company; 1001-5000 employees; CPWR; Management Consulting industry)
February 1992 — December 1996 (4 years 11 months)
· Consultant to three major banks and financial services organizations.
· Performed all SDLC functions, womb to tomb. Seriously.
· n-tier client/server development in CASE tools and scripting languages (OS/2, Windows, Netware, Unix & OS/390 platforms).
· Supervised production support groups as a team lead. Trained staff, supervised operations, and developed procedures, guidelines, and policies.
(Computer & Network Security industry)
1988 — 1992 (4 years)
(Public Company; Telecommunications industry)
June 1991 — February 1992 (9 months)
· Planned and coordinated Comprehensive Testing Phase of major project (Gantt, PERT).
· Created master schedule to organize testing activities of 54 testers on 10 major subsystems into one integrated, cohesive plan.
· Developed detailed specifications and test cases for telephony trouble processing systems, 3-tier client/server.
MBA , Business Admin/MIS , September 1999 — December 2001
Marketing consulting project with Nationwide Insurance.
1984 — 1988
Information Systems Security Association (ISSA)
RSA Program Committee
Beta Gamma Sigma
(ISC)²
ISACA
CISSP-ISSAP
CISM
CISA
MBA
Beta Gamma Sigma
CITP
Distinguished Toastmaster (DTM)