
Sr. Staff Engineer, Security Evaluations Specialist
San Francisco Bay Area

Sr. Staff Engineer, Security Evaluations Specialist
San Francisco Bay Area
- Common Criteria Vendor Program Development and Legal Contracts facilitation with multiple project financial accountability (+ $1M)
- Common Criteria project management and full developer consultancy, including security target development, support and all developer evidence preparation
- Technical writing and web content development
- Seasoned unix generalist with over 25 years working in Unix based architechtures, 15 years in Windows based architechtures.
(Public Company; Computer & Network Security industry)
2008 — Present (1 year )
Security Evaluation Specialist. Prepare complex commercial IT security products for certification through NIAP, CESG, CSE or any other Internationally recognized schemes under the ISO 15408 Common Criteria. (EAL4 and MRPP) Work with engineering design teams to ensure product specifications meet ISO requirements. Track standards evolution and maintain gaps analysis to ensure products remain competitive. Prepare product Security Targets for BU evaluations, maintain schedules to align with engineering development, deliver CCTL-ready evidence, handle communication with CCTL labs, resolve any resulting discrepancies.
(Public Company; 10,001 or more employees; JAVA; Computer Hardware industry)
August 2001 — October 2008 (7 years 3 months)
Software Engineering and Program Manager for Solaris Common Criteria and FIPS140-2 Security Evaluations. Coordinate contractual and work arrangements with consultants, evaluators, laboratories and certification boards, manage cross-functional teams consisting of Sun and vendor engineers and project managers. Responsible for managing fiscal budgets of over $1.5M in NRE in related charges. Responsible for driving quality into future products by incorporating customer feedback collected through formal and informal channels.
(Public Company; 10,001 or more employees; SUNW; Computer Networking industry)
July 1999 — August 2001 (2 years 2 months)
Sr. Software Manager, Software Quality Engineering. Group was responsible for developing all automated tests for Solaris Security Products, including Trusted Solaris.
(Public Company; 10,001 or more employees; SUNW; Computer Networking industry)
January 1997 — July 1999 (2 years 7 months)
Engineering Manager, SQA. Manager of QA group in Developer Products responsible for running tests developed by QE department.
(Public Company; 10,001 or more employees; SUNW; Computer Networking industry)
May 1993 — January 1997 (3 years 9 months)
Software Test Engineer, printer products group
(Privately Held; 51-200 employees; Computer Hardware industry)
August 1986 — January 1989 (2 years 6 months)
Software Quality Assurance Engineer -
Perform software quality assurance for Tolerant Systems' Eternity Series product line running proprietary TX UNIX based operating system. (BSD 4.2) Responsible for testing all TX utilities, CISAM database, COBOL compiler, and fault tolerance capabilities.
USENET Administrator -
USENET administrator responsible for installing and maintaining USENET software on the corporate VAX 11/780. Set up and maintained 5 downstream newsfeeds, monitored upstream flow from 2 major sites. Provided internal and external support for USENET, UUCP and SENDMAIL / electronic mail problems.
(Public Company; 5001-10,000 employees; Information Technology and Services industry)
December 1984 — August 1986 (1 year 9 months)
Worked on a government contract providing systems operations and networking support for numerical simulation development project (project name NAS). Provided daily routine technical support for company's networked VAX systems and Silicon Graphics' workstations, negotiate timeshare for systems time with other sub-contractors.
(Public Company; 5001-10,000 employees; Computer Hardware industry)
March 1982 — December 1984 (2 years 10 months)
Perform software quality assurance on company's Series 6000 product line (Convergent Technologies OEM). Products of responsibility included word processors, desktop publishers and a package designed to handle UNIX administration through windowing interfaces.
networking and operating systems technology (especially personal gadgetry), the continuing evolution of the CCRA, Genealogy, American and European history, travel.