IT Security Risk Advisor at The Ohio State University/Office of the CIO
Columbus, Ohio Area
IT Security Risk Advisor at The Ohio State University/Office of the CIO
Columbus, Ohio Area
I am a Program/Project Manager with over 19 years of IT management & consulting experience in IT Security, ESI, retail, healthcare, banking, government, manufacturing, chemical, & consumer products industries. My experience includes 13 years of delivering projects, including program management, with multiple projects & managers, & acting as the liaison between the business & IT representatives to translate business requirements into scope & system requirements, perform business process reengineering, data conversions & systems integration. I have a strong management background which has been applied in a PMO structure, sales, recruiting, business & technology planning & all phases of the project life cycle. My strengths are organization, communication, problem-solving, financial tracking, mapping business requirements to system design, managing project scope, JAD, data conversion/ETL & systems integration, & the ability to motivate & run a diverse, cohesive project team. I have managed an IT Security & Compliance Program, including reporting overall financials & status, assisting with budgeting & resource allocations, meeting internal audit & compliance requirements, as well as running multiple projects including enterprise-wide PCI compliant CCN & SSN encryption, enterprise-wide IT Security risk assessment, remediation & awareness assisting the client to gain PCI Certification & enterprise-wide ESI (electronically stored information) initiatives. My project experience includes small to large-scaled multi-million dollar projects, centralized & client-server architectures, mainframe platform, legacy data & system integration, third party software enhancement & implementation & web-based development. I utilize PMI, phased approach development, staged delivery & proprietary client project methodologies. I have a Bachelor of Science/Systems Analysis degree from Miami University of Ohio & am a PMI certified project manager since 2002.
Program/Project Management
IT Security & Compliance (i.e. PCI; ESI; enterprise risk remediation)
Retail
Healthcare
Banking
Government
(Higher Education industry)
April 2009 — Present (4 months)
(Computer Software industry)
February 2005 — April 2009 (4 years 3 months)
**See Limited Brands, IT Security Program/Project Manager, JPMorgan Chase, and Ohio Department of Mental Health positions below
(Public Company; LTD; Retail industry)
April 2006 — April 2009 (3 years 1 month)
Served as Project/Program Manager for the CISO. Provided consulting services, including program management for the LBI IT Security program & running enterprise-wide PCI complaint projects & enterprise-wide IT security risk assessment & remediation projects.
•Successfully ran 2 key projects awarding LBI PCI Certification: the enterprise-wide PCI CCN encryption project; & the enterprise IT security/PCI awareness program avoiding major PCI fines & remediating risks to the business.
•Assisted the Limited with improving their risk posture by successfully completing two SAP security go-lives, the enterprise PCI CCN encryption project & the SSN removal/encryption risk remediation project.
•Created IT Security & Compliance Program executive level reporting including overall status, financials via SAP, resource allocation planning & SOX/internal audit remediation planning. Also managed enterprise-wide IT Security assessment & risk remediation & ESI legal regulatory projects for LBI.
(Public Company; Banking industry)
September 2005 — April 2006 (8 months)
Served as a Project Manager in the JPMC GTI/GTAM program that is part of a team responsible for implementing the global solution for a common repository of all technology assets owned by the JPMC/Bank One merged organization. Specific responsibilities include representing the GTI/Asset Integration team as one of the project managers acting as the liaison between the key banking system customers & the Asset Management System development team (Peregrine Asset Center) .
•Participate on a GTAM work group that is analyzing global ‘as-is’ asset information as input to develop a roadmap designed to reach the future state of the asset management program.
•Responsible for multiple project planning, communication, change control/risk management & coordination of asset integration implementation planning and execution, while following PMO procedures & best practices.
•Responsible for facilitating team meetings, documenting minutes, requirement sessions & management reporting.
(Public Company; Banking industry)
February 2005 — August 2005 (7 months)
Served as a Project Manager in an Enterprise Systems PMO of 35+ PMs servicing the Retail banking line of business. Responsibilities included providing overall project management of implementing a phased Retirement Reporting System that included merging the JPMC & Bank One RRS systems & rolling out target system enhancements. The RRS project delivery was part of a critical Enterprise-wide Systems implementation involving 160+ applications & integration efforts.
•Performed project planning, execution & tracking using MS-PROJECT 2000 & Lotus Notes 6.5.
•Conducted JAD sessions, facilitated team meetings, documented issues, meeting minutes, requirement sessions & data flows.
•Responsible for overall project communication.
•Responsible for all phases of the project life cycle, including change control management, risk management & 24 x7 ‘command center style’ implementation plan execution.
•Participated in PMO best practices sessions, updating project management tools & processes.
(Information Technology and Services industry)
March 2003 — February 2005 (2 years)
New In/OutPatient pharmacy systems are implemented with 15 years of data converted into SQL SERVER database on a WINDOWS 2003 SERVER. Integrated with existing operational legacy systems & business processes, including a Statewide reporting process & the enterprise data warehousing project.
•Performed project planning, execution, tracking using MS-PROJECT 2000, MS-OFFICE SUITE
•Coordinated & communicated weekly progress, issues included
•Met with SMEs & performed system gap analysis, proposal review, & vendor/software selection
•Performed business process reengineering, documented current processes & pharmacy workflows in VISIO
•Translated business requirements, via JAD, into software & database design
•Planned ,designed & managed data conversion/ETL including extensive data cleansing
•Documented test requirements, plans & results for quality assurance & system verification
•Defined reporting requirements & implemented solution to support Statewide budget and decision making
(Privately Held; Information Technology and Services industry)
August 2001 — March 2003 (1 year 8 months)
Responsible for business development, contract management & project management of the Internet/Web-based development practice area, including proposal/quote development, marketing, recruiting, consultant management & developing project management “best practices”.
•Created fixed price project cost estimates using MS-PROJECT
•Managed multiple projects using MS-PROJECT & weekly progress meetings, used phased delivery approach
•Assisted project managers with facilitating JAD sessions for requirements definition, change management, scope control & weekly executive presentations
•Consulted with customers/SMEs to purchase/utilize Visual Basic, Crystal Reports & Visual Interdev to web-enable applications & use existing Access & Oracle Databases in a Unix environment
•Defined, documented “best practices” for a company adopted PM approach including PMI practices, phased delivery & an emphasis on understanding unique business environments & respecting project team member diversity
(Information Technology and Services industry)
November 2001 — January 2003 (1 year 3 months)
Technical Project Manager of the Child Care Licensing Systems. The child care facility licensing/inspection data is managed centrally using an IMS database on an IBM 3090 mainframe, coded in CICS & Cobol. Business end users enter licensing data into the centralized database. The child care inspection results are transferred from the inspector’s laptops/desktops to the centralized database & then inspection/licensing data is pushed out to a State of Ohio Child Care website via the TCP/IP; FTP protocol for access by the public.
•Responsibilities include overall project coordination, planning, task & team progress tracking using NIKU
•Managing issues database & coordinated weekly status meetings
•Enhancing current system across multiple platforms, including defining requirements for system enhancements with the business end users
•Responsible for the data ETL, integration & security of child care inspection results on the public website
(Information Technology and Services industry)
August 1998 — August 2001 (3 years 1 month)
Managed the Automated Drug Dispensing Machine Project from initiation to implementation/training. The ADM system replaced an existing cart exchange process which delivered patient prescriptions filled in the Central Pharmacy to all the psychiatric hospitals across Ohio. The new ADM system stored the medications at the “point of sale” (nursing station) where they are administered. Patient legacy data was converted to a centralized Oracle database & integrated with existing mainframe systems.
•Coordinated State employees, off-site vendor, MIS interface contractors to implement the ADM system in 9 psychiatric hospitals (75 nursing stations) across the State of Ohio
•Managed project justification & executive presentations before project “kick-off”
•Participated in statewide nursing “train-the-trainer” roll-out as the business process integration expert
•Defined system security procedures, emergency med access & technical practices for data security, backup/restore procedures
(Information Technology and Services industry)
August 1996 — August 1998 (2 years 1 month)
Technical manager for implementation of the Electronic Benefit Transfer SmartCard Project. Ohio replaced paper food stamps with an EBT/SmartCard system that loaded a recipient’s benefit balance on a SmartCard chip. This system was implemented to cut down on food stamp fraud.
•Acted as the technical project management liaison between the State of Ohio, the vendors (Citibank/Stored Value Systems) & the interface team to coordinate the technical development & support. Architecture included a centralized IMS database/ IBM Mainframe 3090 and daily transactions being stored on an off-site HP.
•Managed all tasks, technical issues & team progress
•Managed weekly technical team meetings & reported progress to the Citibank PM
•Selected to participate as the technical SME for the recipient training program roll-out for all Ohio counties
•Responsible for the integration of the EBT data to other Ohio welfare programs & to the fraud management tracking & reporting system
(Information Technology and Services industry)
September 1995 — August 1996 (1 year)
Responsible for balancing objectives of Origin/Columbus branch, our staff, and clients in order to achieve the most successful results possible. Managed 30 staff in multiple project settings within Bank One, including credit card, bank conversions and mergers, financial applications and reporting, and marketing. Also part of the team responsible for planning and control of Origin/Columbus operations.
•Performed contract development and management following Origin proprietary methodology
•Performed project management for multiple projects and managed multiple project managers and leads following Origin proprietary methodology based on the type of project
•Responsible for quality assurance for all projects and documenting reusable best practices
•Responsibilities also include staffing, account & staff development, sales support, and customer support
(Public Company; Banking industry)
January 1996 — June 1996 (6 months)
Project Manager of the enterprise-wide IT new employee technical training & career development program for Bank One. Origin developed a technical training program for the new consultants entering Bank One. Bank One requested that we take this program, perform a gap analysis & design/implement a technical training & career development program for Bank One IT employees.
•Developed project charter with the project sponsor
•Managed a project steering committee to define & drive deliverables
•Performed overall project management, execution & tracking using MS-PROJEC/waterfall methodology
•Documented business requirements & presented to upper level IT executives
•Mapped business requirements to training & career development processes using VISIO
•For each pogram process, defined tasks, training resources, & roll-out schedules
•Developed training manual requirements & managed development
•Performed weekly status reporting, meetings & presentations
(Information Technology and Services industry)
December 1994 — September 1995 (10 months)
Responsible for the contract and project management of deliverable-oriented contracts in emergent technologies. Management duties included sales support, customer support, staffing, quality assurance, staff development, and infra-structure development. Consulting duties included business & technology planning, and project management services
•Performed contract development and management following Origin proprietary methodology
•Performed project management for multiple projects and managed multiple project managers using TIMELINE
•Utilized Origin proprietary project methodology based on the RAD for new technologies
•Responsible for quality assurance for all projects and documenting reusable best practices
•Responsibilities also include staffing, account & staff development, sales support, and customer support
(Information Technology and Services industry)
July 1992 — December 1994 (2 years 6 months)
Lead the design team of 1.5 and 2.5 effort-year system integration sub-project supporting the installation of American Software’s accounts receivable system into a sophisticated technical environment. The integration effort required stress testing and subsequent re-architecture of ASI databases to enhance performance and accommodate greater capacities.
•Planned the analysis, design, development, training and implementation following Borden’s SDLC
•Documented issue logs and issue resolution
•Developed the functional and detailed design documents, updating them based on outcomes of JAD sessions
•Performed weekly status meetings with IT management and communicated design team planned vs. actual
•Performed design issue resolution, risk assessments, and change control
•Lead development using COBOL, CICS, VSAM, Playback and TELON in an IBM 3090, OS/MVS environment.
(Information Technology and Services industry)
January 1991 — July 1992 (1 year 7 months)
Participated in systems integration project to implement McCormick and Dodge Accounts Payable System.
This integration effort required extensive unit, system, and parallel testing of the product as well as developing interfaces to a myriad of purchased and homegrown software products on a variety of hardware platforms.
•Developed code using COBOL,CICS,VSAM, and TELON in an IBM 3090, OS/MVS, and ROSCOE environment.
•Responsible for all system and parallel testing
(Information Technology and Services industry)
August 1990 — January 1991 (6 months)
Participated in effort to develop a distributed check-writing system featuring centralized and remote check printing. Responsible for development of data encryption algorithms and programs, as well as PC-based check printing programs.
•Performed development using Relay-Gold, desk-top MICR printers, PS/2 PCs running DOS & QuickBASIC, IBM 3090 running OS/MVS, CICS, ROSCOE, VSAM, TELON, and COBOL
(Information Technology and Services industry)
August 1989 — August 1990 (1 year 1 month)
Completed a variety of maintenance and enhancement projects for human resource, employee benefit, and payroll applications.
•Performed coding requirements gathering from Systems/Business Analysts
•Developed code using CICS, COBOL, SQL (Embedded), DB2, VSAM, and SDF (Screen Definition Facility) in a IBM 4381, VM/VSE, CMS environment
BS , Computer Science/Systems Analysis , 1985 — 1989
see below