
Security Analyst and Software Engineer
San Antonio, Texas Area

Security Analyst and Software Engineer
San Antonio, Texas Area
Secure Software Engineer and team lead with a mature depth of experience in new system design, security analysis, software engineering and project management in both the high tech and federal spaces.
Security analysis, architecture design, web application development, Java, .NET, database design, data modeling
(Privately Held; Financial Services industry)
July 2007 — Present (2 years 1 month)
Responsible for technical implementation of security solution. Develop security-related reporting and monitoring solutions using Java, J2EE and C#. Recently received award for development of a production access system reporting solution.
(Public Company; 10,001 or more employees; SAI; Information Technology and Services industry)
February 2000 — July 2007 (7 years 6 months)
Information Assurance Security Officer for Software Development (IASO-SD) with the following responsbilities:
• Met requirements of DoD directive 8570.1
• Responsible for DITSCAP/DIACAP effort for software development section
• Wrote coding guidelines for development section based on DoD regulation 8500.1, HIPAA and related Security Technical Implementation Guides (STIGs)
• Created design for migrating building from wired LAN to wireless in accordance with DoD directive 8100.1 and FIPS 140-2
• Reviewed all code, databases, and servers per DoD directive 5200.40 and NIST SP 800.53
• Architect, project manager and lead developer for several enterprise-wide ASP and .NET solutions as consultant for Air Force and Army
(Public Company; DELL; Computer Hardware industry)
April 1999 — February 2000 (11 months)
Some examples:
• Led project to refactor C++ high-capacity data loaders into Java and PL/SQL solution
• Designed and developed manufacturing data monitoring solution
• Managed Linux servers and source control repository for development group
• Designed and updated mid-tier business rule components
(Privately Held; 1001-5000 employees; Telecommunications industry)
January 1995 — April 1999 (4 years 4 months)
USR was later bought out by 3Com. Worked as Quality Assurance Analyst for R&D, modem division. Created and ran tests for DSP code. Developed several ASP web applications for intranet. Mac specialist for technical support group.
(Public Company; 10,001 or more employees; MOT; Telecommunications industry)
March 1998 — April 1999 (1 year 2 months)
Managed internet development team for government products marketing group. Architect and lead developer of several enterprise ASP/SQL Server applications.
MS , Information Technology , 2002 — 2006
Infrastructure Assurance concentration.
UTSA was redesignated a National Center of Academic Excellence in Information Assurance Education by the National Security Agency and the Department of Homeland Security.
BA , Writing and film , 1988 — 1992
Got into a couple film festivals and got some stuff published.
Information Systems Security Association (ISSA)
Certified Secure Software Lifecycle Professional (CSSLP)
Certified Information Systems Security Professional (CISSP)
Sun Certified Java Programmer (SCJP)
NT Innovator of the Year, Windows NT Magazine
Published chapter "ASP Primer" in book Webdeveloper's Sourcebook