William L. Cooney[pic]
* **** ******* ***** * Edison, NJ 08820 * Tel: H: 908-***-**** W:
Email: *******@*********.*** * LinkedIn:
http://www.linkedin.com/in/williamcooney
SKILLS:
Operating Systems: AIX, HP/UX, Solaris, UNIX, Linux, SCO
Xenix, Windows 3.1/95/98/3.51/NT/2000/XP/Vista/7, Windows
Server 2000/2003/2007
Hardware: Dell Servers, PC's and laptops, Compaq. IBM, HP,
Websense, Checkpoint FW, Bluecoat Proxy, Pyramid Reliant and
Nile Series, AT&T 3B line, Sun Microsystems, DEC VAX,
Computer Consoles,
Software: SAP R/3 releases 4.6, 4.7, and ECC5, BW 3.5, BI
7.0, XI, Solution Manager, APO, EBP, and SRM. Realworld,
Accounting, LEIS/LEIM. (Bellcore/Telcordia Proprietary), MKS
Toolkit, COBOL, Gauntlet firewall, Ethereal, nMap, Superscan,
Microsoft SUS, Globalscape EFT Enterprise Server, Bit9, HP
Mercury Software, PGP, Wireshark, Accellion
Languages: ABAP, Korn Shell, C/C++, COBOL, awk, Visual Basic,
Dibol
Database: Oracle, Informix, Ingres, MS-SQL
Networking: TCP/IPLAN/WAN, Cisco Firewall, IPTABLES, ssh,
ftp, Cisco VPN, OPEN VPN, sftp, http, https, ftps
PROFESSIONAL EXPERIENCE:
Senior IT/SAP Security Manager
L'Oreal USA/Stonehenge Resources/Pro Computer & Network Security
Systems, Berkeley Heights, NJ (July 2001 - Present)
Responsibilities include but not solely:
. Lead IT Security Manager for new and successful implementation
of RSA Single Sign on Solution for L'Oreal USA Cloud and
Internal Applications. This included the project management,
Vendor/Customer coordination and design and implementation of
the following:
o RSA Federated Identity Manager (FIM)
o RSA Access Manager (AxM)
o RSA Authentication Manager
o Apache Server
o Microsoft IWA
o Microsoft ADFS
o Salesforce.com
. Lead IT Security Manager for new and successful implementation
of L'Oreal USA Internal and External File Transfer Solution.
o Currently implemented over 400 internal and external users
performing various secure tasks such as:
. HR File Transfers
. Payroll File Transfers
. Purchase Orders
. Sales Orders
. Advanced Shipping Notices
. PO Acknowledgements
. Sales Forecasting
o This also included the project management and
configuration of the following:
. Globalscape EFT Enterprise
. PGP Command Line
. MKS ToolKit (Unix Tools)
. Lead SAP/IT Security Manager for new and successful
implementation of PCI Standards for L'Oreal USA's in house
SAP/ERP/Store Cash Register Application. This includes:
o Insuring all firewall and network routes are PCI
compliant.
o Confirming all password were truly encrypted and secure
within the custom cash register systems.
o Worked with a 3rd Party Credit Card Processor, insuring
that all Credit Card transaction were secured over a
secure ssl tunnel.
o Auditing that Credit Card are not stored on any system at
L'Oreal and are tokenized in our database for each
customer.
o Created process in order to bring existing customers
credit card information securely over from Legacy systems
and 3rd Party Credit Card Processors, This included:
. Credit Card File Encryption
. Signed Employee NDA's who worked on transferring
Credit Card Information.
. Accellion Secure File Transfer.
. PGP Whole Disk Encryption
. Ensuring that all Credit Card information is written
to memory and not disk for the L'Oreal USA's in
house SAP/ERP/Store Application
. File Wipe of sectors in which Credit Card file
existed on workstation.
. Disk Wipe for each region Credit Card upload of the
workstation.
. Lead L'Oreal SAP Security Manager for new and successful
implementation of SAP modules R/3 releases 4.6, 4.7, ECC5, and
ECC6, BW 3.5, BI 7.0, XI, Solution Manager, APO, EBP, and SRM
for the L'Oreal FUSION and Synergy Projects.
o Performed upgrade activities from ECC5 to ECC6 using
security transactions such as SU01, PFCG, PFUD, SU24 and
SU25. Scripted conversion activities to remove old and
non executed risks to reduce SOD issues.
o Designed and reviewed the GRC Technical Remediation for
L'Oreal USA GRC tool suite. Incorporated potential L'Oreal
USA SOD risks within L'Oreal Worldwide SOD risk design to
generate additional policies to detect additional SOD
risks.
o Created and presented L'Oreal USA's SAP Security Design,
Review and Implementation plan for each Division Go-Live
to Upper Management and functional teams.
o Produced the requirements, developed the design, and
implemented the SAP Security policies and business
profiles for the L'Oreal USA divisions. To attain this it
required working closely with the functional team members,
the business community and the external auditors.
o Directed a staff of four SAP Security developers and
testers.
o Performed auditing of business profiles and users using
the SAP GRC Access Control Risk Analysis and Remediation
tool.
o Managed and analyzed L'Oreal's sensitive information
within SAP against accidental or unauthorized
modification, destruction, extraction and disclosure.
o Organized and planned each divisional Production Go Live
SAP security access. This included working with the Key
Users, Functional IT and each division's user community to
determine and assign the correct business profiles for
each employee job function.
o Supervised the post go-live activities which include the
responsibility the maintenance of the security roles and
the add/change/activation/deactivation of the user
accounts for approximately 2,600 Users over all the
L'Oreal Fusion SAP landscapes.
o Performed security transport creation, releasing, and
auditing test results before releasing into production.
o Developed the landscape and maintained L'Oreal's SAP
Central User Administration system (CUA).
o Coordinated for SAP Security Audit activities with our
external auditors Price Waterhouse Cooper.
o Identified and audited sensitive transactions and
confirmed SOD policies were adhered to by the business
community.
o Presented overall SAP Security design and procedures to
colleagues and management.
o Facilitated the training of interns and various IT staff
members of the L'Oreal USA SAP Security policies.
o Oversaw the security design of the SAP Web console for RF
gun users which allows users to automatically remote login
into SAP from the warehouse.
o Designed and developed customized scripts for loading
initial user and security data using Mercury Quick test
software suite and Unix Korn Shell. The automation of
these processes saved L'Oreal time and money.
o Identified and maintained the Security profiles, Infosets
and Infocubes information for our SAP BW systems.
o Developed the process for the reporting of SAP Licenses to
our corporate offices in France,
o Managed L'Oreal's on-site SAP and Windows helpdesk which
consisted of four people.
o Performed SAP Basis Administration which includes the
following:
. System Tracing, Operating System Monitoring, Transports,
Operating System Monitoring, Active Users Monitoring,
Maintaining External OS Commands, System Log Monitoring,
Client Administration, Developer Tracing, ABAP/4 Runtime
Error Analysis, User Buffer Analysis
o Designed, engineered and managed firewall rules necessary for SAP
access between L'Oreal Worldwide and our SAP Co-locations.
o Investigated as part of a team recommended SAP version upgrades,
OSS patches for Security and SAP GUI upgrades.
o Participated in the IBM hardware configuration for the SAP
environment.
. Lead Security Manager for new implementation of L'Oreal USA
Security Policies.
o Developed, communicated, and implemented security policies
for L'Oreal USA and L'Oreal Worldwide.
o Lead L'Oreal USA Computer and Network Forensics expert.
o Implemented L'Oreal USA windows patch management policy
and software.
o Programmed and implemented IDS systems.
o Administration and configuration of caching and firewall
devices.
o Designed, implemented managed, and secured communications
between internal L'Oreal networks and third party vendors.
o Managed internal security website for divisional security
information for technical staff and end user community.
Senior EDI Manager
L'Oreal USA, Clark, NJ (January 2000 - June 2001)
Responsibilities include but not solely:
. Lead EDI Manager for the new implementation of L'Oreal
Centralized EDI Organization.
o Designed, configured and managed all business related EDI
documents for the L'Oreal Professional Products Division.
o Managed a staff of two EDI developers to create trading
partner documents using Trusted Link software and UNIX
tools.
o Mediated interactions with the L'Oreal trading partners,
EDI staff, and the end users in order to determine what
information needed to be transmitted and received to and
from each other in order to receive Purchase Order,
fulfill orders, shipments invoicing, acknowledgements, and
payment remittance.
o Researched, designed and implemented the UNIX systems
communications between L'Oreal USA, its trading partners
and our Value Added Network (VAN).
o Sole maintainer L'Oreal in-house Corporate A/R system.
Senior Project Manager
L'Oreal USA, Designer Fragrance Division (DFD), North Brunswick,
NJ (June 1995 - January 2000)
Responsibilities include but not solely:
. Lead Project Manager for L'Oreal USA, Designer Fragrance
Division organization.
o Managed, configured and maintained a total of ten HP series 800,
Windows NT, and Novell Servers.
o Managed a staff of three UNIX and DBA administrators.
o Managed and supported a staff of three people, over two hundred
and fifty Windows NT Workstations and printers.
o Designed, configured, and managed the internal network at three
divisional sites.
o Designed, configured, and managed NFS, NIS, DHCP, and UUCP
between the UNIX various servers.
o Instituted division standards for installing new servers and
workstations,
o Created and maintained UNIX file systems, UNIX logins, printers,
and software.
o Drafted the requirements, design and implementation of L'Oreal's
custom Sales Force Automation software.
o Instructed interns and IT staff on how to administer these
environments.
Senior Staff Technologist - Software Technology Systems
Bell Communications Research (September 1986- June 1995)
Responsibilities include but not solely:
. Software Developer for the LEIS Project.
o Software developer responsible for developing and
maintaining the Loop Engineering Inventory Module (LEIM)
and Loop Engineering Inventory System {LEIS) Common Tools.
o Performed helpdesk support to the customers.
o Operated and maintained in house Source Control System.
. UNIX Administrator for the LEIS Project:
o Supervised a staff of 3 UNIX system administrators.
o Designed and programmed tools for the user community and
to automate administrative tasks.
o Planned, designed, and executed the upgrade the computer
center.
o Researched and implemented NFS/PC-NFS between our UNIX
machines and MS-DOS/Windows 3.1 machines.
o Analyzed and automated UNIX user creation process.
o Developed a program to monitor UNIX core dumps.
o Designed and developed tools to monitor UNIX services such
as NFS, ftp, etc.
o Coordinated, recommended, and implemented various OS
patches.
o Performed various DBA duties.
. Applications Tester for the LEIS project
o Designed and programmed custom written applications
before release to the field
o Designed, developed, and implemented test tools in
order to speed up the testing process.
Anthony-Young Associates
(February 1984- September 1986)
Responsibilities include but not solely
. Systems Administrator/Realworld Software Applications
Developer.
EDUCATION:
o Rutgers University (1987-1992), earned credits toward a
B.S. in Computer Science
o Nassau Community College (1980), Associate Degree in Data
Processing
o SAP Web AS Administration (2004)
o SAP Authorization Concepts (2004)
o Secure SAP System Management (2004)
o Security in SAP System Environment (2004)
o SAP BW Authorization (2005)
o SAP BI Authorization (2007)
REFERENCES: Furnished upon request.