Post Job Free
Sign in

Security Manager

Location:
New York, NY, 10036
Posted:
March 09, 2010

Contact this candidate

Resume:

RAFAEL A. CRUZ

CISSP ? ECSA ? CEH

*** * **** ** ? Apt 3E ? Manhattan ? New York ? 10036

(787) 396 ? 1058

************@*****.***

OBJECTIVE

Apply security experience and broad knowledge of hardware, software,

and networking technologies to provide a powerful combination of

analysis, implementation, and support; accomplish confidentiality,

integrity, and availability for the protection of data and information

systems.

PROFESSIONAL EXPERIENCE

Information Security Analyst II

1199SEIU Funds, Manhattan, NY Sep 2007

to Present

. Responsible for developing, deploying and maintaining 1199SEIU Funds'

Vulnerability Assessment and Threat Management program. Achievements

include installing and maintaining Rapid7 NeXpose appliance as part of

the newly established vulnerability assessments and remediation

program; Technical collaborator of MessageLabs email security controls

and encryption enhancement; Drafted security standards, guidelines and

procedures for systems and data security; Team collaborator for major

network security technologies integration.

. Currently collaborating on remote user's definition and deploying

staff to the new VPN solution, enhancing NAC settings and developing

organization's Windows updates and patching procedures, collaborating

for the selection and deployment of a Data Loss Prevention (DLP)

solution and the design of a security test laboratory using VM

LabManager.

. Improving performance and reliability of the network and the

organization service

. Formulating and implementing monitoring, policies, procedures and

standards relating to network management and troubleshooting in

conjunction with IT Department.

. Performing scans of the infrastructure, assessing threats, risks, and

vulnerabilities from emerging security issues and following up with

IT.

. Evaluating and recommending new security technologies and documenting

related business cases.

. Collaborating on technical risk evaluations of hardware, software, and

installed systems and networks and recommending preventive,

mitigating, and alternative controls.

. Assisting in the development of access-controls and separation of

roles/duties.

. Assisting in incident response program and monitoring, correlating and

analyzing network activities from a situational awareness and security

posturing level.

. Coordinating logistics to conduct external Penetration Testing

Medicare Systems Security Officer

Triple-S Management Group, San Juan, PR

Oct 2001 to Aug 2007

. Led Medicare information security program according to the Center for

Medicare and Medicaid Services (CMS) and other federal agencies

requirements, specifications, laws and regulations (HIPAA, NIST,

FISMA, etc); selected Employee of the Year 2004.

. Created and maintained the IS Awareness and Training program

. Implemented EnCase forensics procedures and performed forensic

recovery and analysis

. Performed network vulnerability and risks assessments and evaluated

and recommended safeguards

. Monitored, investigated and reported on intrusion detection events

Maintained existent and created new information security policies and

internal procedures

. Evaluated and recommended IT security products: EnCase, McAffee

Foundstone and McAfee IntruShield among others.

. Lead documentation and testing of the System Contingency and Disaster

Recovery Plan

. Developed and maintained the Medicare Division Systems Security Plan

. Responsible for the OMB Plan of Corrective Actions & Milestones

(Office of Management and Budget) reports submission

. Conducted annual security self-assessments of operations and network

. Approved and conducted reviews of user and computer security access

. Represented the organization at semiannual CMS National Security

Meetings

. Performed informal supervisory duties

EDUCATION

. Bachelor of Science Computer Science, Dec 2001 (Magna Cum Laude)

University of Puerto Rico -Bayam n Campus

IT/IS TECHNOLOGY SKILLS

. Hardware: Rapid 7 NeXpose Appliance, Cisco MARS 110R, Cisco IPS 4260,

IronPort S360

. Software: Rapid 7 NeXpose Vulnerability Management, IronPort Web

Scanner 6.3.x, MessageLabs Email Security, Sawmill for IronPort 7.3.1,

Cisco MARS 6.0.x., Cisco IPS 7, Cisco NAC 4.6.x, Cisco ASDM Launcher

1.5, Cisco VPN Client 5.0 and AnyConnect SSL Client 2.0, Windows

Active Directory and GPO Manager, Hyena, McAfee Foundstone, McAfee

IntruShield IPS, WebSense, SurfControl, CyFin (CyBlock), Altiris

-Inventory and Patch Manager, Checkpoint NG FW-1, EnCase Forensics

Toolkit, Symantec End-Point Protection Manager, VMware Workstation 6.0

and Lab Manager 4.0, ISS Real Secure, ISS Internet Scanner, MS Office

2003/ 2007 Suite

. Operating Systems: Windows Server 2000/2003, Windows XP, Linux, Apple,

Cisco IOS 12.4

CERTIFICATIONS AND PROFESSIONAL DEVELOPMENT

. CISSP (2004) [ID: 67297] - ISC2 recognizes mastery as of an

international standard for information security and understanding of

the ten CISSP information systems security test domains such as Access

Control Systems, Cryptography, and Security Management Practices.

. ECSA (2009) [ID: ECC927471]: EC-Council Security Analyst/ Licensed

Penetration Tester teaches on advanced uses of security testing

methodologies, tools and techniques required for analyzing, designing,

securing and performing intensive assessments of networks; to protect

an organization from threats that hackers and crackers pose.

. CEH (2008) [ID: ECC916426]: An ethical hacker professes hacker skills

and techniques, and uses them for defensive purposes in favor of an

entity.

. CompTIA Security+ (2003) [ID: COMP001001531134]: Windows, Unix and

Novell - Critical knowledge of industry-wide topics, including

communication security, infrastructure security, cryptography, access

control, authentication, external attack and operational and

organization security.

. CompTIA Network+ (2003) [ID: COMP001001531134]: Windows, Unix and

Novell - Critical knowledge of media and topologies, protocols and

standards, network implementation and network support.

. McAfee IntruShield 3.1 Network and Host IPS (2006): Trained in-depth

on how to better prevent attacks with McAfee IntruShield & HIPS

intrusion prevention technology.

. Encase Forensics Intermediate Analysis and Reporting (2005): Trained

on understanding the proper handling of evidence from seizure to

acquisition, and how an evidence e-file is acquired, stored and

verified in an appropriate manner.

. CCNA towards CCSP (in progress): Training to design and implement

highly secure network business systems, emphasizing Cisco security

solutions; Cisco Secure ACS, ASA and PIX security appliances, and 4200

IPS sensors.

SUMMARY OF QUALIFICATIONS

. Solid knowledge of information security principles and best practices.

. Clear understanding of advanced security protocols and standards

. Excellent leadership, organizational and project management skills

. Assertive, aggressive learner, self-motivated, self-starter, goal-

oriented, organized and efficient

. Highly motivated to promote a professional work environment

. Able to work well under pressure and flexible, can handle simultaneous

projects, and meet deadlines

. Able to interact and work in a team environment

. Able to communicate and interact effectively with individuals at all

levels of the company

. Strong writing and documentation skills

. Speak fluent English and Spanish

. Willing to travel



Contact this candidate