Erica D. Santiago, MBA
**** ***** ******* **. ( El Cajon, CA 92020 ( Phone: 619-***-**** ( Email:
**********@***.***
Career Goal: Director of Information Technology and Security
Dedicated IT Auditor with 10 years of experience working in IT Security. My main
contributions include, developing and implementing IT controls policies and
procedures systems, strategies, processes and controls that significantly improve
the overall compliance efforts of IT. Advanced knowledge in establishing PCI,
Sarbanes Oxley, and SAS70 compliance with systems and best practices lasting
business relationships to ensure goal-surpassing fiscal performance. Computer skills
include proficiency in People Soft, Active Directory, Networking, including TCP/IP
protocol layers, Routing/Switching, Wireless Networking, VLANS, Intrusion Detection
(IDS), Firewalls, Remedy, Lotus Notes, Microsoft Project Microsoft Office System
(including Microsoft Word, Microsoft Excel, Microsoft PowerPoint , Microsoft Access,
and Microsoft Outlook) and Iseries/AS 400
.
Education
Certified Information Systems Auditor, (in progress), Exp. Completion,
6/2010
Master of Science in Business, 2009
Bachelor of Science in Information Technology, 2007
Associate of Science in Accounting, 1999
Experience
Encore Capital Group - San diego, CA
IT SECURITY AND AUDIT ANALYST, 3/2008 TO 3/2010
Promoted to IT Security and Audit Analyst to establish and manage
enterprise-wide information-technology audit and Security programs. Oversee
companywide efforts to identify risks and evaluate all critical systems.
Design and implement security processes and procedures and recommended
strategies. Collaborate with external auditors to conduct in-depth
compliance audits and penetration testing, presenting all results to senior
management. Develop security awareness training for management and
employees.
Key results:
. Manage IT compliance efforts and act as project manager to ensure issues
are identified and resolved in a timely manner. Key liaison and project
manager for 3rd party audits (SAS 70, Client Audits and related
requirements) Make recommendations for process improvement related to a
strong system of IT General Controls. Act as key liaison with Financial
Compliance and IT external auditors and IT internal consultants.
. Assist Financial Compliance team and IT consultants with IT related
internal audit projects. Interfacing with the Director of Financial
Compliance, senior management, external auditors, Sarbanes Oxley
consultants and other third parties as required. Perform other audit
related duties as assigned.
. As corporate liaison, responsible for developing and writing policies
pertaining to audit, it security and disaster recovery.
. Responsible for developing, writing, and managing the process, procedures
and planning of all disaster discovery programs in accordance with
organizational information security standards. Performs and evaluates
information risk on a regular time schedule
. Developed the process of granting rights to all users and groups on the
systems. Ensure that monitoring systems are in place to detect security
violations. Responds to internal and external threats to systems
security. Develops and implements security standards and procedures.
. Advised corporate management by providing functional expertise concerning
all aspects of security, integrity and privacy of corporate data
resources. Ensure that all SOX Data requirements are met and adhered to.
Establishes, plans, and administers the overall policies, goals and
procedures for the information security function.
. Initiates, implements and develops information security and information
security awareness within the organization. Maintains systems access to
protect data from unauthorized users. Identifies, reports, and resolves
security violations.
. Responsible for the development and completion of all Security Awareness
training, education and planning. Oversees all aspects of projects. Sets
deadlines, assigns responsibilities, and monitors and summarizes progress
of project. Prepares reports for upper management regarding status of
project.
. Performs information systems administrative procedures and develops
documentation that covers two or more functional areas including, IT
Audit and Compliance, IT Risk and Remediation and IT Security.
Brandes Investments - San Diego, CA
PROJECT COORDINATOR (CONSULTANT; CONCURRENT WITH COLLEGE STUDIES), 4/2007
TO 4/2008
Performed project management functions assisting 4 senior project managers.
Key results:
. Worked directly with Business Development Analysts and Project Managers
on 6 multi-million dollar projects
. Researched and wrote special reports concerning current projects new
business acquisitions prospects.
. Played key role in preparing and implementing a successful department
wide Risk Management Training.
. Prepared corporate analytical and statistical reports for senior
management.
Science application international corporation (saic) - San Diego, CA
IT SECURITY MANAGER, 12/2003 TO 4/2007
Promoted to IT Security Manager; responsible for managing all service
center teams charged with distributing new security products to over 40,000
employees. As Department liaison supervised the development and release of
two new database applications to support IT security service centers; -
Oversaw recruiting and training, resource allocation, and employee
assessment functions. Built and mentored cohesive, qualified teams
committed to meeting schedule and budgetary needs.
Key results:
. Coordinate and collaborate with internal and external auditors to ensure
companywide compliancy in the following areas: Policies and Procedures, IT
service delivery and support, protection of information assets and
information security and access control.
. Provide assistance with the development and communication of the audit
plan and risk assessment. This includes developing and updating
presentations for senior management and communication to the audit
committee
. As internal and external liaison hands on experience coordinating IT
Security compliance efforts;
. Proactively pursued professional development opportunities, including
external and internal training and professional association memberships.
. Maintain budget and expenditures for all service centers.
. Spearheaded creation of four new information-security departments,
including Risk Assessment, Vulnerability, Penetration Testing, and
Identity management services.
. Held key responsibility for day to day operations of four service centers
with a combined customer base of over 35,000.
. Developed and implemented a companywide badge issuance program for over
42,000 existing employees, which enhanced company security, data
encryption protection, and overall appearance.
. Maintain budget and expenditures for all service centers.
. Initiated multiple overseas contacts and served as liaison for foreign
customers on business projects in the U.S.
LPL Financial - San Diego, CA
EXECUTIVE ASSISTANT/PROJECT COORDINATOR (CONSULTANT; CONCURRENT WITH
COLLEGE STUDIES), 12/1998 TO 4/2003
Assistant to three Senior Vice Presidents, eight Project Managers and 24
employees in software development group
Key results:
. Maintain all executive calendars,
. Assist Project Managers with MS project updates
. Arrange travel in CONUS and Abroad
. Maintain and review monthly operational expense budget and cost
accounting to ensure expenses were correctly allocated.
. Perform analysis and project plan updates
. Prepare specialized reports (as required by Senior Management)
. Attend weekly team meetings for each project to record minutes and track
action items