Information Security Consultant and Professional
Raleigh-Durham, North Carolina Area
Information Security Consultant and Professional
Raleigh-Durham, North Carolina Area
A versatile results-oriented Information Security Analyst with a background in Project Management and IT Security. A proven track record of effectively interfacing with management and project team members to meet organizational requirements, goals, and objectives in the secure design and implementation of Information Security solutions to protect critical assets.
Information Security Program Management and Consulting,Information Security Risk and Compliance Management, ISO 17799, GLBA, Supplier Assessments, Gap Analysis and Remediation
(Privately Held; 10,001 or more employees; Financial Services industry)
March 2007 — Present (2 years 9 months)
(Public Company; 10,001 or more employees; BAC; Computer & Network Security industry)
October 2005 — October 2006 (1 year 1 month)
• Consulted with suppliers on the implementation of Information Security Management Programs
• Performed Network Security Risk Assessments on Supplier network architectures to ensure the absence of loop holes or back doors in the overall data flow and network access to the system (Dialups, FTP, Telnet, etc)
• Determined network threats and vulnerabilities to Bank of America confidential and proprietary data on supplier networks
• Analyzed 100’s of major suppliers for Bank of America to ensure compliance with Information Security industry standards and practices (GLBA, ISO 17799, Sarbanes Oaxley Act, Privacy Act, etc)
• Wrote Executive Summaries of the supplier security risk to Bank of
America Senior Executive Management
(Public Company; 10,001 or more employees; Banking industry)
August 2005 — October 2005 (3 months)
Analysis and documentation of new threat and vulenrability management system.
(Public Company; 10,001 or more employees; Financial Services industry)
February 2004 — August 2005 (1 year 7 months)
Assessment of third party suppliers with access to bank data
Ensure Compliance with Information Security best practices (ISO 17799, PCI, GLBA, SOX, Privacy, etc)
Design and Implementation of third party supplier asessment program
(Public Company; 10,001 or more employees; Computer & Network Security industry)
March 2000 — February 2004 (4 years )
Wrote Certification reports to highlight the residual risks that effect the internal/external security of USPS information resources to the Senior Executive Management on any given application before deployment into production
Provided ISA advisory, consulting, and leadership support throughout the Information
Security Assurance (ISA) process
Responsible for performing Security Certification for USPS applications and system
as well as advising the Enabler and Network Operations Portfolio Managers and Business Owners in regards to information security
Ensured compliance with United States Postal Service policies and other Federal
Government regulations (HIPAA compliance, financial, Privacy Act, etc)
Informed upper level management of inherent and residual risks that effect the
internal/external security of USPS information resources
BS BA , Finance , 1989 — 1992