
Information Security Professional
Greater Denver Area

Information Security Professional
Greater Denver Area
An Information Security Professional, Business Owner and IT Consultant with 14 years in Information Technology and 10 years dedicated to Information Security.
Security Governance
Government Liaison
Security Architecture
Forensic Analysis
IT Consulting
Compliance and Remediation
Risk Management
Firewalls, Monitoring, IDS/IPS
eCommerce, Web Services, Web Programming (VB.net, javascript, HTML, etc.)
Security Regulation and Law
Vulnerability and Penetration Testing
Anything Microsoft
Small and Medium Business IT
(Public Company; 1001-5000 employees; LEAP; Telecommunications industry)
February 2008 — Present (8 months)
(Privately Held; 1-10 employees; Information Technology and Services industry)
June 2004 — Present (4 years 4 months)
(Public Company; 10,001 or more employees; Banking industry)
December 2006 — September 2007 (10 months)
(Public Company; 5001-10,000 employees; Hospital & Health Care industry)
August 2005 — January 2006 (6 months)
As an Information Security Architect I was responsble for developing secure IT architectures, ISO17799 compliant security policy and assisting compliance activites related to HIPAA, SOX, corporate policy.
(Public Company; 10,001 or more employees; FDC; Information Technology and Services industry)
2001 — 2005 (4 years)
Established the Information Security Governance Group to ensure regulatory and internal security compliance. Responsible for the management of personnel and operations related to regulatory compliance, policy development and application of security standards across the enterprise.
Developed ISO17799:2000 compliant security policies, standards, and processes based on government methodologies for life-cycle management. Mapped internal policies to regulatory requirements for PCI, GLBA, HIPAA and Sarbanes Oxley.
Responsible for communications, risk management and security compliance for the Electronic Federal Tax Payment System (EFTPS), (a U.S. Department of the Treasury Information System), and the State of California Disbursement Unit.
Directed U.S. Government Security Certification and Accreditation (C&A), Subject Test and Evaluation (ST&E), Security Planning, Security Assessments, Security Analysis, Risk Mitigation, and Government communications
(Information Technology and Services industry)
2000 — 2001 (1 year)
Managed consultative engagements including personnel, budgets, sales and proposals for the implementation and assessment of secure information systems for many large companies within technology, finance and health care industries.
Consulted companies in HIPAA regulatory compliance, risk mitigation and the implementation of secure solutions designed to meet requirements and maintain compliance.
Conducted vulnerability and risk assessments, penetration testing, and policy compliance reviews in relation to regulatory compliance and security best practices.
Generated alliances with major business partners in order to generate sales leads to open new channels of revenue for existing and newly combined services.
(Information Technology and Services industry)
1998 — 2001 (3 years)
(Information Technology and Services industry)
1998 — 2001 (3 years)
Founded and managed the Rush Creek Security Solutions Team comprised of six security consultants and responsible for all Information Security engagements. Consultative revenue increased more than 50% with the introduction of security focused services.
Simultaneously managed the Security Solutions Team and over 50 business accounts supporting network infrastructure, design, security, and systems administration.
Implemented WAN and LAN solutions, including remote access, authentication and firewalls, utilizing Cisco, Checkpoint and Nortel network hardware and Microsoft operating systems.
Responsible for the development of policies, procedures and methodologies related to security assessments, risk analysis, network design and implementation.
CIS, Information Systems and Business Management, 1993 — 2008
CISM, 2005 — 2005
IAM/IEM, 2002 — 2003
CISSP, 2000 — 2000
Computers, Motorcycles, Snowboarding, Travel, Security, Technology, Modding, Web Development, Manufacturing, Mechanical Engineering
ISC2, ISACA, ISSA, BlackHat/Defcon, NSA
• Awarded Web Developer Certification in 2007 (15 Credit Hours)
• Awarded Programmer/Analyst in Information Systems Certification in 2007 (15 Credit Hours)