Security Consultant at Mandiant
San Francisco Bay Area
Security Consultant at Mandiant
San Francisco Bay Area
I am a full time Security Consultant with Mandiant. I am also completing my degree at Penn State University majoring in Information Science and Technology with a focus on System Design and Development, completing my degree part time through independent research. In addition, I am pursing the Information Assurance Option.
Network security, Unix Client Security, Unix Server Security, Windows Client Security, Active Directory, Group Policy, Vulnerablity Assessments, Network Auditing, Host Auditing, Wireless Auditing.
(Privately Held; 51-200 employees; Computer & Network Security industry)
June 2008 — Present (1 year 7 months)
(Public Company; 10,001 or more employees; symc; Computer & Network Security industry)
January 2007 — June 2008 (1 year 6 months)
- Conducting threat analysis for Symantec global Managed Security Services three primary teams, spanning 450+ enterprise customers, spread over four contents, ranging from Financial Services to National Infrastructure.
- Providing documentation, research analysis, handling instructions, as well as customer facing reports and analysis.
- Functional conduit between regional analysis teams and Symantec’s world wide information security intelligence group, Deepsight, conducting specific customer and industry analysis to support Deepsight research and findings.
- Architecting redesign of the Security Operations Center Technology Platform, including key initiatives, in support of creating a new world class analysis console and back end.
- Leading the effort to redevelop six week security analyst training curriculum to develop trainee analysts to deal with cutting edge threats.
(Public Company; 10,001 or more employees; SYMC; Computer & Network Security industry)
April 2006 — January 2007 (10 months)
- Performed advanced network threat analysis, validating attacks and accessing impact for Fortune 500 and private enterprise clients of various industries.
- Provided appropriate tactical and strategic recommendations to clients for incident remediation and proactively preventing future attacks.
- Collaborated with client security teams, third party consultants, and Symantec in-house engineering to implement recommended security countermeasures.
- Researched current vulnerabilities, attacks, and appropriate countermeasures, as well as producing internal documents to educate other analysts.
(Educational Institution; 10,001 or more employees; Computer & Network Security industry)
October 2004 — April 2006 (1 year 7 months)
- Created teaching materials, focused on hand on laboratory exercises, to be used in Information Security classes under a grant from the National Science Foundation.
- Proctored lab sessions using these exercise, providing guidance and extending the educational experience for students.
- Completed multiple accepted, juried research papers submitted to various Academic Information Security Conferences.
(Public Company; 5001-10,000 employees; HSY; Food & Beverages industry)
June 2005 — August 2005 (3 months)
This was my third summer with Hershey and a very different experince from the previous two. This summer I spent much of my time working more as a Security Architect than a Security Analyst, focusing my time on writing new policies, evaluating new technologies, and helping to prepare Hershey for current and upcoming threats. I also worked on increasing our utilization of current investments and auditing our current technologies and practices.
(Public Company; Computer & Network Security industry)
2003 — 2005 (2 years )
(Public Company; 5001-10,000 employees; HSY; Computer & Network Security industry)
May 2004 — August 2004 (4 months)
Focused primarily on desktop specific issues. Extensive time spent on systems auditing and hardening, policy compliance, investigations and forensics, wireless exposure testing, and technology evaluation. Also deeply involved in document creation, creating security summaries, position papers, threat analyses for executive management, and other technical writing tasks.
B.S. , Information Science and Technology: System Design and Development , 2004 — 2006
Network Monitoring, Advanced Exploit Techniques and Defense, TCP/IP Stack Exploitation and Hardening, Information Assurance Teaching and Training, Reactive Intrusion Detection Systems, Information Warfare, Anonymous Protocols
Bleeding Edge Signatures, Northern Virginia Snort Users Group
•GIAC Certified Incident Handler (GCIH)
•Holder of the DoD NSTISSI No. 4011: Information Systems Security Professional Certification.
•Paper Review Committee Member - 10th & 11th Colloquium for Information System Security Education.