Post Job Free
Sign in

Security Management

Location:
7302
Posted:
March 09, 2010

Contact this candidate

Resume:

Alberto Cardona II

Jersey City, NJ, *****

Phone: 201-***-****

***************@*******.***

INFORMATION RISK / SECURITY / PRIVACY PROFESSIONAL

Financial Institutions, Retail and Healthcare

PROFILE

Information security professional with 17 years of experience in protecting information and technology against various types of risks.

Expertise ranging from regulatory (privacy) and contractual (PCI) requirements, policy alignment, education and awareness, regulatory

compliance, assessments (risk, vulnerability, penetration), mitigating controls, and threat/vulnerability management.

KEY AREAS OF EXPERTISE

• • Regulatory & Contractual Compliance

Policy/Standards Governance, Cyber Security, data

security, forensics (SOX, PCI, Privacy)

• Assessing Risks associated to information and technologies

• Negotiator / Relationship Builder / Motivator

(Improper handling of information, Malware, intrusions)

SENIOR CONSULTANT – GOVERNANCE, RISK AND COMPLIANCE

Idea Integration Corp – Jacksonville, FL (wholly-owned subsidiary of the MPS Group) July 2009 – Present

IT consulting and technology solutions firm specializing in application development, digital data management, business intelligence,

integration, information security, and interactive marketing.

Key responsibilities focus on establishing an enterprise wide Governance, Risk and Compliance Program for “Emerson Electric” a Global

Fortune 100 Company with revenues of $24B. As well as assisting with the implementation of information security and compliance

requirements and controls within their IT SDLC and global security education and awareness program.

Duties include analyzing business structures and processes, determining compliance requirements (PCI DSS, SOX Section 404 and Privacy),

development and implementation of a GRC Framework, aligning policies and standards to corporate governance requirements, establishing risk

questionnaires/assessments, assess security and compliance postures, designing security/compensating processes and controls.

Accomplishments:

• REDESIGNED THE PAYMENT PROCESS OF A GLOBAL BUSINESS UNIT TO BE PCI COMPLIANT IN ORDER TO DETER FINANCIAL SANCTIONS. THIS NEW PROCESS

OPEX COSTS BY DECREASING CUSTOMER PAYMENT CYCLES WHICH REDUCED DISTRIBUTION TIMES OF ITS PRODUCTS.

ALSO HELPED LOWER ITS

DIRECTOR OF ENTERPRISE SECURITY / CISO

The New York Times Company – New York, NY (Revenue $2.8B, Employees 9,400) August 2007 – May 2009

Global media company providing newspapers, Internet, and radio station services.

Key responsibilities focused on the establishment of an Information Protection program to achieve compliance to PCI DSS, SOX Section 404

and various Privacy Laws and the protection of general operations. Duties included negotiating with payment card brands, payment processors

and auditors, development of policies and standards, assessing security and compliance postures, designing security/compensating processes and

controls, establishing and managing security operation center, incident response team, and operating budget.

Accomplishments:

• NOMINATED 2008 INFORMATION SECURITY EXECUTIVE NORTHEAST AWARDS FOR EXEMPLARY ACHIEVEMENT

FOR THE IN THE AREAS OF INFORMATION

SECURITY, RISK MANAGEMENT, DATA ASSET PROTECTION, REGULATORY COMPLIANCE, PRIVACY AND NETWORK SECURITY.

• Implemented an information protection program and aligned it to business requirements which helped reduce OPEX costs by 12%.

• IN 2007 REDUCED FINANCIAL LOSSES OF APPROXIMATE $66 MILLION WITHIN 3 MONTHS OF START DATE BY NEGOTIATING WITH PCI PAYMENT BRANDS

AND PAYMENT PROCESSORS (NYTCO WAS DOWNGRADE FROM A PCI DSS LEVEL 1 TO A LEVEL 2). IN 2008 REACHED PCI LEVEL 1 COMPLIANCE

• Worked with peers from different organizations to update sections of PCI DSS standards.

• Reduced SOX deficiencies by 60% by centralizing the management SOX Section 404, becoming focal point between auditors, process

owners and proposing and leveraging mitigating controls used for PCI compliance.

• REDUCED NUMBER OF PRIVACY INCIDENTS BY 80% THROUGH REDESIGNING AND COMMUNICATING POLICIES PERTAINING TO THE HANDLING (PEOPLE,

PROCESSES AND TECHNOLOGY) OF PERSONALLY IDENTIFIABLE INFORMATION.

• Established a risk assessment framework that integrated majority of PCI, SOX 404 General Computing Controls and Privacy controls into

one which led to the reduction of risk assessments by approximately 40 days.

• Created and managed a cross-functional Threat and Assurance team responsible for monitoring assets and implementing vulnerability

assessments this lead to the reduction in time to discover and mitigate incidents and vulnerabilities.

• Implemented and facilitated an incident tracking system to handle Privacy and Security Incidents.

• Designed and facilitated the rollout of a Security Event Incident Management System and file integrity system to monitor approx 3,000

devices within 30 days.

VP OF INFORMATION RISK MANAGEMENT GROUP

Merrill Lynch – New York, NY (Revenue $11.2B, Employees 64,000) April 2006 – May 2007

Financial services organization providing services in wealth management, securities trading and sales, corporate finance and investment

banking.

Key responsibilities focused on redesigning and managing Information Risk and Policy & Standards Governance program. Duties included

working with information security peers from different financial organizations in order to anticipate global fiduciary requirements, identifying

global regulations, working with legal on interpretation and determining required controls, reviewing ISO 17799:2005, AICPA GAPP

(Generally Accepted Privacy Principles) and COBIT frameworks. Conducting and managing security and privacy risk assessments, managing

mitigating plans and dispensations. Establishing a metrics program and creating and analyzing information data workflows.

Accomplishments:

• Reduced the number and time frame to review policies and risk dispensations by establishing and building partnerships with different

groups such as OGC (Legal), Audit/Compliance, Corporate Services, Core Business Units and Technology (BCP/DRP) groups.

• Reduced the number privacy and security incidents by standardizing on a global framework, centralizing global policies, updating and

aligning language to regulations and communicating them via various vectors such as training courses, town-halls, emails and posters.

• Assisted in critiquing as well as quoted in Andrew Jaquith’s book “Security Metrics: Replacing Fear, Uncertainty, and Doubt” - ISBN 0-

321-34998-9

VP OF COMPLIANCE AND INFORMATION SECURITY

Quantinus – Chicago, IL (Revenue undisclosed private company, Employees 50) July 2004 – April 2006

Professional services company providing services in post-merger integration, financial & decision analytics, strategic planning, internal &

regulatory compliance and outsourcing integration (India). Clients included: Horizon Blue Cross Blue Shield, Forsythe Solutions, Doha

Asian Games Organising Committee (DAGOC) -15th Asian Games DOHA 2006, and International Specialty Products (ISP).

Key responsibilities focused on establishing, enhancing and restructuring information security and compliance programs. Duties included

analyzing regulatory requirements such as Sarbanes Oxley, HIPAA, ICCA Responsible Care®, scoping time and effort, facilitating posture

assessments, GAP Analysis, implementation of COBIT and ISO 17799 processes and controls, data security design, implementation of security

policies, procedures, risk management processes, risk threat assessments and mitigations plans, and security awareness programs.

Accomplishments:

• One client achieved HIPAA compliance (projected compliance was originally 2 to 3 years): Ahead of 75% of its competition.

• Improved communications and established a coordination process with HR, Legal, IT and Audit groups that helped with the handling of

incidents, policy violations, and deficiencies.

• Established Information Security Operations groups with full CIRT (Computer Incident Response Team) capabilities.

• Assisted a client with establishing and implementing vendor risk assessment process and selecting an offshore development option that

helped in a saving of $800,000.

SECURITY TECHNOLOGY OFFICER

UBS AG – Weehawken, NJ (Revenue $29B, Employees 66,000) Aug 2003 – July 2004

Financial services company providing wealth management investment services ranging from asset management to estate planning and from

corporate finance to art banking.

Key responsibilities focused within the UBS Wealth Management business unit. Duties included assisting in analyzing regulatory requirements

such as SOX and GLBA, policies/standards, business requirements and processes. Managing semi-annual user recertification process,

recommending and facilitating the implementation of emerging security technologies (identity management, file and log monitoring, forensics,

IDS, IPS). Managing the vulnerability assessment team and providing summaries of vulnerabilities and status of incidents to the Corporate Vice

President. Facilitated investigations and rollout out of security patches.

Accomplishments:

• Reduce SOX deficiencies pertaining to semi-annual user entitlement reviews by implementing and managing processes and technologies

that allowed business owners to review user entitlements.

• Identified and improved threat/vulnerability assessment team by establishing transborder relationships with different groups, standardizing

on threat identification and notification process.

SENIOR INFORMATION SECURITY CONSULTANT

TEKSystems / SourceEDP – New York, NY October 2002 – August 2003

Professional services companies providing technology staffing and services.

Worked on assignments for clients such as Pfizer and HSBC.com. Key responsibilities focused on providing guidance and recommendations

by using industries best practices, standards and technological solutions (from ISO 11779, SAS 70 compliance to VPNs, Firewalls, encryption,

IDS, IPS, SIM). Duties included developing corporate security policies, procedures and guidelines, risk assessments based on SARA, SPRINT,

FRAP, and NIST, security assessments on infrastructure/applications, threat identification and countermeasures, design and automation of threat

management and incident handling processes and the implementation of security into the application/infrastructure SDLC lifecycle.

Accomplishments:

• Reduce time to market on high risk applications by implementing security best practices in the SDLC.

• Reduced loss exposure associated to fraud and privacy breaches through remediation of information security weaknesses found during

application and infrastructure security assessments.

• Leveraged security technologies to reduce operational costs such as replacing private link with internet based VPNs.

• Established standards that help reduce operational costs by due to the rebuilding of workstations and servers.

DOWNSTREAM AMERICAS SECURITY MANAGER

Beyond Petroleum – Wayne, NJ (Revenue $84B, Employees 120,000) March 1998 – August 2002

Integrated Oil & Gas Company providing services in oil, gas and alternative fuel exploration, production, refining and marketing.

Key responsibilities focused on the security of the western hemisphere (North/South America), pertaining to the Downstream Business Group

which covered 5 business sub sectors. Duties included incident and vulnerability management, establishing metrics and reporting of overall

regional security status to the Downstream Global Security Officer and each separate business unit BSS LD (Business Sub Sector leader or

CIO), policy development, risk assessments, regulatory analysis/interpretation, forensic and security audits, and security assessments on

infrastructure and applications, focal point for sharing best practices, security awareness, data security design, DRP (Disaster Recovery Plan) for

corporate data centers and networks.

Accomplishments:

• Reduced budget by 15% by implementing a risk based security program by focusing on high risk assets.

• Reduced loss exposure associated to fraud and breaches by reducing time to detect, report and mitigate incidents.

• Lowered number of accidental incidents by assisting in the design and rollout out of security awareness program.

• Implemented a risk based policy dispensation process that help determine areas of needed expenditure and policies/standards that impeded

business growth.

• Designed one of the first global corporate VPN backbones supporting data and VoIP which reduced telecommunication costs by

approxmently$500K.

• Reduced product operational costs by implementing a remote VPN access for Castrol Sales Force telecommuters and production

development staff located in India.

SENIOR INFORMATION TECHNOLOGY ADVISER

SERCA Corporation – Wanaque, NJ (Revenue undisclosed private company, Employees 25) August 1992 – March 1998

Professional services company providing technology staffing, IT integration services, and product reselling.

Worked on assignments for clients such as AeroTek, UNISYS, VANSTAR, M&M, AlliedSignal Aerospace and HFS Inc. Key responsibilities

focused on analyzing clients requirements, scoping time and effort, designing, implementing and supporting systems and infrastructure. Duties

included procuring, installing and configuring LAN/WAN cabling, hubs, switches, fileservers, remote access servers, workstations,

troubleshooting protocols and applications and training customers.

PROFESSIONAL DEVELOPMENT, CERTIFICATIONS, & AWARDS

CISSP certification in process

Check Point Certified Security Administrator (CCSA)

Check Point Certified Security Expert (CCSE)

Cisco Certified Network Associate (CCNA)

Microsoft Certified Professional (MCP)

Certified Novell Administrator (CNA)

Interviewed and quoted in June 2009 issue of Information Security Magazine

Nominee for the 2008 Information Security Executive Northeast Awards

Quoted in Andrew Jaquith’s book, “Security Metrics: Replacing Fear, Uncertainty, and Doubt” - ISBN 0-321-34998-9

Languages spoken: Spanish & Italian

EDUCATION

1995-1996 The Chubb Institute, Parsippany, New Jersey - Diploma in Network Engineering and Data Communication

1993-1995 William Paterson University, Wayne, New Jersey - Majored in Biological Science



Contact this candidate