Post Job Free
Sign in

Management Security

Location:
8807
Posted:
September 08, 2010

Contact this candidate

Resume:

Phone: 908-***-**** Email: ********@*********.***

Objective:

Diverse experience in Risk Management, Audit, and IT Compliance. Specialize in identification of IT Security weaknesses

and control deficiencies, gap remediation and implement cost effective solutions. Has a very good communication,

presentation, and interaction skills with all levels of staff and management. A good listener, with very organized work habits.

Well focused to team and management annual business objectives, with attention to timely delivery, detail, and quality of

work. Promotes sharing knowledge and development of team members.

Career Achievements:

Successfully converted (mapped, tested, merged) 50 + Business application systems for 3 major New York banks.

o

Remediation of major issues for Production Runbooks (over 130,000 jobs) and information security for the Employee

o

transfer systems and process. Periodically improved Risk Assessment testing and reporting process for Production.

Recommended and Implemented 5 global improvements to Security and Change Standards for a global bank.

o

Improved and implemented the Corporate Audit Division methodology standards for Auditing and Review of Project

o

Life and Systems Development Life Cycle.

PROFESSIONAL EXPERIENCE

SCTI Technology Institute, Bridgewater NJ Dec. 2009 – May 2010

Computer Support - Technician

Maintains technology work and maintenance for 1500 + computers, printers, and 5 networks spread over 7 buildings.

o

Troubleshoot TCP/IP networks, printers, and software related problems. Setup computer patches, upgrades, and system

backups. Deploys and maintain Windows Operating Systems. Configure server roles, functions, and security.

JPMorganChase, New York, NY Oct. 1997 – Nov. 2008

Information Risk Management - Lead (2007-2008) – Production Services, Global Technology Infrastructure Division

Responsible and performed semi-annual Risk and Control Assessments of Infrastructure (900+ Engineers,

o

Developers, Computer Operations, Application Developers, for - Data, Command Centers, Networks) and Business

Application systems. Identify control deviations, present issues and recommend solutions to management, and address

gaps. Continuously check IT setup and processes for compliance to Security Standards and Financial IT Regulations.

Conducts application development and business process risk reviews, risk mitigation and implementation of

o

solutions.

Identify information security breach, flaws and business impact. Work with the Lines of Businesses and Engineering

o

with recommendations, alternative options, and optimum solutions. Monitor resolved risk issues to prevent repeats.

Performed monthly IT Security Monitoring reports (vulnerability scans), prepare Security, Audit, and Production

o

Quality Assurance metrics reporting dashboard. Performed Security Access recertifications for midrange system

applications. Developed vendor contract requirements for Security, Service Level Agreements, and Change

Management compliance.

Formally critique global changes to Corporate IT Security, Business Continuity, and Change Management Standards.

o

Identify security flaws & business impact. Partner with Lines of Business Management to recommend, test, and

implement and follow-up to ensure effective change. Perform risk, security and BC/DR awareness class sessions.

Chaired and run Security compliance to Engineering development Projects. Ensure Development phases and actual

o

risk methodology practices conform to Enterprise Risk Standards and Federal/Government Regulations.

Technology Program Management – Lead (2005-2007)–Production Services, Global Technology Infrastructure Division

Performed project management for remediation of risk issues. This includes chairing weekly meetings, documentation,

o

scheduling, testing, implementation, and update presentations to IT management.

Performed SOX 404/302 tests (planning, testing, documentation, reporting, and resolution), point of contact and

o

assist SAS70, Internal Audit, External Examiners reviews. Performs control/risk issues remediation. Prepares full

documentation for all testing, management summary writeup, then updates the risk registers.

Monitors QA metrics and SLA performance in Production, including capacity thresholds and Security breach.

o

Performed Business Continuity, Disaster Recovery Testing in Global Production Operations and Application Systems.

o

Conduct Business impact analysis and develop the strategy and plan testing.

Infrastructure Auditing – Audit Senior (2001-2005) – Corporate Auditing Division

Performed risk based audits (plan, test, report) of computer operating systems (Distributed, Midrange, Mainframe),

o

database management, Networks, and Voice Communication and Call Center systems.

Formally audited Data Centers, Command Centers, BC/DR sites, and Voice/communication, and Call centers.

o

Performed continuous auditing and installed Key Risk Indicators and control alerts for Infrastructure systems.

o

Application Auditing – Audit Senior (1997-2001) – Corporate Auditing Division

Responsible for Integrated audits of Application and Business Systems. This includes planning and reviews of Project

o

Development Life Cycle, disaster recovery and change management systems.

Audited methods and controls for Outside Service Providers and vendors (i.e. IBM). Reviewed systems conversions.

o

Prudential Insurance Company of America, Newark, NJ Feb. 1994 – Oct. 1997

Management Audit Consultant

Responsible for audits of applications systems, data centers, and voice communications systems. Performed data

o

analytics (extract, report, analyze) using SAS and ACL.

Worked with various Line of Business management as controls advisor for development and implementation of the

o

Enterprise Application and Distributed computing standards. Implemented and Tested the IT standards of the firm.

National Westminster Bank North America (now Bank of America)

Systems Auditor

Responsible for review of Business Applications, Systems Conversions, and all Data centers.

Responsible for programming, development and reporting functions for the Audit Division. Includes Local Area Network,

o

application development, and Computer Audit Assist Technique (CAATs) support.

Responsible for reviews of system conversions and business application development. Prepared quarterly reports and

o

quarterly presentations to the Audit Committee.

Lockheed Corporation, Burbank CA

Computer Programmer Analyst

Responsible for code development, and testing of various on line financial application systems (i.e. Accounts Payable).

EDUCATION and TRAINING

Monmouth University, West Long Branch, New Jersey - Masters in Business Administration. MBA

o

Business, (diploma received)

De La Salle University, Manila, Philippines - BS Accounting (diploma received)

o

SCTI Technology Institute, Bridgewater, New Jersey - Computer Technology (diploma received)

o

CISCO Networking Academy, Midland, Texas – Computer Networking (certificate received)

o

Rutgers University, Computer Science (OS, Programming, compilers, DBMS)

o

CERTIFICATION

Certified Information Systems Auditor (CISA-#9718220 - active status)

SKILL SET

Proficient:

MS Windows; 2000, XP, Microsoft Word/Excel/Access/Powerpoint/Visio, MS Project, OS400, MVS JCL

Knowledge:

Operating and Networking Systems

o

Window Server 2003 – Active Directory

o

CISCO Routers - IOS commands – TCP/IP, DHCP, CIDR/Subnetting, DNS, Routing protocols, ACL,

o

Security, Wireless AP, Cisco Firewall

Unix, OS400, ZOS/390, Visual Basic, C SQL, HTML Netcool Console Integrator

o

Security, Risk, and Audit Tools:

o

ISA/NSS Scans, TACACs/+, ACF2/RACF

o

Audit Command Language (ACL), Phoenix and Horizon Risk Registers

o

Siteminder, RSA SecureID, Illumin and PostX Security

o

Business Technology

o

Database and Change Management – Oracle, DB2, PVCS

o

Application Development – Mercury Interactive

o

Application

o

PeopleSoft/SAP, Wire Transfers, Mortgage Banking (Origination & Servicing), Trust, Trading and Investment

o

Banking

Commercial, Deposits and Savings, Credit Card Services and Payment Systems

o

Asset Management, Health, Property, and Casualty Insurance

o

Regulations and Standards

o

COBIT, GLBA, ISO27000+, NIST, COSO, FFIEC, Basel II, ITIL, CMMI/6Sigma, PCI/DSS, HIPAA

o



Contact this candidate