VP of Information Security at EVO Merchant Services, CISSP / CISM
Greater New York City Area
VP of Information Security at EVO Merchant Services, CISSP / CISM
Greater New York City Area
Dynamic Information Security leader with over ten years of experience in numerous exciting positions. I have hands-on knowledge of the entire project life-cycle process, from specification and requirements through evaluation, purchasing, implementation, and ongoing support.
I have extensive experience with hardware, software, and network technologies with a specific focus on securing highly-available, real-time, internet-based services. I excel at developing Information Security policy and procedures as well as navigating companies through complicated security audit processes (ISO27001 and PCI DSS). My recent focus has been on Policy Development, Compliance, Regulatory Issues, Business Continuity Planing, and Disaster Recovery Planning.
In 2006 I was interviewed by Alan Paller, Director of Research for the SANS Institute for a print interview and webcast titled: "What Works in Intrusion Detection: Monitoring Unique Traffic with Retail Decisions." - www.sans.org
During Summer 2006 I mentored the SANS Security Class 504: "Hacker Techniques, Exploits, and Incident Handling" at Rutgers University.
email: john@abella.net
(Privately Held; Financial Services industry)
July 2009 — Present (5 months)
(Privately Held; Publishing industry)
2007 — Present (2 years )
--
-- This is not my full-time job. See EVO Merchant Services, above.
--
As a Faculty Member for the Institute for Applied Network Security, I get to lead real-world tactical and strategic InfoSec discussions with Fortune 1000 staff up to the CIO / CISO level. Designed to be conversational, the Institute Forums are not typical PowerPoint lectures; the attendees are active participants.
In 2007 I presented at a number of Institute Forums on the following topics:
- Network Architecture Best Practices
- Advanced SIM Management
- Enterprise Network Defense
- Configuration and Patch Management
- Selecting and Purchasing an Intrusion Detection System
- Regulatory Compliance, E-Discovery, and Records Management
- PCI Compliance and updates to the PCI DSS 1.1
(Privately Held; Financial Services industry)
June 2001 — June 2009 (8 years 1 month)
(Privately Held; 51-200 employees; Information Technology and Services industry)
1999 — 2001 (2 years )
(Privately Held; Information Technology and Services industry)
1998 — 1999 (1 year )
B.S. , 1994 — 1998
Faculty Member - The Institute for Applied Network Security
ISACA - Member
Sun Services Advisory Panel - Board Member
FBI Infragard Member - Newark Chapter
SANS Mentor
Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GIAC Certified Incident Handler (GCIH)