
InfoSec Investigations Manager@Cisco Systems
Raleigh-Durham, North Carolina Area

InfoSec Investigations Manager@Cisco Systems
Raleigh-Durham, North Carolina Area
Martin Nystrom is a Member of Technical Staff (MTS) for the Computer Security Incident Response Team (CSIRT) at Cisco Systems. He leads the global security monitoring team and provides guidance for incident response and security initiatives. Prior to joining Cisco's CSIRT, he was responsible for designing and consulting on secure architectures for IT projects. Martin worked as an IT architect and a Java programmer for 12 years prior, where he built his experience in the pharmaceutical and computer industries. He received a bachelor's degree from Iowa State University in 1990, a master's degree from NC State University in 2003, and his CISSP certification in 2004.
He is the author of O'Reilly's "SQL Injection Defenses", and the forthcoming, "Security Monitoring". He is a frequent conference speaker, and was honored on the Java One Rock Star Wall of Fame. He enjoys speaking at FIRST and Cisco Networkers conferences, and providing security guidance to customers via Cisco's Executive Briefing Program.
Most of Martin's papers and presos can be found on his web site at xianshield.org
* incident response
* application security
* network monitoring
* host monitoring
* security consulting
* teaching on security practices
* customer engagements/presentations
* designing/deploying enterprise web applications
* Java application development
(Public Company; 10,001 or more employees; CSCO; Computer Networking industry)
August 2005 — Present (4 years 4 months)
Design and drive improvements to information security monitoring and incident response. Lead initiatives to improve preparedness and methods for responding to security breaches. Serve as escalation point for analyzing and resolving potential security breaches discovered by monitoring staff.
(Public Company; 10,001 or more employees; CSCO; Computer Networking industry)
July 2002 — August 2005 (3 years 2 months)
Provide security direction for Cisco projects. Specializing in web security, consult with IT project teams to provide secure architecture for large projects. Write policy and standards documents to address secure programming and deployment.
(Public Company; 10,001 or more employees; CSCO; Computer Networking industry)
June 2000 — July 2002 (2 years 2 months)
Provide technical direction to team of engineers. Act as consultant to business clients in exploring concepts for new applications. Provide architectural approach guidance to Sales IT Architecture Team. Size and deliver tool enhancements and integration efforts. Develop and articulate technical vision. Mentor engineers through coaching, training, and helping them through technical challenges.
(Public Company; 51-200 employees; Biotechnology industry)
July 1996 — June 2000 (4 years )
(Public Company; 10,001 or more employees; LLY; Biotechnology industry)
June 1996 — June 2000 (4 years 1 month)
Research tools and techniques for software development. Articulate guidelines, languages, tools for software development. Mentor developers in use of architecture-sanctioned technology. Select contractors for projects. Establish training plans for staff. Conduct proof-of-concept testing on various technologies (Java stored procedures, iPlanet, O/R frameworks, etc.). Help developers launch projects by participating in first development cycles.
(Public Company; 10,001 or more employees; LLY; Pharmaceuticals industry)
June 1993 — June 1996 (3 years 1 month)
Developed system for global help desk and support. Created system using Remedy ARS toolkit on Sun Solaris servers. Integrated software with e-mail and paging applications for notification.
(Public Company; 10,001 or more employees; LLY; Pharmaceuticals industry)
January 1991 — June 1993 (2 years 6 months)
Administered MVS based problem tracking application. Developed policies and procedures for enterprise-wide problem tracking and change management. Developed system to enable new enterprise-wide processes. Developed interface to electronic mail system. Integrated system with VM and electronic forms.
(Public Company; 10,001 or more employees; IBM; Computer Hardware industry)
June 1990 — August 1990 (3 months)
Wrote senior mangement measurement reports using PL/I and DB2
(Public Company; 10,001 or more employees; IBM; Computer Hardware industry)
June 1989 — December 1989 (7 months)
Modified assembly-line PL/I programs that ran against IMS database
Master of Engineering , Computer Science , August 2001 — August 2003
BA , Management Information Systems, Economics , August 1986 — December 1990
home networking & security, raising large families :-), Christianity
CISSP, FIRST
• Invited speaker, OreDev developer conference (Sweden), 2005
• Top speaker award, International Java One Conference, 2005
• Guest lecturer, Infragard Denver, Eastern Carolina Infragard, 2005
• Guest lecturer, Mississippi State University, Iowa State University, Florida State University – 2003
• Numerous team achievement awards (CAPs) for outstanding work on projects
• Presenter, Triangle Java User’s Group (“Web Security”) – 2003