
Information Risk Analyst at JPMorgan Chase
Greater Philadelphia Area

Information Risk Analyst at JPMorgan Chase
Greater Philadelphia Area
GIAC Security Essentials Certification (GSEC)
Systems Security Certified Practitioner (SSCP)
Certified Ethical Hacker (CEH)
Certified Penetration Tester (CPT)
Certified Associate Project Manager (CAPM)
NSTISSI No. 4011 IA Certificate (NSA)
Management of Aggressive Behavior Certification (MOAB)
Risk Management, Penetration Tests, Vulnerability Assessments, Wireless Audits, Firewall Reviews, Vendor Due Diligence, Web Application Testing, Architecture Reviews, Static Code Analysis, SDLC, Project Management, Security Awareness.
(Public Company; 10,001 or more employees; JPM; Banking industry)
July 2008 — Present (1 year 5 months)
(Public Company; 1001-5000 employees; RHI; Management Consulting industry)
July 2006 — July 2008 (2 years 1 month)
•Executed over 21 vendor due diligence compliance reviews which included on-site and questionnaire based phone reviews, additionally trained over 8 people on the due diligence process
•Acted as a information security project manager at a leading credit card issuing bank for over 15 projects to draft requirements, review designs and mitigate risks
•Performed both internal and external penetration tests, moreover managing and executing an international internal vulnerability assessment where multiple infrastructures were assessed
•Assessed multiple wireless environments for adherence to industry leading practices
•Drafted corporate security policies and procedures for specific areas such as user awareness, change management and incident response
•Performed firewall reviews for various clients for appropriate and efficient configurations
•Completed multiple compliance audits including GLBA, SOX and PCI
(Educational Institution; 11-50 employees; Research industry)
April 2005 — April 2006 (1 year 1 month)
•Aided in the development of a new website to explain Federal Environmental Protection Agency (EPA) Worker Protection Standards
•Performed daily website maintenance
•Enacted Quality Assurance processes for cross-browser functionality of the website
(Educational Institution; 11-50 employees; Higher Education industry)
August 2004 — April 2006 (1 year 9 months)
•Administered active directory to ensure appropriate access for user accounts
•Executed daily PC troubleshooting as part of a team which supported the college of Health and Human Development at Penn State
•Audited computer systems on the PSU network to ensure license compliance
•Installed new client software on all platforms including Windows, Macintosh, Linux
Bachelor of Science in Information Sciences and Technology , Minor: Japanese , 2002 — 2006