Post Job Free
Sign in

Security Engineer

Location:
Aurora, IL, 60505
Posted:
August 23, 2010

Contact this candidate

Resume:

Jose Morales

Information Security **** Tall Oaks Dr.

Aurora, Illinois

60505

mavenusa.linkit@bluet

ie.com

646-***-****

Profile

Bottom-line-oriented professional with more than fifteen years of

comprehensive experience in compliance oversight. Excellent leader,

motivator, using structured business management skills in building teams

and teaching technology complex topics to non-technical management

personnel. Utilize an anticipatory management style to drive results in a

rapidly changing industry. Produce consistent achievements working with

various Microsoft products. Experience with IBM mainframe operating systems

and Windows NT 4.0, VM/CMS, REXX. Possesses advanced security remediation

assessment skills as well as demonstrated abilities in translating security

and business requirements into processes and systems. Applies excellent

communication skills in managing staff and informing managers of

information security policies and procedures. Advise management on a

variety of risk issues to include: threat management, physical and

technical vulnerabilities, strategic security consultancy and problem

resolution. Maintains up-to-date knowledge of established and emerging

security technologies. Excels in identifying and implementing efficient

strategies for improvement of corporate security protection and reducing

the exposure to internal and external attacks by malicious users.

Additional areas of expertise include:

Open Source Tools System Monitoring GLB, SarBOX

IDS/IPS Analysis Sourcefire RNA HIPAA

Qualys, Nessus, ISS, Nmap Log analysis ISO 27001

Websense Network traffic analysis Data Loss Prevention

Highlights

. Presentation to faculty at John Jay School of Criminal Justice 10/2008 on

Identity Theft

. Presentation to CIS Club at Borough Manhattan Community College 04/2009

on Phishing.

. Created security polices and guidelines for state-of the -art

technologies.

. Proposed acceptable use policies and guidelines for major commercial

banks to mitigate risk resulting in 30% reduction of threats and

vulnerabilities from external perimeter attacks.

. Developed a Top Ten list of immediate threats to desktop systems and

servers as proof of concept using out-of-the-box thinking techniques and

methodologies.

. Developed and wrote custom filters for monitoring of high risk security

events.

. Designed, developed and wrote generic event-driven servers in REXX/CMS to

process all internal/external price feeds for customer portfolios and

reduced the development of server development by 70%.

Continues...

Jose Morales

Information Security Page Two

1990 Tall Oaks

Dr.

Aurora, Illinois

60505

mavenusa.linkit@b

luetie.com

646-***-****

Career Track

Senior Information Security Consultant, RHI 2010-Present

Recruited as the primary senior consultant to lead development and

implementation of SOC to monitor all network activity to detect, defend,

and deter attacks against the business critical assets.

. Instrumental in completing the first Database Monitoring User Guide

processes for the entire US.

The document was the most critical finding during an internal audit

scope that found 103 violations.

. Within a week from my start date was assigned to run meetings with DBA

on new monitoring process thereby relieving my manager to have more

time to attend strategic planning and auditing meetings.

. In addition to assigned responsibilities, I took initiative and found

several vulnerabilities within the

organization that I immediately alerted management and provided

remediation suggestions. This led

directly to reducing the organization exposure to attacks, possible

loss of revenue and tarnished reputation.

. Designed a new semi-automated process for performing daily monitoring

duties, research, review, and

validating of Excel spreadsheets. Reduced the existing process from 4 hours

to a total of 45 minutes,

resulting in a time savings of 81%.

. Discovered first violation of the organization's DB policy, documented

findings accurately and in a

forensically sound manner, so that it could be used in future

investigations.

. Proposed the development of a generic escalation process manual to

management. The value of this document is to show how to streamline

and provide a consistent uniform way for the InfoSec Analyst to report

issues/problems of the diverse vendor applications that are

monitored.

. Business Protection director consulted with me on a number of key

critical projects without my having any involvement or prior knowledge

of the projects. My advice and input was instrumental for the

Director making a powerful presentation and achieving some key

victories for gaining upper managements approval on some long

outstanding projects.

. Authored a script that was instrumental for the DBA to test and

validate the various components of the

organizations DB Compliance application. The detailed nature of the script

reduced the number of test

scenarios and re-testing of DB Compliance policy before it was approved to

be production ready. This shortened the DBA's testing by 10 business

days.

. Delivered a phishing presentation to FBI Infragard chapter three weeks

after having moved to Iowa.

Senior Network Security Engineer, Bloomberg 2007- 2010

Supporting high security surveillance of the DMZ network, which is the

critical for all news and media information provided worldwide to our

customers. Proactively monitor, research daily advisories and network with

senior level professionals at other Fortune 100 companies to stay abreast

of the latest security risk and vulnerabilities to make quick decision to

protect the critical network assets, valuable sensitive and proprietary

data of the firm. Self starter individual, wrote policies to alert on

suspicious file uploads in our dynamic and complex environment.

Troubleshoot difficult and highly technical problems. Great ability to

multi-task and follow through from start to finish on all projects and

assignments given. Advise other IT groups on security risks discovered and

how to close the security holes to decrease or eliminate the risk and

comply with company policies and standards. Perform periodic review of

Bluecoat proxy logs for dangerous malware domains activity. Create custom

Snort and OpenSignature signatures with the aide of tcpdump/Wireshark to

trigger for traffic directed to our internal private network using the

Sourcefire IPS. Interface with Computer Incident Response Team for

breaches, and/or security related events. Point person in evaluating

TippingPoint IPS, initiated, organized and communicated all phases of the

evaluations process from start to finish. Completed high pressure project

to set up a secure area of work for conduction day to day responsibilities

and discussing top confidential matters for the head of the Security

department. The task was finished two days earlier than the assigned

completion date.

Team Lead, Federal Reserve Bank 2005-2007

Tracked and analyzed data to identify real-time computer attacks and probes

to decide the best action plan and steps to detect, deter and defend

against them. Developed in coordination with my West coast counterpart

performance metrics to be incorporated into the existing employee

evaluation process, this was key to raising the productivity and quality of

the NOC by 15% in a 6 month timeframe. Provided levels tier2 and tier3

support and troubleshooting of network security issues and abuses. Key

member of team that reviewed and enforced internal audit findings to help

achieve being awarded the ISO 27001 certification for the first

organization in North America.

Worked closely with BCP/DR planners to ensure NIRT operational continuity

and maintain supporting infrastructure during and after future terrorist

attacks. One of the key players involved in the development, testing and

implementation of

FRBNY security plans, products, controls, security policies and procedures

for the national network security oversight and intrusion response

tracking. Reviewed with our senior internal auditor the assigned duties to

our NOC member to ensure

that they were in compliance with IS9001 quality management standard.

Provided advanced experience and knowledge of incident handling and network

security monitoring using the ArcSight SIEM tool reduced the rate of known

false positives by 25% and improved client-side console monitoring. Use of

open source forensic tools to correlate 1st tier investigation.

SeNIOR Security Analyst, HSBC 2004-2005

Monitored bank perimeter for security vulnerabilities and attacks; assist

in remediation efforts. Performed detailed technical analysis of various

security logs and incident response activities for security events.

Initiate Business As Usual scans to maintain security perimeter. Surveyed

information security information portals and kept abreast of events, R&D

within the security community. Assisted in Global IS implementations.

Conducted a review of the ISS IDS architecture, contribute to the strategic

design of the security perimeter via the various architecture and

engineering implementations. Managed the pentest conducted by an outside

Vendor. Identified and helped mitigate any vulnerability on the network.

Performed periodic security reviews and assessments.

SENIOR Security ASSESSMENT ANALYST, Radianz 2003-2004

Part of the Corporate Security Team. Conduct study and risk assessments of

the Blackberry PDA device security risks on our internal network and

developed the company security policy for PDAs. Authored technical

security guidelines for hardening and securing of Windows 2000. Conducted

vulnerability assessment on Internet facing web server and firewalls using

open source and commercial tools. Interviewed, inspect facilities,

perform configuration review and conducted audits for the following

architectures: Checkpoint firewalls, Solaris Jumpstart script, VPN

gateway. Reported to management any vulnerability discovered and proposed

remediation. Completed vulnerability assessment and security audits on

the company log retention process for UNIX, to insure that we comply with

regulatory requirements. Conducted lunch/learn to educate non-IT groups on

security awareness and company security policies and procedures. Provided

advice, recommendations for the implementation of efficient security

methodologies to proactively defend against future methods of attacks and

vulnerabilities while reducing costs.

SENIOR Security CoNSULTANT, Citigroup 2003-2003

Member of Citigroup Tactical Assessment Center elite team. Provided first

level support for intrusion detection using Enterasys DragonSight NIDS.

Monitored real-time alerts and used logs to determine if internal network

was under a real attack or make determinations if the observed traffic is a

false positive. Worked with the IDS engineering group, proposed two new

signatures and worked day to day to reduce the number of false positives

from 500,000 alerts per day down to 225,000. Familiarity with IP ports.

Used Symantec Deep Threat analysis tool for correlation of alerts with

latest advisories. During third week at the job provided training to

employees on a methodical procedure to confirm or deny real intrusions.

Continues...

Jose Morales

Information Security Page Three

1990 Tall Oaks

Dr.

Aurora, Illinois

60505

mavenusa.linkit@b

luetie.com

646-***-****

VP Security Engineer, Semperfi Global 2001-2003

Member Conducted systems audits on existing systems, secure payroll

department against internal probing.

Made recommendations for securing internal email system against viruses.

. Installed and configured a wireless solution for a commercial bank in

Long Island using 802.11b, this allowed the bank to have Internet

access from anywhere with their mobile laptops, and resulted in a

saving of 23% over using a conventional wired solution.

. Used shareware version of SNORT to demonstrate the importance of

intrusion detection

. Introduction of Cisco Secure Scanner to perform audit on PIX firewall

for system known vulnerabilities.

. Performed detailed audits of Solaris workstations for known security

holes, monitored system to insure that latest patches were installed.

. Prepared detailed management reports for senior executives on

enterprise network project status, security privacy issues.

. Installed and configured DNS, Active Directory and DHCP servers.

SENIOR ENGINEER, Merrill Lynch 1984-2001

Managed several hundred firewalls around the globe. Monitored and performed

system administration on Solaris OS. Monitored firewall logs for IDS

activity.

. Implemented firewall security policies for over 300 Checkpoint

firewalls.

. Provided 24/7 coverage for all firewalls and support servers.

Performed off-hours restoration of servers with disk space and expired

licenses issues.

. Inspect firewall logs on a daily basis checking for intrusion attempts

from external users.

. Member of the 9/11 emergency response team. Restored key business

units with Internet and Corporate connectivity quickly and with

minimal disruption.

. Supported Pix firewalls for Merrill Lynch partnerships. Part of a two-

person team responsible for all Pix configuration changes and 24/7

production support.

. Installed and configured Ace/SecureID to support strong two-factor

authentication and single sign-on.

. Performed vulnerability assessment of UNIX servers and made

recommendations on hardening the servers.

. Maintained and supported Ace/SecureID, performed upgrade from version

3.0 to version 5.0

Credentials

Bachelor of Science, Management Information Systems, York College Queens,

NY

CISSP, CCNA, CCSA, CHS Homeland Security.

Member, FBI INFRAGARD Association, High Tech Crimes Investigators

Association Alliance America Homeland Security Initiatives, Government

Clearance:FBI National Agency Check.

Technical Summary

Hardware: Sourcefire IPS, ISS Proventia RealSecure IPS, DragonSight

Enterasys IDS, IBM Mainframes, Checkpoint Firewall, Nortell 5150 Switch,

IBM PCs, Windows 2003 Server.

Software: Checkpoint, COBOL, PL/1, REXX, VM/CMS, Unix shell, DOS batch

scripts, MS Office 2003/2008, Antivirus, Malware prevention, Zone Alarm

Pro, NIST Windows XP security template.

REFERENCES

Available upon request and mutual interest



Contact this candidate