Alberto Cardona II
Jersey City, NJ, *****
Phone: 201-***-****
***************@*******.***
INFORMATION RISK / SECURITY / PRIVACY PROFESSIONAL
Financial Institutions, Retail and Healthcare
PROFILE
Information security professional with 17 years of experience in protecting information and technology against various types of risks.
Expertise ranging from regulatory (privacy) and contractual (PCI) requirements, policy alignment, education and awareness, regulatory
compliance, assessments (risk, vulnerability, penetration), mitigating controls, and threat/vulnerability management.
KEY AREAS OF EXPERTISE
• • Regulatory & Contractual Compliance
Policy/Standards Governance, Cyber Security, data
security, forensics (SOX, PCI, Privacy)
• Assessing Risks associated to information and technologies
• Negotiator / Relationship Builder / Motivator
(Improper handling of information, Malware, intrusions)
SENIOR CONSULTANT – GOVERNANCE, RISK AND COMPLIANCE
Idea Integration Corp – Jacksonville, FL (wholly-owned subsidiary of the MPS Group) July 2009 – Present
IT consulting and technology solutions firm specializing in application development, digital data management, business intelligence,
integration, information security, and interactive marketing.
Key responsibilities focus on establishing an enterprise wide Governance, Risk and Compliance Program for “Emerson Electric” a Global
Fortune 100 Company with revenues of $24B. As well as assisting with the implementation of information security and compliance
requirements and controls within their IT SDLC and global security education and awareness program.
Duties include analyzing business structures and processes, determining compliance requirements (PCI DSS, SOX Section 404 and Privacy),
development and implementation of a GRC Framework, aligning policies and standards to corporate governance requirements, establishing risk
questionnaires/assessments, assess security and compliance postures, designing security/compensating processes and controls.
Accomplishments:
• REDESIGNED THE PAYMENT PROCESS OF A GLOBAL BUSINESS UNIT TO BE PCI COMPLIANT IN ORDER TO DETER FINANCIAL SANCTIONS. THIS NEW PROCESS
OPEX COSTS BY DECREASING CUSTOMER PAYMENT CYCLES WHICH REDUCED DISTRIBUTION TIMES OF ITS PRODUCTS.
ALSO HELPED LOWER ITS
DIRECTOR OF ENTERPRISE SECURITY / CISO
The New York Times Company – New York, NY (Revenue $2.8B, Employees 9,400) August 2007 – May 2009
Global media company providing newspapers, Internet, and radio station services.
Key responsibilities focused on the establishment of an Information Protection program to achieve compliance to PCI DSS, SOX Section 404
and various Privacy Laws and the protection of general operations. Duties included negotiating with payment card brands, payment processors
and auditors, development of policies and standards, assessing security and compliance postures, designing security/compensating processes and
controls, establishing and managing security operation center, incident response team, and operating budget.
Accomplishments:
• NOMINATED 2008 INFORMATION SECURITY EXECUTIVE NORTHEAST AWARDS FOR EXEMPLARY ACHIEVEMENT
FOR THE IN THE AREAS OF INFORMATION
SECURITY, RISK MANAGEMENT, DATA ASSET PROTECTION, REGULATORY COMPLIANCE, PRIVACY AND NETWORK SECURITY.
• Implemented an information protection program and aligned it to business requirements which helped reduce OPEX costs by 12%.
• IN 2007 REDUCED FINANCIAL LOSSES OF APPROXIMATE $66 MILLION WITHIN 3 MONTHS OF START DATE BY NEGOTIATING WITH PCI PAYMENT BRANDS
AND PAYMENT PROCESSORS (NYTCO WAS DOWNGRADE FROM A PCI DSS LEVEL 1 TO A LEVEL 2). IN 2008 REACHED PCI LEVEL 1 COMPLIANCE
• Worked with peers from different organizations to update sections of PCI DSS standards.
• Reduced SOX deficiencies by 60% by centralizing the management SOX Section 404, becoming focal point between auditors, process
owners and proposing and leveraging mitigating controls used for PCI compliance.
• REDUCED NUMBER OF PRIVACY INCIDENTS BY 80% THROUGH REDESIGNING AND COMMUNICATING POLICIES PERTAINING TO THE HANDLING (PEOPLE,
PROCESSES AND TECHNOLOGY) OF PERSONALLY IDENTIFIABLE INFORMATION.
• Established a risk assessment framework that integrated majority of PCI, SOX 404 General Computing Controls and Privacy controls into
one which led to the reduction of risk assessments by approximately 40 days.
• Created and managed a cross-functional Threat and Assurance team responsible for monitoring assets and implementing vulnerability
assessments this lead to the reduction in time to discover and mitigate incidents and vulnerabilities.
• Implemented and facilitated an incident tracking system to handle Privacy and Security Incidents.
• Designed and facilitated the rollout of a Security Event Incident Management System and file integrity system to monitor approx 3,000
devices within 30 days.
VP OF INFORMATION RISK MANAGEMENT GROUP
Merrill Lynch – New York, NY (Revenue $11.2B, Employees 64,000) April 2006 – May 2007
Financial services organization providing services in wealth management, securities trading and sales, corporate finance and investment
banking.
Key responsibilities focused on redesigning and managing Information Risk and Policy & Standards Governance program. Duties included
working with information security peers from different financial organizations in order to anticipate global fiduciary requirements, identifying
global regulations, working with legal on interpretation and determining required controls, reviewing ISO 17799:2005, AICPA GAPP
(Generally Accepted Privacy Principles) and COBIT frameworks. Conducting and managing security and privacy risk assessments, managing
mitigating plans and dispensations. Establishing a metrics program and creating and analyzing information data workflows.
Accomplishments:
• Reduced the number and time frame to review policies and risk dispensations by establishing and building partnerships with different
groups such as OGC (Legal), Audit/Compliance, Corporate Services, Core Business Units and Technology (BCP/DRP) groups.
• Reduced the number privacy and security incidents by standardizing on a global framework, centralizing global policies, updating and
aligning language to regulations and communicating them via various vectors such as training courses, town-halls, emails and posters.
• Assisted in critiquing as well as quoted in Andrew Jaquith’s book “Security Metrics: Replacing Fear, Uncertainty, and Doubt” - ISBN 0-
321-34998-9
VP OF COMPLIANCE AND INFORMATION SECURITY
Quantinus – Chicago, IL (Revenue undisclosed private company, Employees 50) July 2004 – April 2006
Professional services company providing services in post-merger integration, financial & decision analytics, strategic planning, internal &
regulatory compliance and outsourcing integration (India). Clients included: Horizon Blue Cross Blue Shield, Forsythe Solutions, Doha
Asian Games Organising Committee (DAGOC) -15th Asian Games DOHA 2006, and International Specialty Products (ISP).
Key responsibilities focused on establishing, enhancing and restructuring information security and compliance programs. Duties included
analyzing regulatory requirements such as Sarbanes Oxley, HIPAA, ICCA Responsible Care®, scoping time and effort, facilitating posture
assessments, GAP Analysis, implementation of COBIT and ISO 17799 processes and controls, data security design, implementation of security
policies, procedures, risk management processes, risk threat assessments and mitigations plans, and security awareness programs.
Accomplishments:
• One client achieved HIPAA compliance (projected compliance was originally 2 to 3 years): Ahead of 75% of its competition.
• Improved communications and established a coordination process with HR, Legal, IT and Audit groups that helped with the handling of
incidents, policy violations, and deficiencies.
• Established Information Security Operations groups with full CIRT (Computer Incident Response Team) capabilities.
• Assisted a client with establishing and implementing vendor risk assessment process and selecting an offshore development option that
helped in a saving of $800,000.
SECURITY TECHNOLOGY OFFICER
UBS AG – Weehawken, NJ (Revenue $29B, Employees 66,000) Aug 2003 – July 2004
Financial services company providing wealth management investment services ranging from asset management to estate planning and from
corporate finance to art banking.
Key responsibilities focused within the UBS Wealth Management business unit. Duties included assisting in analyzing regulatory requirements
such as SOX and GLBA, policies/standards, business requirements and processes. Managing semi-annual user recertification process,
recommending and facilitating the implementation of emerging security technologies (identity management, file and log monitoring, forensics,
IDS, IPS). Managing the vulnerability assessment team and providing summaries of vulnerabilities and status of incidents to the Corporate Vice
President. Facilitated investigations and rollout out of security patches.
Accomplishments:
• Reduce SOX deficiencies pertaining to semi-annual user entitlement reviews by implementing and managing processes and technologies
that allowed business owners to review user entitlements.
• Identified and improved threat/vulnerability assessment team by establishing transborder relationships with different groups, standardizing
on threat identification and notification process.
SENIOR INFORMATION SECURITY CONSULTANT
TEKSystems / SourceEDP – New York, NY October 2002 – August 2003
Professional services companies providing technology staffing and services.
Worked on assignments for clients such as Pfizer and HSBC.com. Key responsibilities focused on providing guidance and recommendations
by using industries best practices, standards and technological solutions (from ISO 11779, SAS 70 compliance to VPNs, Firewalls, encryption,
IDS, IPS, SIM). Duties included developing corporate security policies, procedures and guidelines, risk assessments based on SARA, SPRINT,
FRAP, and NIST, security assessments on infrastructure/applications, threat identification and countermeasures, design and automation of threat
management and incident handling processes and the implementation of security into the application/infrastructure SDLC lifecycle.
Accomplishments:
• Reduce time to market on high risk applications by implementing security best practices in the SDLC.
• Reduced loss exposure associated to fraud and privacy breaches through remediation of information security weaknesses found during
application and infrastructure security assessments.
• Leveraged security technologies to reduce operational costs such as replacing private link with internet based VPNs.
• Established standards that help reduce operational costs by due to the rebuilding of workstations and servers.
DOWNSTREAM AMERICAS SECURITY MANAGER
Beyond Petroleum – Wayne, NJ (Revenue $84B, Employees 120,000) March 1998 – August 2002
Integrated Oil & Gas Company providing services in oil, gas and alternative fuel exploration, production, refining and marketing.
Key responsibilities focused on the security of the western hemisphere (North/South America), pertaining to the Downstream Business Group
which covered 5 business sub sectors. Duties included incident and vulnerability management, establishing metrics and reporting of overall
regional security status to the Downstream Global Security Officer and each separate business unit BSS LD (Business Sub Sector leader or
CIO), policy development, risk assessments, regulatory analysis/interpretation, forensic and security audits, and security assessments on
infrastructure and applications, focal point for sharing best practices, security awareness, data security design, DRP (Disaster Recovery Plan) for
corporate data centers and networks.
Accomplishments:
• Reduced budget by 15% by implementing a risk based security program by focusing on high risk assets.
• Reduced loss exposure associated to fraud and breaches by reducing time to detect, report and mitigate incidents.
• Lowered number of accidental incidents by assisting in the design and rollout out of security awareness program.
• Implemented a risk based policy dispensation process that help determine areas of needed expenditure and policies/standards that impeded
business growth.
• Designed one of the first global corporate VPN backbones supporting data and VoIP which reduced telecommunication costs by
approxmently$500K.
• Reduced product operational costs by implementing a remote VPN access for Castrol Sales Force telecommuters and production
development staff located in India.
SENIOR INFORMATION TECHNOLOGY ADVISER
SERCA Corporation – Wanaque, NJ (Revenue undisclosed private company, Employees 25) August 1992 – March 1998
Professional services company providing technology staffing, IT integration services, and product reselling.
Worked on assignments for clients such as AeroTek, UNISYS, VANSTAR, M&M, AlliedSignal Aerospace and HFS Inc. Key responsibilities
focused on analyzing clients requirements, scoping time and effort, designing, implementing and supporting systems and infrastructure. Duties
included procuring, installing and configuring LAN/WAN cabling, hubs, switches, fileservers, remote access servers, workstations,
troubleshooting protocols and applications and training customers.
PROFESSIONAL DEVELOPMENT, CERTIFICATIONS, & AWARDS
CISSP certification in process
Check Point Certified Security Administrator (CCSA)
Check Point Certified Security Expert (CCSE)
Cisco Certified Network Associate (CCNA)
Microsoft Certified Professional (MCP)
Certified Novell Administrator (CNA)
Interviewed and quoted in June 2009 issue of Information Security Magazine
Nominee for the 2008 Information Security Executive Northeast Awards
Quoted in Andrew Jaquith’s book, “Security Metrics: Replacing Fear, Uncertainty, and Doubt” - ISBN 0-321-34998-9
Languages spoken: Spanish & Italian
EDUCATION
1995-1996 The Chubb Institute, Parsippany, New Jersey - Diploma in Network Engineering and Data Communication
1993-1995 William Paterson University, Wayne, New Jersey - Majored in Biological Science