Professional Vitae of
Matthew LoCricchio
***** ********** *****, ******** *******, MI 48312 . 586-***-**** .
***********@*****.***
Objective: CHIEF INFORMATION SECURITY OFFICER
Professional Synopsis
Over 15 years experience as a certified Chief Information Security Manager
(CISM) with responsibilities for implementing compliant-driven security
methods and for ensuring the Board of Directors, management, and employees
are in compliance with the company's:
(1) Rules and regulations as defined by regulatory agencies,
(2) Policies and procedures, and
(3) Standards of Conduct related to behavior as outlined in the Corporate
Compliance Program.
As an active member of the Corporate Compliance Committee, implemented
programs, monitored results, and reported discrepancies to internal audit
agencies regarding compliance violations and ethical issues. Provided
continual guidance to the CEO and senior management on matters relating to
compliance including the structure and organization of all compliance
initiatives. Company auditors came to rely on my efforts for ensuring the
ongoing effectiveness of compliance programs.
Specific Areas of Expertise
- Regulatory Compliance Management - Corporate Information Security
- IT Governance - Strategic Analysis
- Disaster Recovery Planning - Project / Program Management
- Security Accreditation - Staff Development/Training
- Business Process Improvement - Budgeting
- Employee Relations
PROFESSIONAL EXPERIENCE
COMPUTER CONSULTANTS INC., Auburn Hills, MI 2008 to
Present
COMERICA BANK INFORMATION SECURITY, COMPLIANCE, AND RISK
Notable Achievements:
Provided expert regulatory compliance-related consulting services. These
services, in conjunction with the IT Compliance and Servicing departments,
resolved several critical audit-identified problem areas. Led effort to
standardize compliance reporting by department and implemented a detailed
plan to coordinate procedure execution between multiple groups thus saving
time and related costs. Seriously ticked by external auditors, proactively
took steps to enact measures in a short period of time for resolving FED-
related issues and thus passed the audit saving the company hundreds of
thousands of dollars in potential fines and penalties. To prevent future
compliance problems, developed and delivered a standardized corporate
compliance manual with procedures covering administrative ID distribution
and usage.
Accomplishments:
Recognized for excellence, provided internal and external regulatory and
policy guideline expertise that governed the control environment for
Information Technology groups. Acknowledged for integrity and serving in
the best interest of stakeholders, advised business units of real and
potential performance problems that affected regulatory compliance, thus
enabling a proactive response to the issues.
. Monitored, and as necessary, coordinated compliance activities of
other departments to remain abreast of the status of all compliance
activities and to identify trends.
. Identified potential areas of compliance vulnerability and risk and
developed/implemented corrective action plans for resolution of
problematic issues, including the provision of general guidance on how
to avoid or deal with similar situations in the future.
. Provided reports on a regular basis and kept the Corporate Compliance
Committee of the Board and senior management informed of the operation
and progress of compliance efforts.
. Ensured proper reporting of violations or potential violations to duly
authorized enforcement agencies as appropriate and/or required.
VISTEON CORPORATION, Van Buren Twp, MI
2007 to 2008
SENIOR MANAGER, GLOBAL IT SECURITY, COMPLIANCE, AND RISK
Notable Achievements:
Collaborated with organization executive leads to define and manage
organizational risk tolerance. Through team synchronization, resourcefully
provided the organization with a global risk framework meeting company,
regulatory, and partner expectations. Successfully integrated risk
management with a global governance methodology into the project process.
This provided a reduction in organizational risk associated with over 80
percent of IT footprint without impacting delivery time or cost.
Accomplishments:
Created and implemented a risk management strategy based on COBIT and ISO
standards and successfully led six major security initiatives as a direct
result. Controlled costs while interacting globally with executive
leadership, business professionals, and external auditors to mitigate
organizational risk in the face of a lax security environment. Implemented
regulatory compliant control objectives that mapped directly to business
objectives. Provided control processes and personnel supervision to
establish new IT control structure for security adherence thus protecting
data integrity and savings the company tens of thousands of dollars in
potential security breaches.
. Defined a global governance methodology and model for IT operations.
. Directed the development and implementation of core role definitions
that were both audit and regulatory compliant for strategic global
applications.
. Provided executive risk assessment for strategic application projects
as well as mitigated risk and security-related issues reducing overall
project rework and implementation cost.
. Analyzed budget impacts on programs and provided forecasts of long-
term funding requirements.
. Instituted and maintained an effective compliance communication
program for the organization, including promoting (a) use of the
Compliance Hotline; (b) heightened awareness of Standards of Conduct,
and (c) understanding of new and existing compliance issues and
related policies and procedures.
. Worked with the Human Resources Department to develop an effective
compliance training program, including appropriate introductory
training for new employees as well as ongoing training for all
employees and managers.
. Monitored performance of the Compliance Program and related activities
on a continuing basis, taking appropriate steps to improve its
effectiveness.
ROUTEONE, Farmington Hills, MI 2004 to
2007
MANAGER, SECURITY AND CONTROLS
Notable Achievements:
Established an executive team committed to developing a security posture
enabling the company to do business with the over one hundred international
banking organizations-a corporate first! Collaborating with executive
management developed a security control system that enabled the company to
meet the needs and regulatory requirements of banking partners. Passed both
internal and external security audits with no major comments and did so two
millions dollars under the projected cost. Significantly reduced costs
associated with intense and ongoing audit from partner banking
organizations with clear communication, education of the organization, and
solid organizational commitment.
Accomplishments:
Led a team of executives in the research, development, and implementation
of a global security policy (definition of standards, guidelines, and
procedures) to ensure corporate compliance with internal security controls.
Managed incident response planning and investigated breaches in security,
including disciplinary and legal matters associated with such breaches.
Administered network security architecture policies and controlled network
access and monitoring capabilities. Partnered with Human Resources to
develop specialized training programs for educating employees in the
importance of sound network security practices.
. Delivered security metrics to the CEO and Board of Directors Audit
Committee.
. Created, maintained, and executed corporate continuity plan and
associated annual testing.
. Prepared and implemented corporate security and awareness programs.
. Directed internal audits/reviews utilizing COBIT (COSO, ITIL, ISO, CMM
and PMI).
. Analyzed budget impacts on programs, and forecasted long-term funding
requirements.
. Completed multiple SAS 70 II attestations without exceptions.
. Directed outside consultants, as appropriate, for independent
attestation of security audit.
JEFFERSON WELLS INTERNATIONAL, Southfield, MI 2003 to
2004
CONSULTANT, IT RISK ANALYSIS
Notable Achievements:
As a key contributor to the Risk Management Practice team, developed a new
approach to risk management administration that provided significant
savings, and due to acquiring over a million dollars of business, staff
augmentation to five full-time IT risk professionals became a reality.
Accomplishments:
Provided leadership and expertise in planning and executing projects and
programs in both automotive and financial service industries. Provide
internal audit functions, business continuity management, project
management as well as security assessments.
. Developed and performed key security audits identifying risk to
information systems that support operations and assets. Identified key
mitigation strategies that minimized the likelihood of disruption,
unauthorized alteration, and errors.
. Directed security and risk related projects from inception to
completion.
. Key customer American Exchange, Sterling Bank, Intier Automotive,
Meadowbrook Insurance Group.
. Directed team of five security professionals in daily activities
involving security, risk, and continuity management activities.
HEWLETT-PACKARD CORPORATION, Dearborn, MI 2000 to 2003
NORTH AMERICAN OPERATIONS SECURITY
Notable Achievements:
Facilitated work on a multi-million dollar Class "A" data center continuity
planning consolidation for North America utilizing a team of security
professionals. Saved the company excessive expense by developing and
implementing an innovative method of dynamically connecting to existing
documented processes thus avoiding shrink-wrapped solutions.
Accomplishments:
Provided operational security management for an enterprise computing
environment servicing over 135,000 internal users and multiple class "A",
"B", and "C" data centers. Developed, implemented, and maintained hosting
and related security services for thousands of applications and hardware
devices in a multi billion dollar computing environment.
. Developed, implemented, and managed a Global Server Management System
and Business Continuity Planning activity for several HP Class A data
centers.
. Identified potential areas of compliance vulnerability and risk;
developed and implemented corrective action plans for resolution of
problematic issues and provided general guidance on how to avoid
and/or deal with similar situations in the future.
. Developed, implemented, and managed North American and European HP
Managed Services security awareness training utilizing a strategic
collaboration with Hewlett-Packard's IT division.
. Performed Maturity Assessment for GINESS operations and security to
assure and assist operations in aligning overall project controls with
required organization levels.
INTERACTIVE BUSINESS SYSTEMS, Detroit, MI 1998 to
1999
PROGRAM MANAGER, GMAC ENTERPRISE INTEGRATIONS
Notable Achievements:
Provided program leadership in a major desktop deployment initiative for
General Motors Acceptance Corporation. This effort resulted in worker
productivity gains and an approximate annual savings of $100,000 in
licensing fees.
Accomplishments:
As a communicator and technical leader, positively influenced project teams
to work collectively to accomplish common development goals. Adapted new
implementation technologies and successfully persuaded teams to use them.
. Provided technology integrations that incorporated customized
solutions, implementation, security testing, integration testing, user
acceptance testing, and international implementation.
. Led the planning and implementation of programs.
. Facilitated the definition of project scope, goals and deliverables.
. Defined project tasks and resource requirements.
. Developed full scale project plans.
. Assembled and coordinated project staff.
. Managed program budget.
. Managed program resource allocation.
. Planned and scheduled program timelines.
DELOITTE & TOUCHE, Detroit, MI 1997 to
1998
IT DESKTOP AND NETWORK SUPPORT
Notable Achievements:
Led a team of highly skilled technical support analysts to define and
develop a problem support database for internal help desk support
operations. Reduced project costs by thousands and increased support unit
efficiency by administering research and development in a short time
period. Project implementation significantly reduced the company's
dependency on an ineffective shrink-wrapped solution that was not meeting
specific business needs.
Accomplishments:
Accountable for 1500+ users providing fundamental upgrades and computer
support to the entire business.
. Utilized broad base of technical, analytical, human relations, and
communication skills.
. Managed staff of technicians responsible for network sustainability.
. Provided single point of contact for network problem reporting and
customer service.
. Resolved technical problems through critical analysis and
investigation including network down times and numerous other pressure
situations.
EDUCATION AND AFFILIATIONS
MBA Wayne State University, Detroit, MI
BS Information System Management, Wayne State University, Detroit, MI
Certified Information Security Manager (CISM), Information Systems and
Controls Association, 2008
Compliance/Security-specific training:
COSO-based Internal Controls, Jefferson Wells University, 2003
Information Assurance Executive Training, Walsh College-Corporate Services,
2004
CISSP Training Course, Michigan State University Management Center, 2003
Professional Associations:
Michigan Infragard
Information Systems Security Association
Information Systems Audit and Control Association
Theta Tau Professional Engineering Fraternity
Wayne State University Alumni Association