Post Job Free
Sign in

Security Manager

Location:
Sterling Heights, MI, 48312
Posted:
November 03, 2010

Contact this candidate

Resume:

Professional Vitae of

Matthew LoCricchio

***** ********** *****, ******** *******, MI 48312 . 586-***-**** .

***********@*****.***

Objective: CHIEF INFORMATION SECURITY OFFICER

Professional Synopsis

Over 15 years experience as a certified Chief Information Security Manager

(CISM) with responsibilities for implementing compliant-driven security

methods and for ensuring the Board of Directors, management, and employees

are in compliance with the company's:

(1) Rules and regulations as defined by regulatory agencies,

(2) Policies and procedures, and

(3) Standards of Conduct related to behavior as outlined in the Corporate

Compliance Program.

As an active member of the Corporate Compliance Committee, implemented

programs, monitored results, and reported discrepancies to internal audit

agencies regarding compliance violations and ethical issues. Provided

continual guidance to the CEO and senior management on matters relating to

compliance including the structure and organization of all compliance

initiatives. Company auditors came to rely on my efforts for ensuring the

ongoing effectiveness of compliance programs.

Specific Areas of Expertise

- Regulatory Compliance Management - Corporate Information Security

- IT Governance - Strategic Analysis

- Disaster Recovery Planning - Project / Program Management

- Security Accreditation - Staff Development/Training

- Business Process Improvement - Budgeting

- Employee Relations

PROFESSIONAL EXPERIENCE

COMPUTER CONSULTANTS INC., Auburn Hills, MI 2008 to

Present

COMERICA BANK INFORMATION SECURITY, COMPLIANCE, AND RISK

Notable Achievements:

Provided expert regulatory compliance-related consulting services. These

services, in conjunction with the IT Compliance and Servicing departments,

resolved several critical audit-identified problem areas. Led effort to

standardize compliance reporting by department and implemented a detailed

plan to coordinate procedure execution between multiple groups thus saving

time and related costs. Seriously ticked by external auditors, proactively

took steps to enact measures in a short period of time for resolving FED-

related issues and thus passed the audit saving the company hundreds of

thousands of dollars in potential fines and penalties. To prevent future

compliance problems, developed and delivered a standardized corporate

compliance manual with procedures covering administrative ID distribution

and usage.

Accomplishments:

Recognized for excellence, provided internal and external regulatory and

policy guideline expertise that governed the control environment for

Information Technology groups. Acknowledged for integrity and serving in

the best interest of stakeholders, advised business units of real and

potential performance problems that affected regulatory compliance, thus

enabling a proactive response to the issues.

. Monitored, and as necessary, coordinated compliance activities of

other departments to remain abreast of the status of all compliance

activities and to identify trends.

. Identified potential areas of compliance vulnerability and risk and

developed/implemented corrective action plans for resolution of

problematic issues, including the provision of general guidance on how

to avoid or deal with similar situations in the future.

. Provided reports on a regular basis and kept the Corporate Compliance

Committee of the Board and senior management informed of the operation

and progress of compliance efforts.

. Ensured proper reporting of violations or potential violations to duly

authorized enforcement agencies as appropriate and/or required.

VISTEON CORPORATION, Van Buren Twp, MI

2007 to 2008

SENIOR MANAGER, GLOBAL IT SECURITY, COMPLIANCE, AND RISK

Notable Achievements:

Collaborated with organization executive leads to define and manage

organizational risk tolerance. Through team synchronization, resourcefully

provided the organization with a global risk framework meeting company,

regulatory, and partner expectations. Successfully integrated risk

management with a global governance methodology into the project process.

This provided a reduction in organizational risk associated with over 80

percent of IT footprint without impacting delivery time or cost.

Accomplishments:

Created and implemented a risk management strategy based on COBIT and ISO

standards and successfully led six major security initiatives as a direct

result. Controlled costs while interacting globally with executive

leadership, business professionals, and external auditors to mitigate

organizational risk in the face of a lax security environment. Implemented

regulatory compliant control objectives that mapped directly to business

objectives. Provided control processes and personnel supervision to

establish new IT control structure for security adherence thus protecting

data integrity and savings the company tens of thousands of dollars in

potential security breaches.

. Defined a global governance methodology and model for IT operations.

. Directed the development and implementation of core role definitions

that were both audit and regulatory compliant for strategic global

applications.

. Provided executive risk assessment for strategic application projects

as well as mitigated risk and security-related issues reducing overall

project rework and implementation cost.

. Analyzed budget impacts on programs and provided forecasts of long-

term funding requirements.

. Instituted and maintained an effective compliance communication

program for the organization, including promoting (a) use of the

Compliance Hotline; (b) heightened awareness of Standards of Conduct,

and (c) understanding of new and existing compliance issues and

related policies and procedures.

. Worked with the Human Resources Department to develop an effective

compliance training program, including appropriate introductory

training for new employees as well as ongoing training for all

employees and managers.

. Monitored performance of the Compliance Program and related activities

on a continuing basis, taking appropriate steps to improve its

effectiveness.

ROUTEONE, Farmington Hills, MI 2004 to

2007

MANAGER, SECURITY AND CONTROLS

Notable Achievements:

Established an executive team committed to developing a security posture

enabling the company to do business with the over one hundred international

banking organizations-a corporate first! Collaborating with executive

management developed a security control system that enabled the company to

meet the needs and regulatory requirements of banking partners. Passed both

internal and external security audits with no major comments and did so two

millions dollars under the projected cost. Significantly reduced costs

associated with intense and ongoing audit from partner banking

organizations with clear communication, education of the organization, and

solid organizational commitment.

Accomplishments:

Led a team of executives in the research, development, and implementation

of a global security policy (definition of standards, guidelines, and

procedures) to ensure corporate compliance with internal security controls.

Managed incident response planning and investigated breaches in security,

including disciplinary and legal matters associated with such breaches.

Administered network security architecture policies and controlled network

access and monitoring capabilities. Partnered with Human Resources to

develop specialized training programs for educating employees in the

importance of sound network security practices.

. Delivered security metrics to the CEO and Board of Directors Audit

Committee.

. Created, maintained, and executed corporate continuity plan and

associated annual testing.

. Prepared and implemented corporate security and awareness programs.

. Directed internal audits/reviews utilizing COBIT (COSO, ITIL, ISO, CMM

and PMI).

. Analyzed budget impacts on programs, and forecasted long-term funding

requirements.

. Completed multiple SAS 70 II attestations without exceptions.

. Directed outside consultants, as appropriate, for independent

attestation of security audit.

JEFFERSON WELLS INTERNATIONAL, Southfield, MI 2003 to

2004

CONSULTANT, IT RISK ANALYSIS

Notable Achievements:

As a key contributor to the Risk Management Practice team, developed a new

approach to risk management administration that provided significant

savings, and due to acquiring over a million dollars of business, staff

augmentation to five full-time IT risk professionals became a reality.

Accomplishments:

Provided leadership and expertise in planning and executing projects and

programs in both automotive and financial service industries. Provide

internal audit functions, business continuity management, project

management as well as security assessments.

. Developed and performed key security audits identifying risk to

information systems that support operations and assets. Identified key

mitigation strategies that minimized the likelihood of disruption,

unauthorized alteration, and errors.

. Directed security and risk related projects from inception to

completion.

. Key customer American Exchange, Sterling Bank, Intier Automotive,

Meadowbrook Insurance Group.

. Directed team of five security professionals in daily activities

involving security, risk, and continuity management activities.

HEWLETT-PACKARD CORPORATION, Dearborn, MI 2000 to 2003

NORTH AMERICAN OPERATIONS SECURITY

Notable Achievements:

Facilitated work on a multi-million dollar Class "A" data center continuity

planning consolidation for North America utilizing a team of security

professionals. Saved the company excessive expense by developing and

implementing an innovative method of dynamically connecting to existing

documented processes thus avoiding shrink-wrapped solutions.

Accomplishments:

Provided operational security management for an enterprise computing

environment servicing over 135,000 internal users and multiple class "A",

"B", and "C" data centers. Developed, implemented, and maintained hosting

and related security services for thousands of applications and hardware

devices in a multi billion dollar computing environment.

. Developed, implemented, and managed a Global Server Management System

and Business Continuity Planning activity for several HP Class A data

centers.

. Identified potential areas of compliance vulnerability and risk;

developed and implemented corrective action plans for resolution of

problematic issues and provided general guidance on how to avoid

and/or deal with similar situations in the future.

. Developed, implemented, and managed North American and European HP

Managed Services security awareness training utilizing a strategic

collaboration with Hewlett-Packard's IT division.

. Performed Maturity Assessment for GINESS operations and security to

assure and assist operations in aligning overall project controls with

required organization levels.

INTERACTIVE BUSINESS SYSTEMS, Detroit, MI 1998 to

1999

PROGRAM MANAGER, GMAC ENTERPRISE INTEGRATIONS

Notable Achievements:

Provided program leadership in a major desktop deployment initiative for

General Motors Acceptance Corporation. This effort resulted in worker

productivity gains and an approximate annual savings of $100,000 in

licensing fees.

Accomplishments:

As a communicator and technical leader, positively influenced project teams

to work collectively to accomplish common development goals. Adapted new

implementation technologies and successfully persuaded teams to use them.

. Provided technology integrations that incorporated customized

solutions, implementation, security testing, integration testing, user

acceptance testing, and international implementation.

. Led the planning and implementation of programs.

. Facilitated the definition of project scope, goals and deliverables.

. Defined project tasks and resource requirements.

. Developed full scale project plans.

. Assembled and coordinated project staff.

. Managed program budget.

. Managed program resource allocation.

. Planned and scheduled program timelines.

DELOITTE & TOUCHE, Detroit, MI 1997 to

1998

IT DESKTOP AND NETWORK SUPPORT

Notable Achievements:

Led a team of highly skilled technical support analysts to define and

develop a problem support database for internal help desk support

operations. Reduced project costs by thousands and increased support unit

efficiency by administering research and development in a short time

period. Project implementation significantly reduced the company's

dependency on an ineffective shrink-wrapped solution that was not meeting

specific business needs.

Accomplishments:

Accountable for 1500+ users providing fundamental upgrades and computer

support to the entire business.

. Utilized broad base of technical, analytical, human relations, and

communication skills.

. Managed staff of technicians responsible for network sustainability.

. Provided single point of contact for network problem reporting and

customer service.

. Resolved technical problems through critical analysis and

investigation including network down times and numerous other pressure

situations.

EDUCATION AND AFFILIATIONS

MBA Wayne State University, Detroit, MI

BS Information System Management, Wayne State University, Detroit, MI

Certified Information Security Manager (CISM), Information Systems and

Controls Association, 2008

Compliance/Security-specific training:

COSO-based Internal Controls, Jefferson Wells University, 2003

Information Assurance Executive Training, Walsh College-Corporate Services,

2004

CISSP Training Course, Michigan State University Management Center, 2003

Professional Associations:

Michigan Infragard

Information Systems Security Association

Information Systems Audit and Control Association

Theta Tau Professional Engineering Fraternity

Wayne State University Alumni Association



Contact this candidate