
Director at IOActive
Greater Seattle Area

Director at IOActive
Greater Seattle Area
Recognized networking expert offering fresh insight and a passion for innovation, proven track record in designing, building, and supporting several successful national networks. A proven technology leader and strategist able to utilize both software and hardware knowledge to bring company vision, goals and objectives to reality.
Dynamic leader and mentor, able to build team cohesion and inspire individuals to strive toward ever higher levels of achievement. Exceptional client relationship and management skills; relate and interface easily at the top executive levels. Keen, in-depth understanding of Internet tools, technologies, companies, trends, and revenue models. Solid background and qualifications in all core business functions – engineering, finance, marketing, and operations.
CISA, CISSP, CCNP, Visa QDSP
(Privately Held; 11-50 employees; Computer & Network Security industry)
March 2008 — Present (5 months)
New responsibilities include managing deliverables and consultants while engaged with various clients.
(Privately Held; 11-50 employees; Computer & Network Security industry)
August 2006 — Present (2 years)
(Privately Held; 51-200 employees; Internet industry)
June 2006 — August 2006 (3 months)
Network engineer responsible for maintaining the network that supports the ManiaTV internet TV channel. Encoders, Firewalls, Operating Systems, Routers, Servers, and Switches.
(Public Company; 10,001 or more employees; Computer & Network Security industry)
June 2005 — June 2006 (1 year 1 month)
Responsible for information security consulting and developing/expanding the Information Security Solutions Practice, which offers business services in the areas of policy development, security assessments, compliancy auditing, penetration tests, and disaster recovery, business continuity. These responsibilities include:
Developed initial methodology for auditing VoIP installations, additionally helped prepare presentation and demo demonstrating security of VoIP.
Conducting regular network security assessments against corporate network using various open source tool (Nmap, Nessus, Dsniff, Hunt, fragroute, firewalker, etc) and manual methods.
Implementing security policy to protect internal network against unauthorized access, and to making provisions for disaster recovery in the event of successful intrusion/attack.
Performing security compliancy audits - VISA PCI and PABP, SOX, GLBA, and HIPAA.
(Privately Held; 11-50 employees; Computer & Network Security industry)
January 2005 — May 2005 (5 months)
Responsible for providing security consulting services including gap analysis versus regulatory and standards compliance to determine the current state of a clients operation. Responsibilities include demonstrating compliance with Sarbanes-Oxley (Section 404) IT security requirements; compliance with VISA and MasterCard PCI and compliance with Health Information Portability and Accessibility Act (HIPAA) regulations. Additional responsibilities included researching potential security vulnerabilities on a clients external network and public-facing Internet presence utilizing a combination of open source and internally developed tools. Compiling results and research to provide an in-depth analysis of the external network demonstrating clients strengths and weakness, with gap remediation efforts for further security controls.
(Privately Held; 11-50 employees; Telecommunications industry)
February 2003 — February 2005 (2 years 1 month)
Responsible for the lab development and production network integration for UTOPIA (www.utopianet.org) A FTTH deployment encompassing 11 cities in Utah. Specific engineering challenges include a multi-year plan to build a 11 city infrastructure capable of delivering 100 mbps Ethernet to gigabit ethernet to the premise; the introduction of traffic engineering and quality of service to accommodate thousands of voice and video customers without swamping the data network; migrating from a single failure point networks to multiple tiers of redundancy. Responsibilities include managing and training network staff, designing and implementing changes to the network lab architecture and production network, project management for architecture, server, security and new service deployments, maintaining budget requirements set forth for network integration.
(Public Company; 5001-10,000 employees; Computer Networking industry)
2003 — 2004 (1 year)
Responsibilities included maintaining a Cisco multi-honed network that serviced the largest air traffic map generator in the world. Working closely with security, systems and software developers to provide an infrastructure that supported continued new developments for Lockheed.
Also responsible for the migration of the a secondary data center in Los Gatos, CA to Denver location, included mapping all services currently hosted in the location, traffic mapping, and planned minimal customer disruption.
Implemented the first secure wireless access network for Jeppesen. Allowed employees the ability to roam throughout the Jeppesen facility and remained securely connected to the internal infrastructure.
(Privately Held; 51-200 employees; Telecommunications industry)
June 2001 — June 2002 (1 year 1 month)
Responsible for integration of citywide network capable of sustaining 5000 - 500000 FTTH (Fiber to the Home) customers. Services include Voice (VOIP) Data (10 Mbps) and Cable (280 channels and VOD). Responsibilities include managing and training network staffs in all city locations, designing and implementing changes to the network architecture, including the implementation of Change Control processes in conjunction with the Global NOC, project management for architecture, server, security and new service deployments, working with equipment vendors providing product requirements including uptime, errors encountered, as well advanced upgrade requests and future revisions, maintaining budget requirements set forth for network integration, server architecture, software upgrades, and outside software development.
(Public Company; 1001-5000 employees; Telecommunications industry)
March 1999 — June 2001 (2 years 4 months)
Served as the lead consultant responsible for managing, designing, implementing and administrating a complex VPN solution involving worldwide Data Centers. Worked extensively with Microsofts Internal Project Management teams to meet deadlines assigned by business partners. Responsibilities included designing and implementing the secure infrastructure within the hub site, as well as working with multiple large Internet carriers to deploy solutions for over 400 Business Partners.
(Computer & Network Security industry)
1996 — 1997 (1 year)
rugby, fly fishing, snowboarding, weight training, security, mma
ISSA, ISACA, DC303, Twitter,