STEVEN SANTAMORENA
Brewster, NY 10509
******.***********@*****.***
Mobile: (914) 255 - 0074 Home: (845) 259 - 3037
CISSP, CISM, CIPP
Summary
Business-focused information security leader with a unique combination of
strategy, consulting, and IT security expertise. Skilled at articulating
the importance of information security to senior executives as well as
pragmatically providing appropriate security controls.
Education
MS in Information Assurance, Norwich University, Northfield, VT. 2010 Cum
Laude (accredited by the NSA)
BA in Information Science, State University of New York, Oswego, NY. 1993
Certifications
Information Systems Security Professional (CISSP) - December 2005
Certified Information Security Manager (CISM) - June 2006
Certified Information Privacy Professional (CIPP) - May 2008
IBM Certified Advanced System Administrator Release 4, 5, 6, and 7
IBM Certified Advanced Application Developer Release 4, 5, and 6
Professional Experience
THE READER'S DIGEST ASSOCIATION, INC. Pleasantville, NY
September 1999 - Present
Global $2 billion media, marketing and entertainment company. Publicly
traded on NYSE until 2007 private equity transaction.
Director of Global Security:
January 2004 - Present
Responsible for global information security for 5000 employees across 50
countries. Partner with business community and IT organization to ensure
a secure and regulatory-compliant yet productive working environment.
Member of IT Leadership Team. In 2009, given addition responsibility of
managing the IT Infrastructure.
Security Program Management / Information Security / Physical Security
. Developed and implemented a centralized and comprehensive security
program for Reader's Digest and its subsidiaries. Responsible for
security strategies and technologies to safeguard all employees and
the informational assets of the company.
. Created and implemented a security metrics program to measure
effectiveness of the overall security program. The results of the
reporting led to improved security controls and an overall reduction
of security incidents.
. Architected and implemented an endpoint protection program reducing
malware infections by over 50% and reduced impact on employees.
. Established and communicated IT Security Policies through a branded
security portal developed for the global intranet.
. Developed and distributed corporate-wide Security Awareness program,
improving the reporting of suspicious activity. This is achieved
through a Corporate Security Blog, Special Intranet and E-Mail
Bulletins and frequent "Lunch and Learn" seminars.
. Developed and implemented an incident response plan and coordinated
exercises to ensure that the security response team is adequately
prepared and is able to respond to incidents appropriately.
. Responsible for ensuring the Disaster Recovery capabilities for 80% of
the organization's infrastructure. Scheduled recovery tests have
demonstrated a continuous improvement in recovery times and capability
over the past two years.
. Provide senior management with security status updates and risk
assessments addressing existing security threats.
. Preside as chairman of Corporate Information Security Steering
Committee.
. In 2008, managed physical security for the organization's
headquarters. Responsible for card access management and physical
threat assessment for the facility.
Efficiencies, optimizations, and cost savings
. Optimized the security team by eliminating two positions while
simultaneously improving service levels. These staff reductions saved
the company $100,000 annually.
. Reduced overall security spending by 15% in 2008 concurrent with
process improvements while focusing attention on key risk and user-
facing areas.
. Developed specialized metrics reports for divestitures resulting in
better planned, more comprehensive and more expedient business
separation.
. Performed Risk Assessments for Smartphones and developed security
policies and security to ensure that the devices remain secure. The
Smartphone policies implemented led to a 15% reduction in mobile
communication costs.
. Developed cost-effective solutions for providing wireless Internet
access for guests across global offices. This solution led to a
decrease in unmanaged PCs on the internal network and brought
efficiencies to providing Internet access to visiting vendors and
business partners.
. Implemented a PC backup initiative to safeguard critical media files
required to publish magazines.
. Reviewed and provided input for major IT vendor contracts ensuring
that cost-effective and favorable terms were negotiated.
. Performed due diligence and risk assessments during acquisitions and
outsourcing projects to identify and mitigate security gaps and
resulting in improved transitions.
. Maintain several company-wide partnerships and vendor relationships.
Security Architecture / Identity Management / Access Control
. Provided valuable network security architecture guidance for a new
multimedia product initiative resulting in reduced time to market and
over $10,000 reduction in infrastructure costs.
. Developed solutions for secure access and connectivity for several
strategic partners as part of the outsourcing business strategy.
These solutions enabled outsourcing to occur on time, thereby helping
business units to achieve goals.
. Created a custom workflow tool for Identity Management and developed
related procedures. The new processes allowed for centralization of
core Identity Administration while reducing the workload of local
support staff allowing them to handle additional tasks.
Regulatory Compliance
. Coordinated several multi-tiered PCI Data Security Standard
certification processes for multiple business units. This effort
ensured global compliance and reduced the risk of unintentional
disclosure and regulatory penalties.
. Provide leadership for the corporate PCI Council. The council is
comprised of technical and business representatives and was developed
to drive compliance and achieve awareness of the regulatory
requirements of the standard.
. Partnered with Internal Audit and Finance teams in conducting Sarbanes-
Oxley (SOX) auditing and testing. Acted as liaison for external audit
teams by quickly gathering and delivering comprehensive information.
This quick delivery of information reduced the overall costs
associated with audit activities.
. Partnered with General Counsel and Business Units to obtain US-EU Safe
Harbor privacy certification. The certification eliminated the need
for country-specific privacy contracts and reduced costs associated
with external privacy counsel. Workload was reduced for both US-based
and European corporate attorneys.
Global IT Infrastructure Management
. Managed transition and steady-state stages for all infrastructure-
related IT departments, minimizing any impact to the business.
. Worked closely with IT and Security outsources to ensure that 95% of
Service Level Agreements were met. Maintained a customer service
rating of 4.64 out of 5.
Associate Director, Lotus Notes and Groupware Services:
September 1999 - January 2004
Recruited by the CIO to provide leadership and direction within the
messaging environment. Managed a global team of six, responsible for the
global messaging, groupware administration and development. Drove
standardization, operating efficiency, and the strategic usage of groupware
applications, mail, and collaboration services across Reader's Digest's
global infrastructure.
. Centralized Notes administration globally to corporate headquarters,
reducing hardware costs and regional workloads.
. Architected and implemented new mail routing and replication
topologies providing redundancy.
. Implemented collaboration solution saving the organization over
$250,000 annually.
. Implemented enterprise mail antivirus strategy significantly reducing
email borne virus infections.
. Implemented spam prevention solution eliminating over 500,000 messages
daily.
. Migrated acquired organizations to corporate mail platform standard.
. Developed guidelines and standards for Notes Administration and
Development.
HYPOVEREINSBANK New York,
NY June 1999-
August 1999
The second largest private-sector bank in Germany.
Lotus Notes Administrator/Developer
June 1999 to August 1999
. Responsible for Lotus Notes infrastructure and application
development.
. Performed server upgrades and migrations as well as scheduled
maintenance.
. Implemented a Lotus Notes server backup solution.
. Designed new security architecture for bank loan workflow application.
MCKINSEY & COMPANY, INC. New York, NY
May 1996 - June 1999
Global strategic management consulting firm serving clients on their most
important business issues.
Lotus Notes Administrator
April 1998 to June 1999
. Responsible for Lotus Notes infrastructure for the New York Office.
. Performed server upgrades and migrations as well as scheduled
maintenance.
. Designed Lotus Notes applications.
. Designed and implemented redundant server architecture.
. Developed Lotus Notes applications to automate otherwise manual tasks.
. Designed customized database templates to meet the requirements of the
firm.
Microcomputer Specialist
May 1996 to April 1998
. Provided technical support for management consultants and
administrative staff.
. Developed Access databases and Excel models for consultants.
. Created process for creating and deploying imaged computers.
REVELATION SOFTWARE Stamford,
CT November 1995 - May
1996
Software company specializing in development of application development
tools.
Technical Support Analyst
. Provided technical support for developers of database applications
utilizing Revelation software.
. Designed programs for developers in need of technical assistance.
NEW YORK CITY TRANSIT AUTHORITY Queens, NY February
1994-November 1995
The largest agency in the MTA regional transportation network.
Staff Analyst
. Worked on several subway materials projects
. Provided technical support for office personnel.
. Developed system to track car repairs for the E and F subway lines.