Jose Morales
Information Security **** Tall Oaks Dr.
Aurora, Illinois
60505
mavenusa.linkit@bluet
ie.com
Profile
Bottom-line-oriented professional with more than fifteen years of
comprehensive experience in compliance oversight. Excellent leader,
motivator, using structured business management skills in building teams
and teaching technology complex topics to non-technical management
personnel. Utilize an anticipatory management style to drive results in a
rapidly changing industry. Produce consistent achievements working with
various Microsoft products. Experience with IBM mainframe operating systems
and Windows NT 4.0, VM/CMS, REXX. Possesses advanced security remediation
assessment skills as well as demonstrated abilities in translating security
and business requirements into processes and systems. Applies excellent
communication skills in managing staff and informing managers of
information security policies and procedures. Advise management on a
variety of risk issues to include: threat management, physical and
technical vulnerabilities, strategic security consultancy and problem
resolution. Maintains up-to-date knowledge of established and emerging
security technologies. Excels in identifying and implementing efficient
strategies for improvement of corporate security protection and reducing
the exposure to internal and external attacks by malicious users.
Additional areas of expertise include:
Open Source Tools System Monitoring GLB, SarBOX
IDS/IPS Analysis Sourcefire RNA HIPAA
Qualys, Nessus, ISS, Nmap Log analysis ISO 27001
Websense Network traffic analysis Data Loss Prevention
Highlights
. Presentation to faculty at John Jay School of Criminal Justice 10/2008 on
Identity Theft
. Presentation to CIS Club at Borough Manhattan Community College 04/2009
on Phishing.
. Created security polices and guidelines for state-of the -art
technologies.
. Proposed acceptable use policies and guidelines for major commercial
banks to mitigate risk resulting in 30% reduction of threats and
vulnerabilities from external perimeter attacks.
. Developed a Top Ten list of immediate threats to desktop systems and
servers as proof of concept using out-of-the-box thinking techniques and
methodologies.
. Developed and wrote custom filters for monitoring of high risk security
events.
. Designed, developed and wrote generic event-driven servers in REXX/CMS to
process all internal/external price feeds for customer portfolios and
reduced the development of server development by 70%.
Continues...
Jose Morales
Information Security Page Two
1990 Tall Oaks
Dr.
Aurora, Illinois
60505
mavenusa.linkit@b
luetie.com
Career Track
Senior Information Security Consultant, RHI 2010-Present
Recruited as the primary senior consultant to lead development and
implementation of SOC to monitor all network activity to detect, defend,
and deter attacks against the business critical assets.
. Instrumental in completing the first Database Monitoring User Guide
processes for the entire US.
The document was the most critical finding during an internal audit
scope that found 103 violations.
. Within a week from my start date was assigned to run meetings with DBA
on new monitoring process thereby relieving my manager to have more
time to attend strategic planning and auditing meetings.
. In addition to assigned responsibilities, I took initiative and found
several vulnerabilities within the
organization that I immediately alerted management and provided
remediation suggestions. This led
directly to reducing the organization exposure to attacks, possible
loss of revenue and tarnished reputation.
. Designed a new semi-automated process for performing daily monitoring
duties, research, review, and
validating of Excel spreadsheets. Reduced the existing process from 4 hours
to a total of 45 minutes,
resulting in a time savings of 81%.
. Discovered first violation of the organization's DB policy, documented
findings accurately and in a
forensically sound manner, so that it could be used in future
investigations.
. Proposed the development of a generic escalation process manual to
management. The value of this document is to show how to streamline
and provide a consistent uniform way for the InfoSec Analyst to report
issues/problems of the diverse vendor applications that are
monitored.
. Business Protection director consulted with me on a number of key
critical projects without my having any involvement or prior knowledge
of the projects. My advice and input was instrumental for the
Director making a powerful presentation and achieving some key
victories for gaining upper managements approval on some long
outstanding projects.
. Authored a script that was instrumental for the DBA to test and
validate the various components of the
organizations DB Compliance application. The detailed nature of the script
reduced the number of test
scenarios and re-testing of DB Compliance policy before it was approved to
be production ready. This shortened the DBA's testing by 10 business
days.
. Delivered a phishing presentation to FBI Infragard chapter three weeks
after having moved to Iowa.
Senior Network Security Engineer, Bloomberg 2007- 2010
Supporting high security surveillance of the DMZ network, which is the
critical for all news and media information provided worldwide to our
customers. Proactively monitor, research daily advisories and network with
senior level professionals at other Fortune 100 companies to stay abreast
of the latest security risk and vulnerabilities to make quick decision to
protect the critical network assets, valuable sensitive and proprietary
data of the firm. Self starter individual, wrote policies to alert on
suspicious file uploads in our dynamic and complex environment.
Troubleshoot difficult and highly technical problems. Great ability to
multi-task and follow through from start to finish on all projects and
assignments given. Advise other IT groups on security risks discovered and
how to close the security holes to decrease or eliminate the risk and
comply with company policies and standards. Perform periodic review of
Bluecoat proxy logs for dangerous malware domains activity. Create custom
Snort and OpenSignature signatures with the aide of tcpdump/Wireshark to
trigger for traffic directed to our internal private network using the
Sourcefire IPS. Interface with Computer Incident Response Team for
breaches, and/or security related events. Point person in evaluating
TippingPoint IPS, initiated, organized and communicated all phases of the
evaluations process from start to finish. Completed high pressure project
to set up a secure area of work for conduction day to day responsibilities
and discussing top confidential matters for the head of the Security
department. The task was finished two days earlier than the assigned
completion date.
Team Lead, Federal Reserve Bank 2005-2007
Tracked and analyzed data to identify real-time computer attacks and probes
to decide the best action plan and steps to detect, deter and defend
against them. Developed in coordination with my West coast counterpart
performance metrics to be incorporated into the existing employee
evaluation process, this was key to raising the productivity and quality of
the NOC by 15% in a 6 month timeframe. Provided levels tier2 and tier3
support and troubleshooting of network security issues and abuses. Key
member of team that reviewed and enforced internal audit findings to help
achieve being awarded the ISO 27001 certification for the first
organization in North America.
Worked closely with BCP/DR planners to ensure NIRT operational continuity
and maintain supporting infrastructure during and after future terrorist
attacks. One of the key players involved in the development, testing and
implementation of
FRBNY security plans, products, controls, security policies and procedures
for the national network security oversight and intrusion response
tracking. Reviewed with our senior internal auditor the assigned duties to
our NOC member to ensure
that they were in compliance with IS9001 quality management standard.
Provided advanced experience and knowledge of incident handling and network
security monitoring using the ArcSight SIEM tool reduced the rate of known
false positives by 25% and improved client-side console monitoring. Use of
open source forensic tools to correlate 1st tier investigation.
SeNIOR Security Analyst, HSBC 2004-2005
Monitored bank perimeter for security vulnerabilities and attacks; assist
in remediation efforts. Performed detailed technical analysis of various
security logs and incident response activities for security events.
Initiate Business As Usual scans to maintain security perimeter. Surveyed
information security information portals and kept abreast of events, R&D
within the security community. Assisted in Global IS implementations.
Conducted a review of the ISS IDS architecture, contribute to the strategic
design of the security perimeter via the various architecture and
engineering implementations. Managed the pentest conducted by an outside
Vendor. Identified and helped mitigate any vulnerability on the network.
Performed periodic security reviews and assessments.
SENIOR Security ASSESSMENT ANALYST, Radianz 2003-2004
Part of the Corporate Security Team. Conduct study and risk assessments of
the Blackberry PDA device security risks on our internal network and
developed the company security policy for PDAs. Authored technical
security guidelines for hardening and securing of Windows 2000. Conducted
vulnerability assessment on Internet facing web server and firewalls using
open source and commercial tools. Interviewed, inspect facilities,
perform configuration review and conducted audits for the following
architectures: Checkpoint firewalls, Solaris Jumpstart script, VPN
gateway. Reported to management any vulnerability discovered and proposed
remediation. Completed vulnerability assessment and security audits on
the company log retention process for UNIX, to insure that we comply with
regulatory requirements. Conducted lunch/learn to educate non-IT groups on
security awareness and company security policies and procedures. Provided
advice, recommendations for the implementation of efficient security
methodologies to proactively defend against future methods of attacks and
vulnerabilities while reducing costs.
SENIOR Security CoNSULTANT, Citigroup 2003-2003
Member of Citigroup Tactical Assessment Center elite team. Provided first
level support for intrusion detection using Enterasys DragonSight NIDS.
Monitored real-time alerts and used logs to determine if internal network
was under a real attack or make determinations if the observed traffic is a
false positive. Worked with the IDS engineering group, proposed two new
signatures and worked day to day to reduce the number of false positives
from 500,000 alerts per day down to 225,000. Familiarity with IP ports.
Used Symantec Deep Threat analysis tool for correlation of alerts with
latest advisories. During third week at the job provided training to
employees on a methodical procedure to confirm or deny real intrusions.
Continues...
Jose Morales
Information Security Page Three
1990 Tall Oaks
Dr.
Aurora, Illinois
60505
mavenusa.linkit@b
luetie.com
VP Security Engineer, Semperfi Global 2001-2003
Member Conducted systems audits on existing systems, secure payroll
department against internal probing.
Made recommendations for securing internal email system against viruses.
. Installed and configured a wireless solution for a commercial bank in
Long Island using 802.11b, this allowed the bank to have Internet
access from anywhere with their mobile laptops, and resulted in a
saving of 23% over using a conventional wired solution.
. Used shareware version of SNORT to demonstrate the importance of
intrusion detection
. Introduction of Cisco Secure Scanner to perform audit on PIX firewall
for system known vulnerabilities.
. Performed detailed audits of Solaris workstations for known security
holes, monitored system to insure that latest patches were installed.
. Prepared detailed management reports for senior executives on
enterprise network project status, security privacy issues.
. Installed and configured DNS, Active Directory and DHCP servers.
SENIOR ENGINEER, Merrill Lynch 1984-2001
Managed several hundred firewalls around the globe. Monitored and performed
system administration on Solaris OS. Monitored firewall logs for IDS
activity.
. Implemented firewall security policies for over 300 Checkpoint
firewalls.
. Provided 24/7 coverage for all firewalls and support servers.
Performed off-hours restoration of servers with disk space and expired
licenses issues.
. Inspect firewall logs on a daily basis checking for intrusion attempts
from external users.
. Member of the 9/11 emergency response team. Restored key business
units with Internet and Corporate connectivity quickly and with
minimal disruption.
. Supported Pix firewalls for Merrill Lynch partnerships. Part of a two-
person team responsible for all Pix configuration changes and 24/7
production support.
. Installed and configured Ace/SecureID to support strong two-factor
authentication and single sign-on.
. Performed vulnerability assessment of UNIX servers and made
recommendations on hardening the servers.
. Maintained and supported Ace/SecureID, performed upgrade from version
3.0 to version 5.0
Credentials
Bachelor of Science, Management Information Systems, York College Queens,
NY
CISSP, CCNA, CCSA, CHS Homeland Security.
Member, FBI INFRAGARD Association, High Tech Crimes Investigators
Association Alliance America Homeland Security Initiatives, Government
Clearance:FBI National Agency Check.
Technical Summary
Hardware: Sourcefire IPS, ISS Proventia RealSecure IPS, DragonSight
Enterasys IDS, IBM Mainframes, Checkpoint Firewall, Nortell 5150 Switch,
IBM PCs, Windows 2003 Server.
Software: Checkpoint, COBOL, PL/1, REXX, VM/CMS, Unix shell, DOS batch
scripts, MS Office 2003/2008, Antivirus, Malware prevention, Zone Alarm
Pro, NIST Windows XP security template.
REFERENCES
Available upon request and mutual interest