e-Commerce Risk Management
San Francisco Bay Area
e-Commerce Risk Management
San Francisco Bay Area
Experienced risk management professional and MBA (Haas 2007, Strategy and Marketing) with background in technology, business analysis, data protection, secure product design, fraud detection/prevention, and compliance. Direct experience with strategy/policy development, project management, and payments processing infrastructure. Strong communication skills. Interested taking on a leadership role in risk, payments, and/or technology at dynamic, international company with serious growth potential.
Payments, Data Protection, Product Design & Analysis, Project/Program Management, Financial Services, Fraud Prevention, Policy development, Network security
(Public Company; 5001-10,000 employees; ebay; Internet industry)
December 2007 — Present (1 year 8 months)
(Financial Services industry)
2005 — Present (4 years)
(Public Company; 10,001 or more employees; ebay; Internet industry)
August 2005 — January 2008 (2 years 6 months)
In this role, I worked with Product Managers who were either developing new products/features or optimizing performance on their existing portfolios, making sure there were solid controls in place to minimize exposure to fraud, data security issues, and other risks. This means on a given day I might have needed to: conduct quantitative analysis of transaction data, review a technical design or spec, develop a business case for introducing a new risk feature (such as a limit, rule, authentication method, model, user criteria, or monitoring process), or spend time trying to understand how a system can be broken -- or at least twisted around a bit. There tended to be cross-functional teams involved. In this role I had the opportunity to work with PayPal's Mobile, Debit Card, Virtual Debit Card, Student Account, and Skype teams. (Plus a few innovations which are yet to be public.)
(Privately Held; Financial Services industry)
April 2001 — July 2005 (4 years 4 months)
I designed a process for assessing the risks associated with new global products, as they were being developed -- and then conducted several major reviews (focusing on fraud, data protection, and regulatory compliance). I'm a big proponent building risk controls into a product as opposed to adding features on later (cure is more expensive than prevention), so I appreciated the opportunity to get involved early in the product design process. I also managed Risk's vetting process for changes to the Visa International Operating Regulations -- which is the "law" Visa's payments infrastructure "land". Both responsibilities required developing new risk controls and policy, and getting sign-off from executive management on recommendations. My specialties on the team were: e-commerce, emerging technologies, prepaid cards, authentication, remittances, micropayments, acceptance technologies.
(Public Company; 10,001 or more employees; gsk; Pharmaceuticals industry)
1997 — 2001 (4 years)
As the first official hire into the company's IT Security team, I led the creation and implementation of key operating processes for enterprise's information security operations function, including:
* Monitoring: Network & host based intrusion detection, access control
* Global policy: Data protection and Acceptable Use (for all employees/systems)
* Incident management: Owned investigative process for internal and external incidents, including computer forensic response
* IT and Service Provider Assessments: Tested internal systems (including simulated attack testing) and set requirements/conducted vetting for service providers
* General: Fielded questions about HIPAA. Worked with system administrators to protect servers, data, email, and PC's and configure routers, firewalls and operating systems. Consulted with marketing on web technology. Conducted threat assessments for executive management.
(Public Company; Information Services industry)
1996 — 1996 (less than a year)
Market research, Competitive analysis, Business intelligence
(Online Media industry)
1995 — 1995 (less than a year)
MBA , Strategy and Marketing , 2004 — 2007
MS , Network Security , 2002 — 2005
1997 , Business , 1993 — 1997
Triple concentration: Finance, Information Systems, & Legal Studies
1997 , Business/Economics , 1993 — 1997