IT Security Analyst
Ireland
IT Security Analyst
Ireland
I have worked as a Security Professional in two of the largest companies in the industry, first at Symantec and currently at Trend Micro. I have a lot of interest in Computer and Network Security and Malware analysis.
I am a Mentor for the SANS Incident Handling and Hacker Exploits Certificate (GCIH) and also for their Security Essentials Certificate (GSEC), as well as being a member of the SANS Advisory Board.
I have a lot of Presentation Experience in the Security field, a lot of which was Press related. I also have gathered a lot of knowledge and experience in Malware Analysis and Security research in general.
Professional Qualifications (More Details Below)
CISSP
GCIH
GREM
GSEC
Groups:
SANS Mentor for GCIH and GSEC
Member of the SANS Advisory Board
(Public Company; TYO: 4704; Computer Software industry)
August 2007 — Present (2 years 4 months)
• Research into advanced threats and design of systems to monitor and protect against them, including Future Threat Landscapes..
• Gathering Intelligence about European targeted malware attacks
• Giving regular presentations (internal and external) for Press, Sales, Marketing and at Security Conferences.
• Publication of Security related White papers and articles
• Development of tools / systems for malware analysis
• Give Training on current threat landscape
• Regular writer for the Trend Micro weblog (http://blog.trendmicro.com)
• Have featured in interviews in several newspapers including Irish Examiner, Irish Independant, The Guardian and USA Today
• Speaker at several security conferences including Mneumonic RISK 2008 and VB 2009.
• Promoted to Senior AntiVirus Specialist after 6 months with the company.
(Privately Held; Computer & Network Security industry)
2006 — Present (3 years )
I have delivered several SANS courses in Dublin and Cork (Ireland), and plan delivering more in the future for both the GIAC Incident Handling and Hacker Exploits course (GCIH) and the GIAC Security Essentials course (GSEC). These courses are delivered in either the traditional 6-day Instructor format, or alternatively the Mentor format (over 10 weeks)
(Public Company; 10,001 or more employees; SYMC; Information Technology and Services industry)
November 2004 — August 2007 (2 years 10 months)
• Identification / Analysis of latest Malware threats.
• Testing of Anti-Virus signatures for all Symantec products.
• Testing of Threat Writeups for Symantec’s website.
• Design of a system for input & indexing of several hundred gigabytes of software for prevention of false positive detections.
• Design of a large international PHP/MySQL database system for test results input and Metrics generation.
• Responsible for all Mobile Threat QA Analysis for Symantec & developed analysis tools and procedure docs for threats targeting Symbian and Windows Mobile Operating Systems.
• Producing reports on competitive testing of Symantec’s products
• Creation of documented QA Testing Practices & Procedures
• Creation of weekly and monthly Metrics reports.
• Regular presentations on Mobile Threat landscape for visiting local, European and International Journalists.
• Training of QA members in Dublin and abroad.
• Often called on to test on less used and less familiar systems.
SANS GSEC , SANS GIAC Security Essentials Certification , 2008 — 2008
From the SANS GSEC Website Description:
" Security Professionals that want to fill the gaps in their understanding of technical information security and demonstrate they are qualified for hands on roles with IT systems with respect to security tasks. This is also appropriate for hands on, technically oriented managers that want to understand information security beyond simple terminology and concepts; anyone new to information security with some background in information systems and networking.
GIAC Security Essentials Certification graduates have been taught the knowledge, skills and abilities required to incorporate good information security practice in any organization. The GSEC tests the essential knowledge and skills required of any individual with security responsibilities within an organization."
Website: http://www.giac.org/certifications/security/gsec.php
CISSP , Certified Information Systems Security Professional , 2007 — 2007
From the CISSP Website Description:
"Global Recognition for Top Information Security Professionals
As the first ANSI ISO accredited credential in the field of information security, the Certified Information Systems Security Professional (CISSP®) certification provides information security professionals with not only an objective measure of competence but a globally recognized standard of achievement. The CISSP credential demonstrates competence in the 10 domains of the (ISC)² CISSP® CBK®.
CISSP® CBK® Domains
- Access Control
- Application Security
- Business Continuity and Disaster Recovery Planning
- Cryptography
- Information Security and Risk Management
- Legal, Regulations, Compliance and Investigations
- Operations Security
- Physical (Environmental) Security
- Security Architecture and Design
- Telecommunications and Network Security"
Website: https://www.isc2.org/cgi-bin/content.cgi?category=1331
SANS GREM , SANS GIAC Reverse Engineering Malware , 2007 — 2007
From the SANS GREM Website Description:
" System and Network Administrators, Auditors, Security Consultants, and Security Managers responsible for protecting the organization from malicious code
The GIAC Reverse Engineering Malware (GREM) certificate is designed for technologists who protect the organization from malicious code. The certificate focuses on tools and techniques for analyzing malicious software such as viruses, worms, and trojans. Students are asked to try their hand at studying malware using system monitoring tools, a disassembler, and a debugger in a controlled environment. When performing the analysis, students study the program's behavioral patterns, and look at portions of its assembly code. This advanced, technical program expects the students to be familiar with using Windows and Linux operating environments, and to understand programming concepts such as stacks and function calls."
Website: http://www.giac.org/certifications/description/grem.php
SANS GCIH , SANS Incident Handling and Hacker Exploits , 2006 — 2006
From the SANS GCIH Description:
"Individuals responsible for incident handling/incident response; individuals who require an understanding of the current threats to systems and networks, along with effective countermeasures.
GIAC Certified Incident Handlers (GCIHs) have the knowledge, skills, and abilities to manage incidents; to understand common attack techniques and tools; and to defend against and/or respond to such attacks when they occur."
Website: http://www.giac.org/certifications/security/gcih.php
M.Sc. Security and Forensics Computing , Computer Forensics, Computer Security , 2003 — 2004
Practicum: Open Source Security Technologies
Course Included Cyptography, Forensics, Secure Coding, Security Protocols, Biometrics, Network / OS Security.
Full Course Details: http://www.dcu.ie/prospective/deginfo.php?classname=MSSF&mode=full
B.A. Computer Science , Computer Science, Programming, Software Design, Computer Hardware , 1999 — 2003
Course included Programming (C++, Java, Eiffel, Level 5), Networking, Operating Systems, Win32 Assembly, Digital Logic Design, Algorithms, Computer Architecture, Electrotechnology, Computer Vision, Computer Graphics
Full Details: https://www.cs.tcd.ie/courses/ba/
- SANS Advisory Board
- SAN Instructor / Mentor Program (GCIH and GSEC)
- CISSP (Certified Information Systems Security Professional)
- CISSP (Certified Information Systems Security Professional)
- SANS GCIH (Incident Handling and Hacker Exploits)
- SANS GREM (Reverse Engineering Malware)
- SANS GSEC (Security Essentials)